A high-severity flaw in the All-in-One WP Migration and Backup WordPress plugin, tracked as CVE-2026-19949, can let attackers trigger remote code execution by abusing a second-order SQL injection during archive restore operations. The issue affects versions up to 7.109, and with only 35% of installations updated to 7.110, about 3.2 million websites may still be vulnerable. #CVE-2026-19949 #All-in-OneWPMigrationandBackup
Keypoints
- CVE-2026-19949 is a high-severity flaw in All-in-One WP Migration and Backup.
- The vulnerability is a second-order SQL injection in the archive restore process.
- Attackers can abuse WordPress trackbacks to expose the secret restore key.
- The leaked key can be used to import a malicious .wpress archive and achieve RCE.
- Version 7.110 patches the flaw, but millions of sites remain unupdated.