CVE-2026-18216
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.
| Vendor | unknown |
| Product | backup migration |
| Published | Aug 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown backup migration
Be the first to know when new unknown vulnerabilities affecting unknown backup migration are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Backup Migration
0 < 2.1.7
References
Credits
Thanh Lam Tang WPScan