WordPress Plugin Vulnerabilities
All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
Description
The plugin does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
The affected user is not a network super administrator and is otherwise denied the ability to install plugins or themes, so this crosses the tenant separation boundary that multisite exists to enforce.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Mohamed Bassia
Submitter
Mohamed Bassia
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-14 (about 2 days ago)
Added
2026-08-14 (about 1 day ago)
Last Updated
2026-08-14 (about 1 day ago)