Impact
The Backup Migration WordPress plugin versions before 2.1.7 contain an authentication flaw that allows a user with administrative rights on one site within a multisite network to automatically obtain a long‑lived administrator session on any other site in the same network. The flaw bypasses standard credential verification and even two‑factor authentication, giving the attacker full control of the target site without having logged in personally. This constitutes a significant elevation of privilege that can be used to modify site data, install malware, or move laterally within the network.
Affected Systems
Backup Migration WordPress plugin for any site using a multisite installation. Versions lower than 2.1.7 are affected; versions 2.1.7 and later contain the fix.
Risk and Exploitability
The vulnerability is exploitable by any administrator who can trigger a restore on another site in the network; the attack path requires no additional credentials. The EPSS score is < 1% and the CVSS score of 6.5 indicates moderate severity, yet the potential for privilege escalation and 2FA bypass suggests a significant risk. The KEV catalog does not list this issue.
OpenCVE Enrichment