Feed›Vulnerability›WordPress backup plugin flaw exposes millions of sites to ta...
VulnerabilityBleeping Computer
8.8 — CRITICAL

WordPress backup plugin flaw exposes millions of sites to takeover attacks

📅 2 September 2026 at 19:28 UTC📰 Bleeping ComputerView original source ↗
WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress allows unauthenticated attackers to execute remote code and take control of affected websites, impacting over 5 million active installations.

⚙️Technical Details
Affected Systems
All-in-One WP Migration and Backup plugin for WordPress
Attack Vectors
NETWORK
💥Impact Assessment
Severity: HIGH
Who Is at Risk
WordPress users with active installations of the affected plugin
🛡️Recommended Actions
1Update to version 7.110 or later of the All-in-One WP Migration and Backup plugin
2Disable the plugin until a patch is available
3Monitor for suspicious activity on vulnerable sites
📦Affected Products
All-in-One WP Migration and Backup plugin for WordPress
🔐NVD Verified DataVERIFIED
CVE-2026-19949 ↗CVSS 8.8 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed