Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18216— Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login

Quick assessment

Affected
Unknown Backup Migration
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Backup Migration WordPress 插件版本低于 2.1.7 的版本中,存在一个恢复后自动登录机制未能正确限制的问题。这使得一名管理多站点网络中某个站点的用户,可以在不提供凭证的情况下,绕过双因素认证,获得作为该网络中另一站点管理员的长期认证会话。

AI Predicted 7.5 Difficulty: Easy EPSS 0.51% · P41

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Backup Migration < 2.1.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18216

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login
Source: CVE Program / CVE List V5
Vulnerability Description
The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Backup Migration 0 ~ 2.1.7 -

II. Public POCs for CVE-2026-18216

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18216

请登录查看更多情报信息。

Vendor Pages for CVE-2026-18216 (1)

Same Patch Batch · Unknown · 2026-08-15 · 6 CVEs total

CVE-2026-14230 ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
CVE-2026-14229 ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
CVE-2026-16541 Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users an
CVE-2026-16611 Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
CVE-2026-18807 ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynam

IV. Related Vulnerabilities

V. Comments for CVE-2026-18216

No comments yet


Leave a comment