CVE-2023-40004: Servmask All-In-One Wp Migration
High severity, CVSS 7.3. EPSS: 11% chance of exploitation in the next 30 days.
Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a through 1.53; All-in-One WP Migration OneDrive Extension: from n/a through 1.66; All-in-One WP Migration Dropbox Extension: from n/a through 3.75; All-in-One WP Migration Google Drive Extension: from n/a through 2.79.
Affected products
- Servmask All-In-One Wp Migration: version 1.54 only; version 2.80 only; version 1.67 only; version 3.76 only
- Servmask All-In-One Wp Migration Box Extension: up to and including 1.53
- Servmask All-In-One Wp Migration Dropbox Extension: up to and including 3.75
- Servmask All-In-One Wp Migration Google Drive Extension: up to and including 2.79
- Servmask All-In-One Wp Migration OneDrive Extension: up to and including 1.66
Published 2024-06-19. Last modified 2026-06-17.