A Critical Vulnerability in a Popular WordPress Backup Plugin Exposes Millions of Sites to Takeover Attacks
A devastating security flaw has been discovered in the All-in-One WP Migration and Backup plugin, used by over 5 million WordPress websites. The vulnerability, tracked as CVE-2026-19949, allows unauthenticated attackers to execute remote code and take control of affected sites, compromising sensitive data and potentially leading to financial losses.
The issue lies in an SQL injection vulnerability that affects versions up to 7.109 of the plugin. In a nutshell, this means that when a malicious user submits crafted data through WordPress’s trackbacks feature, it can inject harmful SQL code into the database. This code is then executed when an administrator exports and imports a site using the plugin, allowing the attacker to obtain the secret import key (ai1wm_secret_key) and import a malicious archive containing executable code.
The scenario plays out as follows: an unauthenticated attacker plants crafted data through trackbacks, which remains dormant until an administrator restores a backup archive. This is a routine action for users of this plugin, making it a ticking time bomb waiting to unleash its full potential. The good news is that the vulnerability has been patched in version 7.110, released by ServMask on August 20.
However, the bad news is that only approximately 35% of the plugin’s user base has updated to the latest version, leaving a staggering 3.25 million sites vulnerable to takeover attacks. The numbers are daunting, and it’s essential for users to take immediate action to secure their sites.
This vulnerability highlights the importance of keeping software up-to-date, especially when it comes to critical plugins like backup and migration tools. It also underscores the need for users to be cautious when interacting with their websites, avoiding actions that could trigger the exploit. Administrators should review their plugin versions, update to the latest release, and ensure they are using secure import keys.
In light of this revelation, we urge all WordPress site owners to take a close look at their plugin configurations and update All-in-One WP Migration and Backup to version 7.110 or later. Remember that cybersecurity is an ongoing process, and vigilance is key to protecting your online assets. Don’t wait until it’s too late – secure your website today and avoid falling victim to these type of attacks.
Source: Bleeping Computer — 2026-09-02