News

WordPress migration plugin flaw puts millions of sites at risk

CVE-2026-19949 is a CVSS 8.8 SQL injection in the All-in-One WP Migration and Backup plugin by ServMask, affecting all versions up to 7.109 and fixed in 7.110 (released August 20, 2026). It is a second-order flaw that fires when an administrator restores a backup and can end in full site takeover. Two weeks after the patch, only about 35 percent of the 5 million-plus installs had updated, leaving roughly 3.2 million sites exposed. Update to 7.110 or newer now.

WordPress migration plugin flaw puts millions of sites at risk

If you run WordPress with the All-in-One WP Migration and Backup plugin, update it tonight. A newly published flaw, CVE-2026-19949, carries a CVSS score of 8.8 and can end in full site takeover. ServMask, the plugin's maker, already shipped the fix in version 7.110 on August 20. The problem is how few sites have installed it.

The WordPress logo

The plugin sits on more than 5 million active sites. As of early September, only about 35 percent had moved to 7.110, which leaves roughly 3.2 million sites still on a vulnerable build, according to SecurityWeek citing WordPress.org data. That adoption gap, two full weeks after the patch shipped, is the number operators act on.

What the bug is

This is a second-order SQL injection (CWE-89) tied to the plugin's archive restore. In plain terms, an attacker can leave crafted data in a public input on the site, where it sits inert until an administrator runs the plugin's core job: exporting and then importing or restoring a backup archive. During that rewrite of URLs and table prefixes, the planted data can be promoted into a database query.

Wordfence (Defiant), which assigned the CVE, describes the downstream impact bluntly: "As with all remote code execution vulnerabilities, this can lead to complete site compromise through the use of webshells and other techniques." The chain can expose the plugin's internal import key and let an attacker load a malicious .wpress archive, which is what turns a backup tool into a route to remote code execution. Researcher Jack Taylor reported it through Wordfence.

The catch is that it fires during a restore

There is a reason not to file this under theoretical. The planted payload does not execute on its own. It triggers when an administrator runs a backup restore or import, which is exactly what this plugin exists to do. So the safe assumption is that vulnerable sites get exercised eventually, not never.

That said, this is a patch-now advisory, not a confirmed mass-exploitation event. None of the primary write-ups report the flaw being widely exploited in the wild yet. The urgency here is the install base and the plausibility of the trigger, not a live fire alarm.

It also fits a run of 2026 flaws in the tools teams trust by default, from PaperCut's emergency zero-day patch to a JFrog Artifactory auth bypass under active exploitation, a Rails flaw already being exploited, and ServiceNow's CVSS 10 platform flaws. The shape repeats each time: the fix ships fast, and the exposure lives in the sites that never apply it.

What to do tonight

Update All-in-One WP Migration and Backup to 7.110 or newer first. Then, because the trigger is a restore and the payload hides in stored content, review recent comments and trackbacks for anything malformed, watch for .wpress imports you did not initiate, and check wp-content/mu-plugins/ for must-use plugins you did not put there. Patch first, hunt second, in that order.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free