logo

WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover

ID: db339724-4e51-5b13-8b7e-ebb6630eaa1c

STIX ID: report--db339724-4e51-5b13-8b7e-ebb6630eaa1c

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

Author: Divya

...
...

A critical unauthenticated second-order SQL injection (CVE-2026-19949) in the All-in-One WP Migration plugin (affecting versions up to 7.109) allows attackers to store crafted data (e.g., via public trackbacks) that later escapes its SQL string context during backup restore, enabling leakage of the plugin's secret key and unauthenticated import of a malicious must-use plugin that can achieve remote code execution and full site takeover; the issue is fixed in version 7.110 and administrators are advised to update immediately, review trackback/comment usage, and investigate recent restore activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.