Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
PoC publicAll-in-One WP Migration and BackupWordPressOur summary
Security firm Defiant has issued a warning regarding a high-severity flaw in the All-in-One WP Migration and Backup plugin, which leaves approximately 3.2 million WordPress sites exposed to remote code execution attacks. Identified as CVE-2026-19949 with a CVSS score of 8.8, this second-order SQL injection vulnerability resides in the archive restore feature due to inadequate input escaping.
An unauthenticated attacker can exploit this by submitting specific trackbacks that allow them to steal a secret key and subsequently upload a malicious plugin, resulting in full site compromise. The issue affects all versions prior to 7.110, so administrators should update their plugins to the latest release to mitigate the risk.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.