← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 3, 2026 · 08:47via CyberPress

WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover

Brief

A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin could allow unauthenticated attackers to exploit a stored SQL injection flaw to achieve remote code execution and a full website compromise.

Tracked as CVE-2026-19949, the issue affects plugin versions 7.109 and earlier, which are installed on more than 5 million WordPress sites.

Developer ServMask addressed the flaw in version 7. 110, released on August 20, 2026. The vulnerability carries a CVSS score of 8. 8 and was discovered by security researcher Jack Taylor through the Wordfence Bug Bounty Program.

WordPress Plugin Flaw

The flaw is classified as an unauthenticated second-order SQL injection vulnerability. Unlike direct SQL injection attacks , the malicious input does not execute immediately.

Read more on CyberPress