CVE-2026-19949 is an unauthenticated second-order SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress through version 7.109. Attacker-controlled Trackback data can be stored in WordPress comments and later processed during the plugin's export and archive-import workflow. The archive restoration logic inadequately escapes user-controlled values and insufficiently prepares SQL queries; its quote and backslash handling can alter SQL string boundaries when rewriting stored database data. This permits injected SQL to execute during restoration and can expose the ai1wm_secret_key used to authorize the plugin's otherwise unauthenticated import operation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVSS 8.8 second-order SQL-injection vulnerability in All-in-One WP Migration and Backup's archive-restore functionality. Crafted WordPress trackbacks can ultimately expose the restore secret key and enable an unauthenticated attacker to import a malicious archive and execute a malicious must-use plugin for remote code execution and complete site compromise.
A high-severity vulnerability in the WordPress All-in-One WP Migration and Backup plug-in that can enable unauthenticated attackers to plant malicious Trackback data and, after an administrator performs an export/import workflow, recover the plug-in secret key and trigger a manipulated import resulting in possible server-side code execution and full site compromise.
A high-severity unauthenticated second-order SQL injection vulnerability in the All-in-One WP Migration and Backup WordPress plugin. Malicious trackback data can be stored and later made executable during a site export-and-restore workflow, enabling theft of the ai1wm_secret_key and subsequent abuse of the unauthenticated import action to upload a malicious .wpress archive containing a must-use plugin, resulting in remote code execution and full site compromise.
A CVSS 8.8 high-severity unauthenticated second-order SQL injection vulnerability in the All-in-One WP Migration and Backup WordPress plugin. Stored malicious trackback input is transformed into executable SQL during archive restore, enabling secret-key disclosure and ultimately remote code execution if an administrator exports and then imports the site.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.