PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Aug 25, 2026

All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
7
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-12898
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
All-in-One WP Migration and Backup
AFFECTED< 7.106SAFE ✓≥ 7.106
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write CVE-2026-12898 Scanner | S4E