A high-severity vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup WordPress plugin poses a major risk to over 3 million websites, allowing remote code execution (RCE) attacks. The issue, described as a second-order SQL injection in the archive restore functionality, results from inadequate input escaping, enabling attackers to exploit the public post trackback feature to extract a secret key for malicious payloads. Despite a fix being released in version 7.110 on August 20, only 35% of installations have updated, leaving around 3.2 million sites vulnerable.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
CyberSIXT Evidence Panel
Article by CyberSIXT