CVE-2026-17533

The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-16 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-17533

Mitre link : CVE-2026-17533

CVE.ORG link : CVE-2026-17533


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management