Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

WordPress Backup Plugin Flaw Exposes 3.25 Million Sites

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could let unauthenticated attackers execute remote code and take complete control of affected websites.

Tracked as CVE-2026-19949, the high-severity flaw affects plugin versions through 7.109. Security researcher Jack Taylor discovered the issue and reported it through Wordfence, Defiant’s cybersecurity branch, in mid-August.

Wordfence described the vulnerability as a second-order SQL injection caused by incorrect parsing of escaped backslashes and quotation marks while the plugin rewrites database content during archive restoration. An attacker could plant crafted data through WordPress trackbacks. When an administrator exports and imports the site, the injected SQL could expose the plugin’s secret import key, ai1wm_secret_key, through a public comment.

Attackers could then use the key to import a malicious .wpress archive containing executable code. The payload remains dormant until an administrator restores a backup archive.

The plugin has more than five million active installations, according to WordPress.org. About 35% of users had updated after the fix, leaving approximately 3.25 million sites on a vulnerable release. Developer ServMask addressed the issue in version 7.110 on August 20.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.