A critical SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take complete control of vulnerable websites.
The popular WordPress plugin is designed to back up, export, import, and migrate entire websites—including databases, media files, themes, and plugins—between servers or domains.
Tracked as CVE-2026-19949, the vulnerability has received a High severity rating. Security researcher Jack Taylor discovered the flaw and reported it through Defiant’s Wordfence cybersecurity division in mid-August.
In a report published yesterday, Wordfence researchers said CVE-2026-19949 is a second-order SQL injection vulnerability affecting All-in-One WP Migration and Backup versions up to and including 7.109.
The flaw occurs because escaped backslashes and quotation marks are not correctly parsed when the plugin rewrites database contents while restoring an archive.
An unauthenticated attacker can inject specially crafted data through a WordPress trackback. The malicious data is triggered when an administrator exports and imports the website, a routine operation for users of the plugin.
The injected SQL can expose the plugin’s secret import key, ai1wm_secret_key, through public comments. Attackers who obtain this key can then import a malicious .wpress archive containing executable code.
According to Wordfence, executing code with these privileges could allow an attacker to gain complete control of the affected WordPress website.
According to WordPress.org statistics, All-in-One WP Migration and Backup has more than 5 million active installations.
Although the vendor has released a security update, only about 35% of users have upgraded to the latest version. As a result, approximately 3.25 million websites may still be running a vulnerable release of All-in-One WP Migration and Backup.

Source: BleepingComputer
Exploitation requires an administrator action
The malicious payload remains dormant until an administrator restores a backup archive. During the restoration process, the plugin processes SQL string boundaries and executes the stored data as SQL commands.
Although this requirement reduces the immediate risk of exploitation, Wordfence noted that administrators are expected to use the plugin’s backup and restore features regularly because they are its core functions.
“Since backup and restore is the core purpose of this plugin, this is a routine action, but the inserted SQL will not be executed until it is executed,” Wordfence said.
Researchers added that deactivating a vulnerable version of the plugin can reduce the risk. However, temporarily reactivating it for a migration or restoration could still expose the website to exploitation.
After reviewing Taylor’s findings, Wordfence disclosed the vulnerability to ServMask, the developer of All-in-One WP Migration and Backup, on August 15.
ServMask fixed CVE-2026-19949 in version 7.110, released on August 20. WordPress administrators should update the plugin immediately and review their websites for signs of unauthorized changes.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



