S4E just found an informational finding from tcp full port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2022-2546

4.7
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.
Description

The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the response from the ai1wm_export AJAX action, allowing an attacker to craft a request that when submitted by any visitor will inject arbitrary html or javascript into the response that will be executed in the victims session. Note: This requires knowledge of a static secret key

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
all-in-one wp migration
Updated Sep 28, 2026View on NVD →
S4E scanner

CVE history: all-in-one wp migration

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →