PT-2026-72165 · WordPress · Backup Migration
CVE-2026-18216
·
Published
2026-08-15
·
Updated
2026-08-15
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Backup Migration WordPress plugin versions prior to 2.1.7
Description
An issue exists in the post-restore automatic login mechanism that lacks proper restrictions. This allows a user with administrator privileges on one site within a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network. This process occurs without requiring credentials and bypasses two-factor authentication.
Recommendations
Update Backup Migration WordPress plugin to version 2.1.7 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backup Migration