SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12898

MEDIUM · CVSS 6.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The All-in-One WP Migration and Backup plugin for WordPress versions prior to 7.106 is vulnerable due to insufficient sanitization of user-supplied input, enabling unauthenticated attackers to create or append log files in unintended locations. This could lead to unauthorized access or data manipulation, posing a risk to the integrity of the affected WordPress installations. Website administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-12898
Severity
MEDIUM
CVSS
6.5
EPSS
0.31%
WordPress

Original NVD Description

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.