CVE-2026-81810: CWE-269 Improper Privilege Management in All-in-One WP Migration and Backup
The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the export capability to a role that does not hold the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability, which is not a default configuration.
AI Analysis
Technical Summary
CVE-2026-81810 is an improper privilege management vulnerability (CWE-269) in the All-in-One WP Migration and Backup WordPress plugin prior to version 7.111. The plugin fails to perform capability checks on several AJAX actions, instead gating them only by an installation-wide secret. This secret is disclosed to any user permitted to export the site. If an administrator has granted the export capability to a role that does not have the import capability, such a user can import arbitrary site archives, potentially gaining administrator access. The vulnerability depends on a non-default configuration of user capabilities.
Potential Impact
An attacker with export capability but without import capability can exploit this vulnerability to import arbitrary site archives and escalate privileges to administrator level. This could lead to full site compromise. However, exploitation requires a specific, non-default capability assignment by an administrator, limiting the exposure.
Mitigation Recommendations
Upgrade the All-in-One WP Migration and Backup plugin to version 7.111 or later, where this vulnerability is fixed. Until then, ensure that the export capability is not granted to roles lacking the import capability to prevent exploitation.
CVE-2026-81810: CWE-269 Improper Privilege Management in All-in-One WP Migration and Backup
Description
The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the export capability to a role that does not hold the All-in-One WP Migration and Backup WordPress plugin before 7.111's own import capability, which is not a default configuration.
CVSS v3.1
Score 7.2high
Affected software
All-in-One WP Migration and Backup
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-81810 is an improper privilege management vulnerability (CWE-269) in the All-in-One WP Migration and Backup WordPress plugin prior to version 7.111. The plugin fails to perform capability checks on several AJAX actions, instead gating them only by an installation-wide secret. This secret is disclosed to any user permitted to export the site. If an administrator has granted the export capability to a role that does not have the import capability, such a user can import arbitrary site archives, potentially gaining administrator access. The vulnerability depends on a non-default configuration of user capabilities.
Potential Impact
An attacker with export capability but without import capability can exploit this vulnerability to import arbitrary site archives and escalate privileges to administrator level. This could lead to full site compromise. However, exploitation requires a specific, non-default capability assignment by an administrator, limiting the exposure.
Mitigation Recommendations
Upgrade the All-in-One WP Migration and Backup plugin to version 7.111 or later, where this vulnerability is fixed. Until then, ensure that the export capability is not granted to roles lacking the import capability to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-27T12:32:40.032Z
- State
- PUBLISHED
Threat ID: 6aacd5a155bf5e2cf5955f13
Added to database: 09/18/2026, 06:09:37 UTC
Last enriched: 09/18/2026, 06:31:31 UTC
Last updated: 09/18/2026, 23:09:03 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.