CyberRota Analysis
AI-GeneratedThe Backup Migration plugin for WordPress versions prior to 2.1.7 has a vulnerability that allows an administrator of one site in a multisite network to gain unauthorized long-lived access to another site’s admin account, bypassing credential checks and two-factor authentication. This poses a significant risk to the security of multisite networks, as it can lead to unauthorized administrative actions across multiple sites. WordPress administrators managing multisite installations should prioritize updating this plugin to mitigate potential exploitation.
Original NVD Description
The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.