CVE-2025-8490 Overview
CVE-2025-8490 is a stored Cross-Site Scripting (XSS) vulnerability in the All-in-One WP Migration and Backup plugin for WordPress. The flaw affects all versions up to and including 7.97. It stems from insufficient input sanitization and output escaping in the plugin's Import functionality.
Authenticated attackers with administrator-level access can inject arbitrary web scripts into pages. Those scripts execute when other users view the injected pages. The vulnerability only impacts WordPress multi-site installations and installations where the unfiltered_html capability has been disabled.
Critical Impact
Authenticated administrators on multi-site WordPress deployments can inject persistent JavaScript that executes in the browsers of other privileged users, enabling session theft and further compromise.
Affected Products
- All-in-One WP Migration and Backup plugin for WordPress, all versions through 7.97
- WordPress multi-site installations running the affected plugin
- WordPress installations where the unfiltered_html capability has been disabled
Discovery Timeline
- 2025-08-27 - CVE CVE-2025-8490 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8490
Vulnerability Analysis
The vulnerability is a stored XSS flaw categorized under [CWE-79]. It resides in the plugin's Import controller, specifically in logic exposed through lib/controller/class-ai1wm-import-controller.php. The controller processes user-supplied import data without applying WordPress sanitization helpers such as wp_kses or esc_html before persisting content that is later rendered in page context.
Exploitation requires authenticated access with administrator-level privileges. The attack surface is further restricted to multi-site installations or environments where unfiltered_html has been removed from the administrator role. In standard single-site WordPress installations, administrators already possess the unfiltered_html capability, so the injection is not considered a privilege boundary crossing.
Successful exploitation delivers persistent JavaScript to any user who loads an affected page. Attackers can pivot to session hijacking, forced administrative actions via CSRF-like flows, or delivery of second-stage payloads to super-admin accounts.
Root Cause
The root cause is missing input sanitization on data ingested through the Import routine and missing output escaping when that data is later rendered in the page body. WordPress provides sanitize_text_field, wp_kses_post, and esc_attr helpers to prevent script injection, and the affected controller does not consistently apply them to imported content.
Attack Vector
The attack vector is network-based and requires high privileges plus a susceptible configuration. An authenticated administrator on a WordPress multi-site network uses the plugin's Import feature to submit a crafted archive or payload containing JavaScript inside page or post content. The payload is stored in the database and executes in the browser of any user who subsequently views the injected page, including super admins.
No verified public exploit code is available for this issue. Technical details are documented in the WordPress plugin code review and the Wordfence vulnerability report.
Detection Methods for CVE-2025-8490
Indicators of Compromise
- Unexpected <script>, onerror, or onload attributes present in wp_posts content for pages or posts created after an import operation.
- Recent invocations of the All-in-One WP Migration Import feature by administrator accounts without a corresponding change-management ticket.
- Outbound requests from admin browsers to unfamiliar domains shortly after loading a WordPress page.
Detection Strategies
- Review the plugin's import logs and WordPress audit logs for import events performed by administrator or super-admin accounts.
- Query the wp_posts table across all subsites for content containing common XSS markers such as <script, javascript:, or event handler attributes.
- Compare installed plugin versions across the multi-site network against the fixed release to identify hosts still exposed.
Monitoring Recommendations
- Enable WordPress activity logging for plugin installations, updates, and Import operations on all subsites.
- Alert on administrator sessions originating from new geolocations or user agents, which may indicate credential compromise preceding exploitation.
- Monitor web server logs for anomalous POST requests to admin-ajax.php or plugin endpoints associated with ai1wm.
How to Mitigate CVE-2025-8490
Immediate Actions Required
- Update the All-in-One WP Migration and Backup plugin to a version above 7.97 on every site in the network.
- Audit administrator and super-admin accounts and reset credentials that show signs of unauthorized use.
- Inspect all pages and posts imported since the plugin was installed for embedded scripts and remove injected content.
Patch Information
The vulnerability affects all plugin versions through 7.97. Site operators should install the vendor-supplied fixed release available through the WordPress plugin repository. Confirm the update on each subsite in a multi-site network, since plugin state can vary per site.
Workarounds
- Restrict Import functionality to a minimal set of trusted super-admin accounts and enforce multi-factor authentication on those accounts.
- Restore the unfiltered_html capability for trusted administrators on non-multi-site installations if the plugin cannot be updated immediately, understanding this reduces defense in depth.
- Deploy a web application firewall rule to block requests containing script tags in the plugin's import parameters.
# Configuration example: verify installed plugin version via WP-CLI
wp plugin get all-in-one-wp-migration --field=version
wp plugin update all-in-one-wp-migration
# Multi-site: verify across all sites
wp site list --field=url | xargs -I {} wp --url={} plugin get all-in-one-wp-migration --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.