What is CVE-2026-17533?
In All-in-One WP Migration and Backup WordPress plugin versions before 7.108, the migration import functionality on multisite installations is not restricted to network administrators. This allows a single subsite administrator to execute arbitrary PHP code across the entire network. Immediate update to version 7.108 or later is required.
Azərbaycanca: All-in-One WP Migration and Backup WordPress plugin-in 7.108-dən əvvəlki versiyalarında, multisite qurğularda miqrasiya idxalı funksionallığının yalnız şəbəkə administratorları ilə məhdudlaşdırılmaması boşluğu aşkar edilib. Bu, tək bir alt saytın administratoruna bütün şəbəkə üzrə ixtiyari PHP kodu icra etməyə imkan verir. Plugin-i dərhal 7.108 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the All-in-One WP Migration and Backup plugin are affected by CVE-2026-17533?
Versions before 7.108 are affected. An immediate update to version 7.108 or later is required.
What is the impact of CVE-2026-17533 on a multisite installation?
It allows a single subsite administrator to execute arbitrary PHP code across the entire network.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.