๐Ÿ” CVE Alert

CVE-2026-18216

UNKNOWN 0.0

Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.

Vendor unknown
Product backup migration
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for unknown backup migration

Be the first to know when new unknown vulnerabilities affecting unknown backup migration are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Backup Migration
0 < 2.1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/f12530c5-4069-42c2-9f1c-b00fc62aa387/

Credits

Thanh Lam Tang WPScan