CVE-2026-89064 | ServMask All-in-One WP Migration and Backup Plugin up to 7.110 on WordPress admin-ajax.php init PHP_AUTH_USER/PHP_AUTH_PW insufficiently protected credentials

SecurityVulns

A vulnerability was found in ServMask All-in-One WP Migration and Backup Plugin up to 7.110 on WordPress. It has been declared as critical. Affected by this issue is the function Ai1wm_Main_Controller::init of the file admin-ajax.php. Such manipulation of the argument PHP_AUTH_USER/PHP_AUTH_PW leads to insufficiently protected credentials.

This vulnerability is documented as CVE-2026-89064. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More