Home » Security News » 5 Million WordPress Sites at Risk: Update All-in-O...

5 Million WordPress Sites at Risk: Update All-in-One WP Migration Now

5 Million WordPress Sites at Risk: Update All-in-One WP Migration Now
Deepanker Verma September 1, 2026 Security

Add Techlomedia as a preferred source on Google. Preferred Source

More than 5 million WordPress websites could be exposed to a serious security flaw in the popular All-in-One WP Migration and Backup plugin. The vulnerability can allow an unauthenticated attacker to eventually take complete control of an affected website. It has a CVSS score of 8.8 and is tracked as CVE-2026-19949.

The issue affects All-in-One WP Migration and Backup version 7.109 and older. The developer has already released a fix, so WordPress site owners should update to version 7.110 or newer.

The flaw was discovered by security researcher Jack Taylor and reported through the Wordfence Bug Bounty Program on August 14. Wordfence reported the issue to ServMask the next day. The developer acknowledged it on August 17 and released the patched version on August 20.

What makes this vulnerability unusual is that an attacker does not need to be logged into the WordPress site. The attack uses what security researchers call a second-order SQL injection. The attacker first plants malicious data on the website. That data is not immediately executed. It becomes dangerous later when the plugin processes it during an archive restore.

According to Wordfence, the attack can use WordPress’s trackback system to plant the malicious data. The attacker then waits for a site administrator to perform an export and import using the migration plugin. During the restore process, a flaw in how the plugin handles certain SQL strings can cause the stored data to be executed as SQL. This can allow the attacker to extract the plugin’s secret key.

That secret key is important because it protects the plugin’s import function. Once the attacker gets it, they can use it to access the import process and load a malicious backup archive.

The final result can be remote code execution on the server. This can give the attacker control of the WordPress site and allow them to install malicious code, steal information or make other changes.

There is one important detail. The attack is not completely automatic. The attacker needs a site administrator to perform an export followed by an import after the malicious data has been planted.

However, that is not enough reason to ignore the problem. Backup and migration are the main reasons people use this plugin, so export and restore operations are normal activities on many WordPress websites.

Wordfence has already added firewall protection for its Premium, Care and Response customers. Free Wordfence users are scheduled to receive the protection on September 15. But you should not wait for a security plugin to protect your site. If you use All-in-One WP Migration and Backup, update it to version 7.110 or newer now.

In my experience, keeping WordPress secure is not just about installing a security plugin and forgetting about it. Plugins, themes and WordPress itself need regular updates, and websites also need to be monitored for suspicious activity. If you need help securing or maintaining your WordPress website, our WordPress security services can help with security checks, malware cleanup, hardening and ongoing protection. Contact us using our contact details.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.