Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gentlemen Ransomware Disables EDR, Backups Before Network Encryption
September 3, 2026
Microsoft Teams, Outlook Crash on ARM After August Updates
September 3, 2026
Critical Sangoma Switchvox RCE Vulnerability Actively Exploited
September 3, 2026
Home/CyberSecurity News/Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection
CyberSecurity News

Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection

Key Takeaways A severe SQL injection vulnerability (CVE-2026-19949) affects the popular All-in-One WP Migration and Backup plugin. Over 5 million WordPress sites are potentially exposed to...

Emy Elsamnoudy
Emy Elsamnoudy
September 3, 2026 3 Min Read
4 0

Key Takeaways

  • A severe SQL injection vulnerability (CVE-2026-19949) affects the popular All-in-One WP Migration and Backup plugin.
  • Over 5 million WordPress sites are potentially exposed to unauthenticated remote code execution.
  • The flaw leverages a “second-order” SQL injection, requiring an administrator to perform a site export and subsequent import after an initial malicious trackback injection.
  • The vulnerability has been patched in plugin version 7.110.

Critical Flaw in All-in-One WP Migration Exposes Millions of WordPress Sites

A high-severity security vulnerability within the widely used All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to fully compromise over 5 million WordPress websites. The flaw, identified as CVE-2026-19949, poses a significant risk of SQL injection leading to remote code execution.

Table Of Content

  • Key Takeaways
  • Critical Flaw in All-in-One WP Migration Exposes Millions of WordPress Sites
  • Understanding the All-in-One WP Migration Plugin
  • The Second-Order SQL Injection Mechanism
  • What You Should Do

The vulnerability was brought to light on August 14, 2026, by security researcher Jack Taylor, who reported it to Wordfence through their Bug Bounty Program. Taylor was awarded $5,761 for his discovery. The issue has been assigned a CVSS score of 8.8, indicating its critical nature.

Understanding the All-in-One WP Migration Plugin

The All-in-One WP Migration and Backup plugin is a staple for WordPress administrators, facilitating essential tasks such as exporting, importing, restoring, and migrating entire WordPress sites. It functions by creating proprietary .wpress archive files that encapsulate all website files and database information.

Versions of the plugin up to and including 7.109 are susceptible to an unauthenticated second-order SQL injection vulnerability during the archive restoration process.

The Second-Order SQL Injection Mechanism

Unlike conventional SQL injection attacks where malicious code executes immediately, this flaw involves a two-stage process. Attackers first embed a specially crafted payload into a WordPress site via the core trackback feature. This initial step does not require authentication, provided the public post allows pings. The malicious trackback data, disguised as an ordinary comment, is then stored in the WordPress comments table, remaining dormant.

The attack escalates when a site administrator exports the website using the vulnerable plugin and subsequently restores it. During the restoration, the All-in-One WP Migration plugin processes and rewrites URLs and database table prefixes within SQL statements before importing them into the database.

According to a Wordfence report, a defect in the plugin’s regular expression handling of backslashes and quoted strings allows the stored malicious payload to break free from its intended SQL string boundary. This critical flaw enables the attacker-controlled content to become executable SQL during the database import phase.

The injected SQL can then be leveraged to extract the plugin’s ai1wm_secret_key. This secret key is vital for protecting the plugin’s unauthenticated import function. Once retrieved, an attacker can leak this key into an approved comment and access it through the site’s public WordPress REST API.

Possessing the secret key grants the attacker access to the plugin’s import process, enabling them to upload a malicious .wpress archive. Such an archive could contain a malicious WordPress “must-use” plugin. Since must-use plugins load automatically, the embedded malicious code would execute whenever a visitor or administrator accesses any page on the site.

This chain of events culminates in remote code execution on the server, potentially leading to a full site compromise. Attackers could deploy webshells, exfiltrate sensitive data, or install additional malware, gaining complete control over the affected WordPress installation.

While the exploit does require an administrator to perform an export and then an import after the malicious trackbacks are planted, these backup and restore operations are routine for many WordPress administrators, making the attack feasible.

Wordfence implemented a firewall rule for its Premium, Care, and Response users on August 16, 2026, with free Wordfence users slated to receive protection on September 15, 2026. ServMask, the plugin vendor, acknowledged the report on August 17 and promptly released version 7.110, containing the fix, on August 20.

What You Should Do

  • Update Immediately: Ensure your All-in-One WP Migration and Backup plugin is updated to version 7.110 or higher.
  • Disable Trackbacks: Consider disabling trackbacks on your WordPress site if they are not essential, especially on public posts.
  • Review Comments: Regularly review and moderate comments for any suspicious content or unusual URLs.
  • Security Audits: Verify that no unauthorized plugins or administrator accounts have been added to your site.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwareSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users

Next Post

Critical Sangoma Switchvox RCE Vulnerability Actively Exploited

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Cisco Nexus 9000 Switches Flaw Lets Remote Attackers Run Code
September 3, 2026
CISA Warns of Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited
September 3, 2026
Critical CrowdStrike Falcon Vulnerability Lets Attackers Escalate Privileges
September 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us