AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18216

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Backup Migration plugin for WordPress versions prior to 2.1.7 has a vulnerability that allows an administrator of one site in a multisite network to gain unauthorized long-lived access to another site’s admin account, bypassing credential checks and two-factor authentication. This poses a significant risk to the security of multisite networks, as it can lead to unauthorized administrative actions across multiple sites. WordPress administrators managing multisite installations should prioritize updating this plugin to mitigate potential exploitation.

CVE
CVE-2026-18216
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress

Original NVD Description

The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.