PT-2026-73119 · WordPress · All-In-One Wp Migration/Backup

·

CVE-2026-17533

·

Published

2026-08-16

·

Updated

2026-08-16

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions All-in-One WP Migration and Backup WordPress plugin versions prior to 7.108
Description On multisite installations, the migration import functionality is not restricted to network administrators. This allows an administrator of a single subsite to execute arbitrary PHP code across the entire network. PHP is a server-side scripting language used primarily for web development.
Recommendations Update the plugin to version 7.108 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17533

Affected Products

All-In-One Wp Migration/Backup