Urgent.News

What's breaking now, across thousands of outlets.

Tech

All-in-One WP Migration CVE-2026-19949: From Second-Order SQL Injection on Restore to Site Takeover

1. Basic Information Article Title : WordPress backup plugin flaw exposes millions of sites to takeover attacks Publisher : BleepingComputer Publication Date : 2026-09-02 Original Source : BleepingComputer Related Sources : Wordfence technical analysis , Wordfence vulnerability record Related Malware / Threat Groups / CVEs / Products : CVE-2026-19949, WordPress, All-in-One WP Migration and Backup…

An SQL injection vulnerability, CVE-2026-19949, has been discovered in the All-in-One WP Migration and Backup plugin for WordPress. This flaw allows attackers to inject malicious second-order SQL code through public WordPress input channels. When administrators restore a backup, the plugin inadvertently reveals its secret key, which can then be exploited to gain remote code execution and take control of the entire website.

Attackers can exploit this vulnerability by injecting specially crafted data into public input channels like trackbacks. When an administrator exports, imports, or restores a backup, the plugin processes this data, inadvertently allowing the attacker to execute SQL queries and retrieve the secret key. With this key, the attacker can bypass authentication during the import process, extract a malicious .wpress archive containing executable code, and gain complete control of the web server.

Victims may not notice the compromise as the site continues to function normally, making it difficult to detect. Administrators, however, may observe unusual quotes or backslashes in trackbacks or comments, abnormal SQL queries during the restore process, or the appearance of the secret key in public comments. Evidence of a successful attack includes the import of .wpress archives from unknown sources, followed by the spawning of new PHP files and child processes.

To mitigate this risk, administrators should update to version 7.110 or later and disable or strictly validate unnecessary public inputs like trackbacks. Additionally, secret keys should be rotated to enhance security. Upon successful exploitation, attackers can read sensitive information from the WordPress database, leak the secret key, execute arbitrary code, and take complete control of the site. This can lead to web defacement, credential theft, malware distribution, and attacks against visitors.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

10 Smartest Cities in the World in 2026

From Zurich to Singapore, these 10 cities lead the 2026 IMD Smart City Index for infrastructure, technology, governance and quality of life.

  • Zurich retains top spot as world's smartest city for 7th consecutive year
  • Oslo second, focusing on sustainability and renewable energy
  • Geneva, London, and Copenhagen round out top five for public services

More from Thursday 3 September →