
CVE-2026-18216 The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a … https://www.cve.org/CVERecord?id=CVE-2026-18216
Post summary
The statement announces a CVE for the Backup Migration WordPress plugin, identifying an authentication bypass in the post‑restore auto‑login feature.
