Description
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
Published: 2026-08-16
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The All‑in‑One WP Migration and Backup plugin contains a flaw that allows a subsite administrator on a WordPress multisite network to import a migration file that executes arbitrary PHP code across the entire network. The import routine lacks a check that the user is a network administrator, so a subsite admin can run code with the privileges of the network. This vulnerability can compromise confidentiality, integrity, and availability of all sites in the network.

Affected Systems

WordPress sites running All‑in‑One WP Migration and Backup plugin version prior to 7.108 on a multisite setup. Anyone who can create or manage a subsite – typically a subsite administrator – can exploit the issue. Network‑wide administrators are unaffected directly, but the vulnerability can be leveraged to compromise them as well once the network is at risk.

Risk and Exploitability

The flaw enables remote code execution using only subsite administrator privileges, which are commonly granted in multisite environments. An attacker can craft a malicious migration file and trigger the import endpoint from any subsite. No EPSS score is provided and the vulnerability is not listed in the CISA KEV catalog, yet the limited privilege requirement lowers the barrier to exploitation and increases impact risk.

Generated by OpenCVE AI on August 16, 2026 at 07:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the All‑in‑One WP Migration and Backup plugin to version 7.108 or newer, which enforces a network‑administrator check on the import functionality.
  • Restrict access to the migration/import feature so that only network administrators can use it; remove or disable the import capability for subsite administrators.
  • Uninstall or disconnect the plugin from subsites that do not need migration features to eliminate the attack surface.

Generated by OpenCVE AI on August 16, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
Title All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-16T06:00:15.315Z

Reserved: 2026-07-27T09:11:40.271Z

Link: CVE-2026-17533

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T06:16:51.340

Modified: 2026-08-16T06:16:51.340

Link: CVE-2026-17533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T08:00:10Z

Weaknesses

No weakness.