All-in-One WP Migration flaw could put millions of WordPress sites at risk
CVE-2026-19949 affects versions up to 7.109 of the popular backup and migration plugin. An attack could escalate from SQL injection to remote code execution and a complete site takeover.
A vulnerability in All-in-One WP Migration and Backup, one of WordPress’s most popular plugins, could allow attackers to take control of vulnerable sites.
The flaw has been identified as CVE-2026-19949 and affects plugin versions up to 7.109. A fix was released in version 7.110.
The issue is particularly concerning because of its scale.
All-in-One WP Migration has more than 5 million active installations. At the beginning of September, approximately 35% of users had already updated, meaning around 3.25 million installations could still have been vulnerable at that time.
How the attack works
The vulnerability is a second-order SQL injection.
In practice, this means an attacker can insert malicious content into the database, but the attack does not necessarily happen right away.
The code remains stored.
The problem arises later, when an administrator uses the plugin to export or restore the site.
During this process, the malicious content can be interpreted as an SQL instruction.
In other words, a routine maintenance task could become the trigger for an attack.
According to the published analysis, manipulated data can be introduced through WordPress trackbacks and then executed during export and import operations.
From SQL injection to site takeover
The risk goes beyond access to the database.
Exploitation could allow an attacker to obtain a secret key used by the All-in-One WP Migration import process.
With this key, the attacker could import a malicious .wpress file containing executable code.
This turns the vulnerability into a remote code execution (RCE) scenario.
In practice, an attacker could execute code in the server environment and, depending on the available permissions, take complete control of the site.
From there, the attacker could alter pages, create administrative users, install backdoors, redirect visitors, or use the site to distribute malware.
The plugin has been patched
ServMask, the developer of All-in-One WP Migration, fixed the vulnerability in version 7.110, released in August.
Anyone using the plugin should therefore check the installed version immediately.
Versions 7.109 and earlier need to be updated.
But there is an important detail.
Updating the plugin fixes the vulnerability, but it does not automatically rule out the possibility that a site was compromised before the update.
For this reason, environments that remained vulnerable should also review logs, administrative users, recent changes to PHP files, unknown plugins, and unusual modifications within WordPress.
The problem goes beyond a single plugin
This case also highlights a recurring issue with WordPress.
A site’s security does not depend on WordPress Core alone.
It depends on the entire installed ecosystem:
WordPress + plugins + theme + server + PHP + database + settings + users.
Every plugin adds functionality, but it also adds a new dependency that needs to be updated, monitored, and maintained.
And a backup plugin deserves special attention.
Tools that can import, export, and restore databases and files have privileged access to the application.
They should therefore be treated as critical infrastructure components.
What to do now
Anyone using All-in-One WP Migration should take three immediate steps:
Update the plugin to version 7.110 or later.
Check the environment for signs of compromise.
Review the number of installed plugins and whether they are all necessary.
This incident reinforces a basic rule of digital security:
A site does not remain secure simply because it was secure when it was launched.
Security depends on ongoing maintenance, vulnerability monitoring, and regular updates to the technologies that support the operation.