A high-severity unauthenticated second-order SQL injection flaw, CVE-2026-19949 (CVSS 8.8), affects the All-in-One WP Migration and Backup WordPress plugin through version 7.109, exposing roughly 5 million sites. Attackers can plant malicious data through unauthenticated WordPress trackbacks; the payload is triggered only if an administrator later exports and restores the affected site using the plugin, where faulty regular-expression handling converts stored comment data into executable SQL.
Successful exploitation can expose the plugin's ai1wm_secret_key, allowing an attacker to invoke its unauthenticated import action with a crafted .wpress archive. That archive can install a malicious must-use plugin and yield remote code execution, potentially resulting in complete site compromise. ServMask addressed the flaw in version 7.110; Wordfence released a firewall rule to paid customers and scheduled free-tier coverage for September 15.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
As of September 3, 2026, approximately 35% of All-in-One WP Migration and Backup installations had updated to version 7.110. Roughly 3.2 million sites remained on versions vulnerable to CVE-2026-19949.
CVE-2026-19949, affecting All-in-One WP Migration and Backup versions through 7.109, was publicly disclosed. The flaw is a high-severity second-order SQL injection issue in archive restoration that can lead to extraction of ai1wm_secret_key and ultimately remote code execution.
ServMask released version 7.110 of All-in-One WP Migration and Backup, patching CVE-2026-19949, a CVSS 8.8 flaw that could ultimately enable remote code execution when a vulnerable site's administrator exports and restores attacker-seeded trackback data.
ServMask acknowledged the report concerning CVE-2026-19949 in its All-in-One WP Migration and Backup plugin.
Wordfence deployed a firewall rule protecting Premium, Care, and Response customers from attempts to exploit CVE-2026-19949.
The All-in-One WP Migration and Backup vendor received full disclosure of CVE-2026-19949, affecting plugin versions through 7.109.
Researcher Jack Taylor submitted the unauthenticated second-order SQL injection vulnerability in the All-in-One WP Migration and Backup plugin through the Wordfence Bug Bounty Program.
Technical reporting identified the vulnerable replace_table_values() database-rewrite routine and described how malformed trackback data can escape a SQL string during archive restoration. The described chain uses staged payloads to obtain ai1wm_secret_key through WordPress comments and then imports a crafted archive containing a persistent must-use plugin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
12 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecysecurity.news
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcecve.circl.lu
Open sourcewordfence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.