A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin can let unauthenticated attackers achieve remote code execution and take over WordPress sites. The issue, tracked as CVE-2026-19949, affects versions through 7.109 and was fixed by ServMask in version 7.110 after disclosure by Wordfence and researcher Jack Taylor. #CVE-2026-19949 #All-in-OneWPMigrationandBackup #Wordfence #ServMask #JackTaylor
Keypoints
- The flaw is a second-order SQL injection in All-in-One WP Migration and Backup.
- It can lead to remote code execution and full website compromise.
- Attackers can plant crafted data through WordPress trackbacks.
- The exploit triggers when an administrator restores or imports a backup archive.
- ServMask fixed the issue in version 7.110, but many sites remain vulnerable.