SQL injection vulnerability in All-in-One WP Migration plugin: 3.25 million WordPress sites still at risk

A serious SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress allows unauthenticated attackers to execute remote code and take control of vulnerable sites. The flaw, identified as CVE-2026-19949 with a high severity score, was discovered by researcher Jack Taylor and reported through Wordfence, the cybersecurity arm of Defiant.

Quick Response

  • The CVE-2026-19949 vulnerability is a second-order SQL injection affecting plugin versions up to 7.109
  • It allows remote code execution by exploiting backup and restore features
  • 3.25 million sites (65% of installations) have not yet applied the patch
  • The attack requires administrative action but is likely given the plugin's usage context

Exploitation Mechanism: How the Vulnerability Works

The technical issue lies in the incorrect handling of backslashes and quotes during backup archive restoration. An attacker can inject manipulated data via WordPress trackbacks, which will be executed as SQL when an administrator re-exports and imports the site. This common process for the plugin is the main attack vector.

Exposure of the Secret Key and Execution of Malicious Code

The vulnerability allows exposing the secret import key (ai1wmsecretkey) through a public comment. Attackers can then use this key to import a '.wpress' archive containing executable code. Wordfence emphasizes that code execution at this privilege level can lead to complete site compromise.

Alarming Statistics: Only 35% of Users Have Updated

With over 5 million active installations according to WordPress.org data, the plugin is one of the most widespread on the platform. However, despite the patch released on August 20 in version 7.110, only 35% of users have updated. This means that 3.25 million sites remain vulnerable.

Exploitation Conditions: The Crucial Role of Administrative Actions

The attack payload remains inactive until an administrator restores a backup archive, an action that triggers the execution of the injected data as SQL. Although this condition reduces the immediate risk, Wordfence notes that, given the plugin's main function, it is highly likely that administrators will perform this operation periodically.

Residual Risk: Even Deactivated Versions Can Be Vulnerable

Wordfence highlights that even a deactivated vulnerable version of the plugin can be exploited if temporarily reactivated. This scenario increases the importance of keeping all installations updated, even those not currently in use.

Disclosure Timelines and Vendor Response

The vulnerability was validated by Wordfence on August 15 and immediately reported to ServMask developers. The vendor responded promptly, releasing the patch in version 7.110 just 5 days later, on August 20.

Security Implications: What Administrators Can Do

WordPress site administrators using All-in-One WP Migration and Backup must update immediately to version 7.110 or later. It is also advisable to:

  • Perform data backups before updating
  • Verify the integrity of existing backups
  • Monitor suspicious administrative activities
  • Consider implementing additional security solutions

This vulnerability underscores the critical importance of keeping all components of a WordPress site updated and adopting proactive security measures to mitigate risks associated with essential management plugins like All-in-One WP Migration and Backup.

A Reminder on Vulnerability Management

The widespread nature of this vulnerability and the observed low update rate serve as a warning to the entire WordPress community. Plugin developers must continue to invest in secure development practices, while users must adopt proactive update management to protect their installations.

Wordfence, in its report, also emphasized that overall prevention scores can hide what happens after the initial access, highlighting how once attackers use valid credentials, prevention capabilities drastically decrease. This aspect is particularly relevant for vulnerabilities like this one, which can lead to complete site compromise.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decisions.