PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Nov 14, 2025

All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8852
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.86 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information such as full paths contained in the exposed log files.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
All-in-One WP Migration and Backupby servmask
0
all-in-one_wp_migrationby servmask
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure cve-2024-8852 Scanner | S4E