< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

WordPress plugin flaw exposes millions of sites to takeover

A high-severity second-order SQL injection vulnerability, tracked as CVE-2026-19949, has been identified in the All-in-One WP Migration and Backup plugin for WordPress. The flaw affects versions 7.109 and earlier.

Discovered by security researcher Jack Taylor and reported via Wordfence, the vulnerability allows unauthenticated attackers to execute remote code. The attack involves planting malicious data through WordPress trackbacks, which remains dormant until an administrator performs a site export or restoration. During these operations, the plugin’s database rewriting process can trigger the injected SQL, potentially exposing the plugin’s secret import key. An attacker can then use this key to import a malicious archive and take complete control of the website.

While the developer, ServMask, released a patch in version 7.110, reports indicate that millions of sites remain at risk. Out of more than five million active installations, approximately 3.25 million sites were estimated to be running vulnerable versions as of early September.

Entities

All-in-One WP Migration and Backup · Jack Taylor · ServMask · WordPress · Wordfence

Claims

What the coverage asserts, and how many sources carry each claim.