All-in-One WP Migration plugin flaw puts 5 million WordPress sites at risk
A critical second-order SQL injection vulnerability, tracked as CVE-2026-19949, has been discovered in the All-in-One WP Migration and Backup plugin version 7.109 and earlier, affecting over 5 million WordPress installations. Attackers can inject malicious payloads through public input vectors like trackbacks, which remain dormant in the database until an administrator triggers a backup restore or import operation. Once activated, the exploit can expose the site's secret key, enabling unauthenticated attackers to upload a malicious archive and achieve remote code execution. Developer ServMask released version 7.110 on August 20, 2026, to patch the flaw, but only around 35% of active installations had updated at the time of reporting. No large-scale active exploitation has been confirmed yet, and administrators are urged to update immediately, rotate secret keys, and audit past restore activity and database changes.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in