CVE-2026-17533
N/A
N/A
Summary
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | All-in-One WP Migration and Backup | 0 < 7.108 | affected |
Weaknesses
- CWE-269 Improper Privilege Management
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.