www.securityweek.com 9/3/2026, 11:11:00 AM · external

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A high-severity vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup WordPress plugin poses a major risk to over 3 million websites, allowing remote code execution (RCE) attacks. The issue, described as a second-order SQL injection in the archive restore functionality, results from inadequate input escaping, enabling attackers to exploit the public post trackback feature to extract a secret key for malicious payloads. Despite a fix being released in version 7.110 on August 20, only 35% of installations have updated, leaving around 3.2 million sites vulnerable.

View full article

Article by CyberSIXT