WordPress backup plugin flaw exposes millions of sites to takeover attacks

WordPress backup plugin flaw exposes millions of sites to takeover attacks

SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

The plugin is used to backup, export, import and move entire websites, including their databases, media, themes and plugins, between servers or domains.

The vulnerability is tracked as CVE-2026-19949 and has a high severity rating. It was discovered by security researcher Jack Taylor, who reported it in mid-August via Defiant’s cybersecurity branch, Wordfence.

In a report yesterday, Wordfence researchers say that CVE-2026-19949 is a second-order SQL injection vulnerability that affects All-in-One WP Migration and Backup versions through 7.109.

The problem is that escaped backslashes and quotes are not parsed correctly while the plug-in overwrites the database contents during backup restore.

An unauthorized attacker can place crafted data through WordPress backlinks that will be executed when an administrator exports and imports the site, both common operations for the plugin.

The injected SQL can reveal the plugin’s import secret key (ai1wm_secret_key) via a public comment, allowing an attacker to obtain it and import a malicious “.wpress” archive containing executable code.

Wordfence mentions that executing code at this privilege level can result in taking full control of the target website.

According to statistics from WordPress.orgAll-in-One WP Migration and Backup has more than five million active installations.

Since the vendor fixed the issue, only approximately 35% of the plugin’s user base has updated to the latest version, with the remaining 3.25 million sites running a vulnerable version of All-in-One WP Migration and Backup.

Update statistics for WP All-in-One Migration and Backup plugin
source: BleepingComputer

Exploit triggered by administrator action

The payload that triggers the exploit remains inactive until an administrator restores a backup archive, an action that causes SQL string boundary processing to execute the stored data as SQL.

While this premise reduces the immediate risk of exploitation, Wordfence notes that given the role of the plugin, administrators should be expected to perform the action at some point.

“Since backup and restore is the primary purpose of this plugin, this is a routine action, but the injected SQL will not execute until it is done.” Wordfence notes.

The researchers explain that the disabled vulnerable version of the plugin poses less risk, but can still be used if temporarily enabled.

Wordfence disclosed the issue to the developers of the All-in-One WP Migration and Backup plugin, ServMask, on August 15 after confirming Taylor’s discovery.

On August 20, ServMask addressed the CVE-2026-19949 vulnerability in version 7.110 of the plugin.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *