bleeping-computer · Crawled Sep 2, 2026
WordPress backup plugin flaw exposes millions of sites to takeover attacks
Read original article ↗AI Summary
A high-severity SQL injection vulnerability, tracked as CVE-2026-19949, exists in the All-in-One WP Migration and Backup plugin for WordPress, affecting versions up to 7.109. The flaw allows unauthenticated attackers to inject malicious SQL through trackbacks, which executes when an administrator performs a backup import, enabling remote code execution and full site takeover. The vulnerability stems from improper handling of escaped backslashes and quotes during database restoration. Despite a patch released in version 7.110 on August 20, only 35% of the over five million installations have been updated, leaving millions of sites at risk.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.