V-Help
← All news
Security

Critical WordPress Plugin Vulnerability Threatens Millions of Sites

Critical WordPress Plugin Vulnerability Threatens Millions of Sites

Photo: BleepingComputer

Quick answer

A critical SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin for WordPress allows attackers to take over sites by exploiting improper input handling during database…

A critical SQL injection vulnerability has been identified in the popular WordPress plugin All-in-One WP Migration and Backup, allowing attackers to fully compromise websites. Tracked as CVE-2026-19949, the flaw was discovered by security researcher Jack Taylor and has been rated as high severity.

The issue stems from improper handling of escaped characters and quotes during database restoration from archives. Attackers can inject malicious SQL code via WordPress trackbacks, which executes when an administrator restores a backup. This grants the attacker access to the plugin's import secret key (ai1wm_secret_key), enabling the upload of a malicious archive containing executable code.

According to WordPress.org, the plugin is installed on over 5 million sites. However, only 35% of users have updated to the secure version 7.110, released by ServMask on August 20. The remaining 3.25 million sites remain vulnerable to attacks. Experts warn that even deactivated vulnerable versions can be exploited if temporarily reactivated.

Developers urge all users to immediately update the plugin to the latest version and avoid restoring backups from untrusted sources. The vulnerability was addressed after Wordfence specialists confirmed Taylor's findings and reported it to ServMask.

Common questions

What vulnerability has been found in the All-in-One WP Migration and Backup plugin?
A critical SQL injection flaw (CVE-2026-19949) has been discovered, enabling unauthorized attackers to execute arbitrary code and take control of WordPress sites.
Which plugin versions are affected by this vulnerability?
Versions of All-in-One WP Migration and Backup up to and including 7.109 are vulnerable. A patch is available in version 7.110.
How can I protect my site from this vulnerability?
Update the plugin to the latest version (7.110 or later) and avoid restoring backups from untrusted sources.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer