WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks
ID: 3b54f031-47a5-57ea-9fd9-c43bd7a3a7f0
STIX ID: report--3b54f031-47a5-57ea-9fd9-c43bd7a3a7f0
Feed Name: cybersecurityNews.com
A high-severity second-order SQL injection (CVE-2026-19949, CVSS 8.8) in the All-in-One WP Migration and Backup plugin (<=7.109) can allow unauthenticated attackers to plant malicious trackbacks, have that payload converted into executable SQL during a site restore, leak the plugin's secret key, and then import a crafted .wpress archive that installs a must-use plugin to achieve remote code execution; the issue affects millions of active installs, was fixed in v7.110, and Wordfence deployed firewall protections while owners are advised to update, disable unnecessary trackbacks, inspect comments, and verify no unauthorized plugins or admin accounts exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
