WordPress Plugin Vulnerabilities

All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import

Description

The plugin does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.

The affected user is not a network super administrator and is otherwise denied the ability to install plugins or themes, so this crosses the tenant separation boundary that multisite exists to enforce.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Mohamed Bassia
Submitter
Mohamed Bassia
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-14 (about 2 days ago)
Added
2026-08-14 (about 1 day ago)
Last Updated
2026-08-14 (about 1 day ago)

Other