WordPress Plugin Vulnerabilities

Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login

Description

The plugin does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.

Proof of Concept

Affects Plugins

Fixed in 2.1.7

References

Classification

Miscellaneous

Original Researcher
Thanh Lam Tang
Submitter
Thanh Lam Tang
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-13 (about 2 days ago)
Added
2026-08-13 (about 1 day ago)
Last Updated
2026-08-13 (about 1 day ago)

Other