Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ICE Plans to Pay $5 Million to Create National Voting Database

    September 3, 2026

    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    September 3, 2026

    When The Banks Don’t Work, Bitcoin Does: Report

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ICE Plans to Pay $5 Million to Create National Voting Database
    • WordPress backup plugin flaw exposes millions of sites to takeover attacks
    • When The Banks Don’t Work, Bitcoin Does: Report
    • Philippines fast-tracks critical minerals, raising Indigenous, environmental concerns
    • Iran Calls a Deadly U.S. Strike on a Wedding a ‘War Crime’
    • Minneapolis shooting kills two, wounds three police officers | News
    • Meta Pushes Its New AI Agent on Employees—but Eases Off on Tokenmaxxing
    • Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

    The plugin is used to back up, export, import, and move entire websites, including their databases, media, themes, and plugins, between servers or domains.

    The security flaw is tracked as CVE-2026-19949 and received a high-severity score. It was discovered by security researcher Jack Taylor, who reported it in mid-August through Defiant’s cybersecurity branch, Wordfence.

    In a report yesterday, Wordfence researchers say that CVE-2026-19949 is a second-order SQL injection vulnerability that impacts All-in-One WP Migration and Backup versions throuhg 7.109.

    The issue consists of incorrect parsing of escaped backslashes and quotation marks while the plugin rewrites database content during archive restoration.

    An unauthenticated attacker could plant crafted data through WordPress trackbacks, which would execute when an administrator exports and imports the site, both common operations for the plugin.

    The injected SQL can expose the plugin’s secret import key (ai1wm_secret_key) through a public comment, allowing the attacker to obtain it and import a malicious ‘.wpress’ archive containing executable code.

    Wordfence mentions that code execution at this privilege level may lead to taking complete control of the target website.

    According to statistics from WordPress.org, All-in-One WP Migration and Backup has more than five million active installations.

    Since the vendor fixed the issue, only approximately 35% of the plugin’s user base has updated to the latest version, with the remaining 3.25 million sites running a vulnerable release of All-in-One WP Migration and Backup.

    Update stats for All-in-One WP Migration and Backup plugin
    source: BleepingComputer

    Exploit triggered by admin action

    The payload that triggers the exploit remains dormant until the administrator restores a backup archive, an action that causes the processing of SQL string boundaries to execute the stored data as SQL.

    While this prerequisite lessens the immediate risk of exploitation, Wordfence notes that, given the plugin’s role, it is to be expected that admins perform the action at some point.

    “Since backup and restore is the core purpose of this plugin, this is a routine action, but the injected SQL will not execute until it takes place,” Wordfence notes.

    The researchers explain that a deactivated vulnerable version of the plugin poses less risk, but it can still be exploited if temporarily activated.

    Wordfence disclosed the issue to the developers of the All-in-One WP Migration and Backup plugin, ServMask, on August 15, after validating Taylor’s finding.

    On August 20, ServMask addressed the CVE-2026-19949 vulnerability in version 7.110 of the plugin.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks backup exposes Flaw millions Plugin sites takeover WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    Chrome and Firefox Updates Patch Dozens of Vulnerabilities

    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days

    Malicious Virtualizor Update Served via BGP Hijacking

    Exploit Published for Fresh Cleo Harmony Vulnerability

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ICE Plans to Pay $5 Million to Create National Voting Database

    September 3, 2026

    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    September 3, 2026

    When The Banks Don’t Work, Bitcoin Does: Report

    September 3, 2026

    Philippines fast-tracks critical minerals, raising Indigenous, environmental concerns

    September 3, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ICE Plans to Pay $5 Million to Create National Voting Database

    September 3, 2026

    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    September 3, 2026

    When The Banks Don’t Work, Bitcoin Does: Report

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.