---
id: CVE-2026-89064
title: >-
  The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to
  Insufficient Credential Protection in versions up to, and including, 7.110
summary: >-
  The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to
  Insufficient Credential Protection in versions up to, and including, 7.110.
  This is due to the `Ai1wm_Main_Controller::init()` method — registered on the
  `admin…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-522
vendor: servmask
product: All-in-One WP Migration and Backup
affected:
  - all-in-one_wp_migration_and_backup <= 7.110
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:17:17.637'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89064'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.110/lib/controller/class-ai1wm-main-controller.php#L1303
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.110/lib/controller/class-ai1wm-main-controller.php#L1315
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.110/lib/controller/class-ai1wm-main-controller.php#L82
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3696427%40all-in-one-wp-migration&new=3696427%40all-in-one-wp-migration
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/5a8737b1-fb68-4609-8474-9395f30c1089?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T14:39:43.573696Z'
epss: 0.00496
epssPercentile: 0.39893
ingestedAt: '2026-09-17T03:10:13.906Z'
---

## Overview

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin_init` hook, which fires unauthenticated on `admin-ajax.php` and `admin-post.php` requests — reading `$_SERVER['PHP_AUTH_USER']` and `$_SERVER['PHP_AUTH_PW']` from any incoming request and writing them to the `ai1wm_auth_header` option via `update_option()` as a reversible base64-encoded string, with no capability check, nonce verification, `is_user_logged_in()` check, or confirmation that Basic authentication actually succeeded. This makes it possible for unauthenticated attackers to capture into the database, in reversible base64 form, any WordPress Application Password or HTTP Basic credential presented to `/wp-admin/` by a legitimate integration, or to overwrite the stored credential with an attacker-chosen value by sending an anonymous request carrying a crafted `Authorization: Basic` header. This is particularly impactful in environments using WordPress Application Passwords for REST API or third-party integrations, as those credentials are transmitted as HTTP Basic auth to `/wp-admin/` and will be silently harvested via this unauthenticated write path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
