A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to execute remote code and gain full control of affected WordPress sites. The vulnerability is tracked as CVE-2026-19949, while WordPress.org statistics indicate that the plugin is active on more than five million sites.
Security researcher Jack Taylor discovered the issue and reported it in mid-August through Wordfence, Defiant’s cybersecurity arm. After verifying the findings, Wordfence notified the plugin’s developers, ServMask, on August 15. The company fixed the vulnerability in version 7.110 on August 20, according to the published information.
How does the vulnerability work?
Researchers classify the issue as a second-order SQL injection vulnerability, affecting versions through 7.109. It is related to a flaw in parsing backslashes and escaped quotation marks while rewriting database content during the restoration of a site archive.
An unauthenticated attacker can inject specially crafted data through WordPress trackbacks. This data remains dormant until a site administrator performs an export and import operation or restores a backup, actions that fall within the plugin’s normal use. When the data is processed, the injected payload can reveal the secret import key, ai1wm_secret_key, through a public comment.
After obtaining the key, the attacker can import a malicious archive with the .wpress extension containing executable code. According to Wordfence, execution with this level of privilege could result in complete control of the site.
What reduces the risk, and what does not eliminate it?
The payload does not activate immediately after being injected; an administrator must restore a backup archive before the stored data begins to be interpreted as SQL instructions. This requirement reduces the likelihood of immediate exploitation, but it does not constitute complete practical protection, because backup and restoration are the plugin’s primary functions and an administrator is expected to perform this operation at some point.
Disabling a vulnerable version also reduces the risk, but does not eliminate it entirely if the plugin is temporarily enabled. Therefore, relying on disabling alone is insufficient for sites that may need restoration or migration operations.
Why does this matter?
The vulnerability is significant because three factors converge: a broad installation base, the ability to initiate the attack without logging in, and the transition from stored data to importing an archive capable of executing code. The available figures show that only about 35% of the plugin’s user base has updated to the latest version, while approximately 3.25 million sites remain on a vulnerable version.
In practical terms, the clear action for users is to update All-in-One WP Migration and Backup to version 7.110 or the latest version available from ServMask, while reviewing any recent restoration or import operations and any unexpected comments or data. The source does not establish whether the vulnerability has been actively exploited, nor does it provide details about specific victims; therefore, the scale of real-world exploitation remains an open question.