WordPress · All-In-One Wp Migration/Backup · CVE-2026-17533
**Name of the Vulnerable Software and Affected Versions**
All-in-One WP Migration and Backup WordPress plugin versions prior to 7.108
**Description**
On multisite installations, the migration import functionality is not restricted to network administrators. This allows an administrator of a single subsite to execute arbitrary PHP code across the entire network. PHP is a server-side scripting language used primarily for web development.
**Recommendations**
Update the plugin to version 7.108 or later.