Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
A high-severity flaw in the All-in-One WP Migration and Backup WordPress plugin, tracked as CVE-2026-19949, can let attackers trigger remote code execution by abusing a second-order SQL injection during archive restore operations. The issue affects versions up to 7.109, and with only 35% of installations updated to 7.110, about 3.2 million websites may still be vulnerable. #CVE-2026-19949 #All-in-OneWPMigrationandBackup

Keypoints

  • CVE-2026-19949 is a high-severity flaw in All-in-One WP Migration and Backup.
  • The vulnerability is a second-order SQL injection in the archive restore process.
  • Attackers can abuse WordPress trackbacks to expose the secret restore key.
  • The leaked key can be used to import a malicious .wpress archive and achieve RCE.
  • Version 7.110 patches the flaw, but millions of sites remain unupdated.

Read More: https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/