Vulnerability Management

SQL injection vulnerability in WordPress plugin affects millions of sites

(Credit: Bilal Ulker – stock.adobe.com)

As reported by Bleeping Computer, a critical SQL injection vulnerability has been discovered in the popular All-in-One WP Migration and Backup plugin for WordPress, potentially allowing unauthenticated attackers to gain full control of affected websites.

The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110. Attackers can exploit this by planting crafted data through WordPress trackbacks. This malicious data remains dormant until an administrator performs a common plugin operation, such as exporting or importing a site. During this process, the plugin incorrectly parses escaped backslashes and quotation marks, leading to the execution of injected SQL. This can expose the plugin's secret import key, allowing attackers to import a malicious archive containing executable code.

With over five million active installations, a significant portion of WordPress sites remain vulnerable. The plugin's vendor, ServMask, released a patch in version 7.110, but only about 35% of users have updated, leaving millions of sites at risk.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds