WordPress Plugin Vulnerabilities
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
Description
The plugin does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
AUTHBYPASS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Thanh Lam Tang
Submitter
Thanh Lam Tang
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-13 (about 2 days ago)
Added
2026-08-13 (about 1 day ago)
Last Updated
2026-08-13 (about 1 day ago)