CVE-2026-17533: All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
All-in-One WP Migration and Backupto a version that resolves this vulnerability.Fixed in 7.108
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17533?
CVE-2026-17533 has a risk rating of 73, indicating a high severity level.
How do I fix CVE-2026-17533?
To fix CVE-2026-17533, update the All-in-One WP Migration and Backup plugin to version 7.108 or later.
Who is affected by CVE-2026-17533?
CVE-2026-17533 affects WordPress multisite installations where subsites can execute PHP code due to insufficient restriction in migration import functionality.
What can an attacker do with CVE-2026-17533?
An attacker exploiting CVE-2026-17533 can execute arbitrary PHP code across the entire WordPress multisite network.
Is there a workaround for CVE-2026-17533 before applying a patch?
Disabling the All-in-One WP Migration and Backup plugin temporarily can serve as a workaround until the plugin is updated.