WordPress backup plugin flaw exposes millions of sites to takeover attacks

WordPress backup plugin flaw exposes millions of sites to takeover attacks
A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin can let unauthenticated attackers achieve remote code execution and take over WordPress sites. The issue, tracked as CVE-2026-19949, affects versions through 7.109 and was fixed by ServMask in version 7.110 after disclosure by Wordfence and researcher Jack Taylor. #CVE-2026-19949 #All-in-OneWPMigrationandBackup #Wordfence #ServMask #JackTaylor

Keypoints

  • The flaw is a second-order SQL injection in All-in-One WP Migration and Backup.
  • It can lead to remote code execution and full website compromise.
  • Attackers can plant crafted data through WordPress trackbacks.
  • The exploit triggers when an administrator restores or imports a backup archive.
  • ServMask fixed the issue in version 7.110, but many sites remain vulnerable.

Read More: https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/