What is CVE-2026-18216?
This vulnerability stems from the Backup Migration WordPress plugin before version 2.1.7 not properly restricting a post-restore automatic login mechanism. A user administering one site in a multisite network can obtain a long-lived administrator session on another site within the same network. The plugin must be updated immediately.
Azərbaycanca: Bu boşluq 2.1.7-dən əvvəlki Backup Migration WordPress pluginində post-bərpa avtomatik giriş mexanizminin düzgün məhdudlaşdırılmamasından qaynaqlanır. Multisite şəbəkədə bir saytı idarə edən istifadəçi, eyni şəbəkədəki başqa bir saytda administrator sessiyası əldə edə bilər. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the Backup Migration plugin are affected by CVE-2026-18216?
CVE-2026-18216 affects Backup Migration WordPress plugin versions prior to 2.1.7.
What can an attacker gain by exploiting CVE-2026-18216?
A user administering one site in a multisite network can obtain a long-lived administrator session on another site within the same network.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.