started · updated
WordPress plugin flaw exposes millions of sites to takeover
A high-severity second-order SQL injection vulnerability, tracked as CVE-2026-19949, has been identified in the All-in-One WP Migration and Backup plugin for WordPress. The flaw affects versions 7.109 and earlier.
Discovered by security researcher Jack Taylor and reported via Wordfence, the vulnerability allows unauthenticated attackers to execute remote code. The attack involves planting malicious data through WordPress trackbacks, which remains dormant until an administrator performs a site export or restoration. During these operations, the plugin’s database rewriting process can trigger the injected SQL, potentially exposing the plugin’s secret import key. An attacker can then use this key to import a malicious archive and take complete control of the website.
While the developer, ServMask, released a patch in version 7.110, reports indicate that millions of sites remain at risk. Out of more than five million active installations, approximately 3.25 million sites were estimated to be running vulnerable versions as of early September.
Entities
All-in-One WP Migration and Backup · Jack Taylor · ServMask · WordPress · Wordfence
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] CVE-2026-19949 is a second-order SQL injection vulnerability affecting All-in-One WP Migration and Backup versions through 7.109. cybernoz.com · www.it-daily.net · www.esecurityplanet.com · dev.to
- [● 2 SOURCES] The All-in-One WP Migration and Backup plugin has over five million active installations. cybernoz.com · dev.to
- [● 3 SOURCES] Unauthenticated attackers can plant malicious data via WordPress trackbacks to trigger the exploit during an administrator's archive restoration. cybernoz.com · www.it-daily.net · dev.to
- [● 2 SOURCES] Security researcher Jack Taylor discovered the vulnerability and reported it through Wordfence. cybernoz.com · www.esecurityplanet.com
- [● 2 SOURCES] Approximately 3.25 million sites were still running vulnerable versions of the plugin as of early September. cybernoz.com · www.esecurityplanet.com
- [● 3 SOURCES] The SQL injection can expose the plugin’s secret import key, allowing attackers to import malicious archives and execute remote code. cybernoz.com · www.esecurityplanet.com · dev.to
- [● 2 SOURCES] The developer, ServMask, released a patch in version 7.110 to address the vulnerability. www.esecurityplanet.com · dev.to