Vulnerability Description
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin_init` hook, which fires unauthenticated on `admin-ajax.php` and `admin-post.php` requests — reading `$_SERVER['PHP_AUTH_USER']` and `$_SERVER['PHP_AUTH_PW']` from any incoming request and writing them to the `ai1wm_auth_header` option via `update_option()` as a reversible base64-encoded string, with no capability check, nonce verification, `is_user_logged_in()` check, or confirmation that Basic authentication actually succeeded. This makes it possible for unauthenticated attackers to capture into the database, in reversible base64 form, any WordPress Application Password or HTTP Basic credential presented to `/wp-admin/` by a legitimate integration, or to overwrite the stored credential with an attacker-chosen value by sending an anonymous request carrying a crafted `Authorization: Basic` header. This is particularly impactful in environments using WordPress Application Passwords for REST API or third-party integrations, as those credentials are transmitted as HTTP Basic auth to `/wp-admin/` and will be silently harvested via this unauthenticated write path.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.110/li
- https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.110/li
- https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.110/li
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3696427%40all-in-one-
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5a8737b1-fb68-4609-847
FAQ
What is CVE-2026-89064?
CVE-2026-89064 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init...
How severe is CVE-2026-89064?
CVE-2026-89064 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-89064?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.