SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17533

HIGH · CVSS 7.2 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The All-in-One WP Migration and Backup plugin for WordPress prior to version 7.108 is vulnerable due to insufficient restrictions on its migration import functionality in multisite installations. This flaw allows an administrator of a single subsite to execute arbitrary PHP code, potentially compromising the entire network. WordPress multisite administrators and users of the affected plugin should prioritize updating to mitigate the risk of network-wide exploitation.

CVE
CVE-2026-17533
Severity
HIGH
CVSS
7.2
EPSS
0.32%
WordPress

Original NVD Description

The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.