Impact
The All‑in‑One WP Migration and Backup plugin contains a flaw that allows a subsite administrator on a WordPress multisite network to import a migration file that executes arbitrary PHP code across the entire network. The import routine lacks a check that the user is a network administrator, so a subsite admin can run code with the privileges of the network. This vulnerability can compromise confidentiality, integrity, and availability of all sites in the network.
Affected Systems
WordPress sites running All‑in‑One WP Migration and Backup plugin version prior to 7.108 on a multisite setup. Anyone who can create or manage a subsite – typically a subsite administrator – can exploit the issue. Network‑wide administrators are unaffected directly, but the vulnerability can be leveraged to compromise them as well once the network is at risk.
Risk and Exploitability
The flaw enables remote code execution using only subsite administrator privileges, which are commonly granted in multisite environments. An attacker can craft a malicious migration file and trigger the import endpoint from any subsite. No EPSS score is provided and the vulnerability is not listed in the CISA KEV catalog, yet the limited privilege requirement lowers the barrier to exploitation and increases impact risk.
OpenCVE Enrichment