loader image
WordPress Plugin Flaw Risks Takeover of 5M Sites

A critical flaw in the All-in-One WP Migration and Backup plugin threatens over 5 million WordPress sites, exploiting SQL injection risks. Known as CVE-2026-19949, the vulnerability affects versions up to 7.109, allowing attackers to take control of websites. Security researcher Jack Taylor, through Wordfence’s Bug Bounty Program, identified the issue, earning $5,761 for his discovery. The flaw becomes active during archive restoration when the plugin misinterprets SQL strings, potentially enabling unauthorized access and remote code execution. Attackers can inject malicious payloads using trackbacks, which regular users might overlook. Wordfence installed a firewall rule on August 16 for some users, with wider protection arriving by mid-September. Site owners should update to version 7.110 immediately and review security settings. The plugin flaw risks underscore the urgency for administrators to tighten their security protocols. For more detailed coverage, please visit the full article at the following link:

WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks

Write a Reply or Comment

Your email address will not be published. Required fields are marked *