As reported by Bleeping Computer, a critical SQL injection vulnerability has been discovered in the popular All-in-One WP Migration and Backup plugin for WordPress, potentially allowing unauthenticated attackers to gain full control of affected websites.The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110. Attackers can exploit this by planting crafted data through WordPress trackbacks. This malicious data remains dormant until an administrator performs a common plugin operation, such as exporting or importing a site. During this process, the plugin incorrectly parses escaped backslashes and quotation marks, leading to the execution of injected SQL. This can expose the plugin's secret import key, allowing attackers to import a malicious archive containing executable code.With over five million active installations, a significant portion of WordPress sites remain vulnerable. The plugin's vendor, ServMask, released a patch in version 7.110, but only about 35% of users have updated, leaving millions of sites at risk.Source: Bleeping Computer
Vulnerability Management
SQL injection vulnerability in WordPress plugin affects millions of sites
(Credit: Bilal Ulker – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
