Junglewise Threat Intelligence

CVE-2026-5753: ServMask All-in-One WP Migration Unlimited Extension missing authorization

CVE-2026-5753 · Severity: medium · CVSS 6.5 · Published 2026-05-06

Vendors: ServMask.

Executive brief

A vulnerability in a popular WordPress migration and backup plugin allows low-level users, such as subscribers, to gain unauthorized access to full website backups. By manipulating the plugin's scheduling feature, an attacker can trigger a backup and have the download link sent to their own email address. This could lead to the theft of sensitive site data, including customer information and configuration files.

Technical details

The All-in-One WP Migration Unlimited Extension plugin for WordPress fails to perform adequate capability checks in the 'Ai1wmve_Schedules_Controller::save' handler. This missing authorization vulnerability allows authenticated attackers with subscriber-level permissions or higher to submit malicious requests to the 'admin_post_ai1wm_schedule_event_save' action. Attackers can create new scheduled export jobs and configure the notification email to an address they control. Because the resulting email notifications contain the randomized filename of the backup, the attacker can then download the complete site backup directly from the server. The issue is addressed in version 2.84.

Affected products

  • ServMask All-in-One WP Migration Unlimited Extension up to, and including, 2.83

Timeline

  • 2026-03-16: patched: Version 2.84 released to address permission issues.
  • 2026-05-06: disclosed: Initial disclosure by Wordfence.
  • 2026-05-06: advisory: NVD published the CVE record.

References

Related threats