← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 3, 2026 · 08:52via Cyber Security News

WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks

Brief

A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 million active installations and has been fixed in version 7.

  • The issue was reported to Wordfence on August 14, 2026, by security researcher Jack Taylor through the Wordfence Bug Bounty Program. Taylor received a $5,761 bounty for discovering the vulnerability, which received a CVSS score of 8.
  • All-in-One WP Migration and Backup is widely used to export, import, restore, and migrate WordPress sites. It creates . wpress archive files containing website files and database data.

The vulnerable versions, up to and including 7.109, contain an unauthenticated second-order SQL injection flaw in the archive restore process.

Read more on Cyber Security News