CVE Tools

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

SecurityWeekBy Ionut Arghire

PoC publicAll-in-One WP Migration and BackupWordPress

Our summary

Security firm Defiant has issued a warning regarding a high-severity flaw in the All-in-One WP Migration and Backup plugin, which leaves approximately 3.2 million WordPress sites exposed to remote code execution attacks. Identified as CVE-2026-19949 with a CVSS score of 8.8, this second-order SQL injection vulnerability resides in the archive restore feature due to inadequate input escaping.

An unauthenticated attacker can exploit this by submitting specific trackbacks that allow them to steal a secret key and subsequently upload a malicious plugin, resulting in full site compromise. The issue affects all versions prior to 7.110, so administrators should update their plugins to the latest release to mitigate the risk.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store