CVE-2026-6128 | ServMask All-in-One WP Migration Unlimited Extension Plugin settings cross site scripting

SecurityVulns

A vulnerability labeled as problematic has been found in ServMask All-in-One WP Migration Unlimited Extension Plugin up to 2.84 on WordPress. This issue affects the function Settings. Such manipulation of the argument ai1wm_backups_path leads to cross site scripting.

This vulnerability is documented as CVE-2026-6128. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More