S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-12898 Scanner

CVE-2026-12898 Scanner - Arbitrary Log File Write vulnerability in All-in-One WP Migration and Backup

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-12898
6.5
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage directory.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
All-in-One WP Migration and Backup
AFFECTED< 7.106SAFE ✓≥ 7.106
Updated Sep 9, 2026View on NVD →
Detail

The All-in-One WP Migration and Backup plugin is widely used by WordPress site administrators for site backups and migrations. Developed by ServMask, it provides a simple interface for migrating websites without needing technical knowledge. Its popularity stems from its ease of use, allowing users to export and import site data effortlessly. Due to its direct interaction with site files, maintaining security and updates is crucial for the plugin to function securely. The plugin plays a crucial role in data protection and site transfer functionalities. Regular updates and patches are essential to prevent vulnerabilities and ensure data safety.

The arbitrary log file write vulnerability allows attackers to write or append log files at arbitrary locations. It enables unauthenticated actors to exploit improper sanitization of user inputs in the file path construction. This flaw can lead to exposing sensitive information or providing a foothold for further attacks. By leveraging this vulnerability, attackers can create files in locations outside the intended directory. Such unauthorized file creation may cause information disclosure or privilege escalation. Recognizing and addressing this vulnerability is vital for maintaining security and operational integrity.

The vulnerability occurs due to improper handling of user-supplied inputs leading to log file path manipulation. Attackers can use crafted requests to append log files in directories not intended for storage. The 'action=ai1wm_export' parameter in requests is manipulated for this attack. Exploitation involves sending a crafted POST request to the 'admin-ajax.php' endpoint with malicious parameters. These parameters can bypass intended restrictions, leading to unauthorized locations for log file writes. The presence of such endpoints underscores the importance of input validation in web development practices.

If exploited, the vulnerability can lead to serious security issues. Attackers may expose sensitive logs, gaining insights into server configurations or application flows. The arbitrary log creation also risks overwriting or corrupting critical system or application files. This can lead to service disruption, data loss, or compromised site integrity. Unauthorized access to system information from these logs could facilitate further attacks. Organizations could face reputational damage and financial losses due to breaches exploiting this flaw.

REFERENCES

Solution Advice
  • Update the All-in-One WP Migration and Backup plugin to version 7.106 or later to patch this vulnerability.
  • Implement strict input validation to prevent unauthorized file access.
  • Regularly audit and monitor log files to detect any unauthorized changes.
  • Restrict permissions for directories to minimize exposure risk.
  • Conduct frequent security assessments of web applications and plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-12898 Scanner - Arbitrary Log File Write vulnerability in All-in-One WP Migration and Backup | S4E