Answer in brief
CVE-2026-17533 records a High severity (CVSS 7.2) vulnerability in All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import. The current sources do not mark it as known exploited. The current feed maps Unknown/All-in-One WP Migration and Backup (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/All-in-One WP Migration and Backup (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/All-in-One WP Migration and Backupgeneric | >=0 <7.108 | 7.108 |
Published upstream
Aug 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 16, 2026
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, allowing an administrator of a single subsite to execute arbitrary PHP code across the entire network.
Quoted source text, attributed separately from HOL analysis.