ConicPlex

Start Your Project

A brass key resting on a stack of archive folders in front of a laptop glowing with WordPress-blue light, symbolizing a stolen secret key used to exploit a WordPress backup plugin

On this Page

All-in-One WP Migration Plugin Patches a Critical Unauthenticated SQL Injection Flaw (CVE-2026-19949)

CVE-2026-19949 is an unauthenticated SQL injection in All-in-One WP Migration and Backup, patched in version 7.110. Millions of sites remain unpatched.

Aftab Memon

September 4, 2026

An unauthenticated SQL injection flaw in All-in-One WP Migration and Backup, tracked as CVE-2026-19949, puts more than 5 million WordPress sites at risk of full takeover. The plugin’s developer, ServMask, patched the bug in version 7.110 on August 20, and Wordfence published its full technical disclosure on September 2. As of September 3, roughly 35% of the plugin’s user base had updated, leaving an estimated 3.25 million sites still running a vulnerable copy.

The flaw carries a CVSS score of 8.8 (high severity) and affects every version up to and including 7.109.

How the Attack Actually Works

This isn’t a simple form-field injection. It’s a second-order attack, which is part of why it slipped through for as long as it did. An attacker submits a specially crafted trackback to any public post on the site. That payload sits harmlessly in the database, doing nothing, until a site administrator runs a routine archive export and import using the plugin, something migration and backup tools are used for constantly.

When that restore happens, the plugin rewrites database content but fails to properly escape backslashes and quotation marks in the stored trackback data. That gap lets the injected SQL execute. From there, an attacker can pull the plugin’s ai1wm_secret_key out of the database, and that key is enough to import a malicious .wpress archive, which can plant a webshell or backdoor and hand over full control of the site.

Who Should Care, and What to Do

If a site is running All-in-One WP Migration and Backup, this isn’t optional homework. With 5 million active installs and only about a third of them patched so far, it’s exactly the kind of plugin most agencies and site owners installed once for a migration years ago and never think about again.

  • Update to version 7.110 or later immediately.
  • If the plugin hasn’t been used for an active migration in a while, consider whether it needs to stay installed at all. Fewer active plugins means a smaller attack surface.
  • Check recent comment and trackback activity for anything that looks like injected SQL syntax, particularly around the time of the last archive restore.
  • If a restore was run on an unpatched version, treat the site as potentially compromised and audit admin accounts and file changes, not just apply the update.

This is also a good reminder of why a periodic plugin audit matters more than a one-time setup. A lot of these exposures come from utility plugins that were installed for a single task and then left alone. ConicPlex’s WordPress Development and plugin development work regularly turns up exactly this kind of dormant, outdated plugin during a site review, and it’s the same pattern behind last week’s Avada RCE disclosure: widely installed software that quietly falls behind on updates.

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

News & Updates

A laptop glowing with WordPress blue light on a dark desk at night, surrounded by several identical old brass keys half hidden under a notebook, symbolizing a backdoor that hides duplicate copies of itself.

WordPress Backdoor SC Survives Cleanup by Hiding in Files, Database, and Memory

Sucuri documented a self-healing WordPress backdoor called SC that rebuilds itself from eight hiding spots, including shared memory, after a…

Aftab Memon

October 3, 2026

News & Updates

A laptop glowing with a soft magenta light next to an ID keycard on a wooden desk, symbolizing a WordPress admin access vulnerability

Elementor Patches a Critical CSRF Flaw That Could Hand Attackers Admin Access (CVE-2026-62062)

A CSRF flaw in Elementor 4.3.0 and 4.3.1 (CVE-2026-62062, CVSS 8.8) let attackers create admin accounts with one click. Patched…

Aftab Memon

October 2, 2026

Plugins

Stack of to-do list task cards with checkboxes in front of a faded kanban board, illustrating WordPress dashboard to-do list and task management plugins

How to Add a To-Do List to Your WordPress Dashboard (4 Plugins Compared)

Compare four real WordPress plugins for a dashboard to-do list or task board, from a simple single-person widget to full…

Husen Memon

October 2, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant