WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
Brief
A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin could allow unauthenticated attackers to exploit a stored SQL injection flaw to achieve remote code execution and a full website compromise.
Tracked as CVE-2026-19949, the issue affects plugin versions 7.109 and earlier, which are installed on more than 5 million WordPress sites.
Developer ServMask addressed the flaw in version 7. 110, released on August 20, 2026. The vulnerability carries a CVSS score of 8. 8 and was discovered by security researcher Jack Taylor through the Wordfence Bug Bounty Program.
WordPress Plugin Flaw
The flaw is classified as an unauthenticated second-order SQL injection vulnerability. Unlike direct SQL injection attacks , the malicious input does not execute immediately.
