CVE-2026-18216: Unknown Backup Migration

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.

Affected products

  • Unknown Backup Migration: before 2.1.7 (fixed in 2.1.7)

Published 2026-08-15. Last modified 2026-08-26.