CVE-2026-41558: WordPress WP Migration Plugin DB & Files – WP Synchro plugin <= 1.16.1 - 2FA Bypass vulnerability
Published Oct 6, 2026
·Updated
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
Affected Software
1 affected component
WP Synchro WP Migration Plugin DB & Files<=1.16.1
Event History
Oct 6, 2026
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Installations using WP Synchro WP Migration Plugin DB & Files version 1.16.1 or earlier are affected.
2
What access does an attacker need?
The vulnerability is described as a subscriber bypass issue, and the CVSS vector indicates that an attacker needs low-level privileges. No user interaction is required.
3
Can this be exploited remotely?
The CVSS vector indicates network-based attack access, meaning exploitation can be attempted remotely by an attacker with the required low-level privileges.