Millions of WordPress websites are at risk of being taken over by hackers due to a serious vulnerability in a popular backup plugin. The issue, discovered by security researcher Jack Taylor, allows attackers to execute malicious code and gain control of affected sites.
The All-in-One WP Migration and Backup plugin is used by more than five million WordPress users to back up, export, import, and move their websites between servers or domains. However, versions 7.109 and below contain a second-order SQL injection vulnerability that can be exploited even without authentication. This means that an attacker can plant malicious data through a WordPress trackback, which will execute when an administrator exports and imports the site.
The injected SQL code can expose the plugin’s secret import key (ai1wm_secret_key) through a public comment, allowing the attacker to obtain it and import a malicious ‘.wpress’ archive containing executable code. Wordfence researchers warn that code execution at this privilege level may lead to taking complete control of the target website.
The good news is that the vendor, ServMask, has fixed the issue in version 7.110 of the plugin, which was released on August 20. However, only approximately 35% of the plugin’s user base has updated to the latest version, leaving around 3.25 million sites running a vulnerable release of All-in-One WP Migration and Backup.
The exploit requires admin action to trigger, as the payload remains dormant until the administrator restores a backup archive. While this lessens the immediate risk of exploitation, Wordfence notes that it is to be expected that admins perform the action at some point, given the plugin’s core purpose.
A deactivated vulnerable version of the plugin poses less risk, but it can still be exploited if temporarily activated. Wordfence disclosed the issue to ServMask on August 15 and validated Taylor’s finding before reporting it.
The fact that only a third of the affected sites have updated to the latest version is concerning, as this leaves them exposed to potential takeover attacks. WordPress site owners are advised to update their All-in-One WP Migration and Backup plugin to version 7.110 or higher immediately to prevent any potential security risks.
In practical terms, this means that administrators should check their website’s plugin versions, identify whether they have the vulnerable version installed, and take immediate action by updating to the latest version. This is a critical step in securing their site against potential takeover attacks.
Source: Bleeping Computer — 2026-09-02