WordPress backup plugin flaw exposes millions of sites to takeover attacks
PatchWordPressAll-in-One WP Migration and BackupOur summary
ServMask has released version 7.110 of the All-in-One WP Migration and Backup plugin to fix a high-severity second-order SQL injection vulnerability identified as CVE-2026-19949. Discovered by researcher Jack Taylor and reported via Wordfence, this flaw affects versions through 7.109 and enables unauthenticated attackers to inject malicious code through WordPress trackbacks. The payload executes only when an administrator performs a backup or restore operation, potentially exposing secret keys and allowing full site takeover via a compromised archive. With over five million active installations, approximately 35% of users have already updated, leaving roughly 3.25 million sites still vulnerable.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.