CVE Tools

WordPress backup plugin flaw exposes millions of sites to takeover attacks

BleepingComputerBy Bill Toulas

PatchWordPressAll-in-One WP Migration and Backup

Our summary

ServMask has released version 7.110 of the All-in-One WP Migration and Backup plugin to fix a high-severity second-order SQL injection vulnerability identified as CVE-2026-19949. Discovered by researcher Jack Taylor and reported via Wordfence, this flaw affects versions through 7.109 and enables unauthenticated attackers to inject malicious code through WordPress trackbacks. The payload executes only when an administrator performs a backup or restore operation, potentially exposing secret keys and allowing full site takeover via a compromised archive. With over five million active installations, approximately 35% of users have already updated, leaving roughly 3.25 million sites still vulnerable.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store