Search
Find merged stories by title or summary.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek .
WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks
A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 million active installations and has been fixed in version 7. 110. The issue was reported to Wordfence on August 14, 2026, by security researcher Jack Taylor through the Wordfence Bug Bounty Program. Taylor received a $5,761 bounty for discovering the vulnerability, which received a CVSS score of 8. 8. All-in-One WP Migration and Backup is widely used to export, import, restore, and migrate WordPress sites. It creates . wpress archive files containing website files and database data. The vulnerable versions, up to and including 7.109, contain an unauthenticated second-order SQL injection flaw in the archive restore process.
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin could allow unauthenticated attackers to exploit a stored SQL injection flaw to achieve remote code execution and a full website compromise. Tracked as CVE-2026-19949, the issue affects plugin versions 7.109 and earlier, which are installed on more than 5 million WordPress sites. Developer ServMask addressed the flaw in version 7. 110, released on August 20, 2026. The vulnerability carries a CVSS score of 8. 8 and was discovered by security researcher Jack Taylor through the Wordfence Bug Bounty Program. WordPress Plugin Flaw The flaw is classified as an unauthenticated second-order SQL injection vulnerability. Unlike direct SQL injection attacks , the malicious input does not execute immediately.
You've reached the end of current stories for this search.
