{
  "id": 5239917,
  "title": "All-in-One WP Migration CVE-2026-19949: From Second-Order SQL Injection on Restore to Site Takeover",
  "url": "https://urgent.news/2026/09/03/all-in-one-wp-migration-cve-2026-19949-from-second-order-sql",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-03T03:56:10.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/all-in-one-wp-migration-cve-2026-19949-from-second-order-sql-injection-on-restore-to-site-takeover-21be"
  },
  "original_language": "en",
  "account": "An SQL injection vulnerability, CVE-2026-19949, has been discovered in the All-in-One WP Migration and Backup plugin for WordPress. This flaw allows attackers to inject malicious second-order SQL code through public WordPress input channels. When administrators restore a backup, the plugin inadvertently reveals its secret key, which can then be exploited to gain remote code execution and take control of the entire website.\n\nAttackers can exploit this vulnerability by injecting specially crafted data into public input channels like trackbacks. When an administrator exports, imports, or restores a backup, the plugin processes this data, inadvertently allowing the attacker to execute SQL queries and retrieve the secret key. With this key, the attacker can bypass authentication during the import process, extract a malicious .wpress archive containing executable code, and gain complete control of the web server.\n\nVictims may not notice the compromise as the site continues to function normally, making it difficult to detect. Administrators, however, may observe unusual quotes or backslashes in trackbacks or comments, abnormal SQL queries during the restore process, or the appearance of the secret key in public comments. Evidence of a successful attack includes the import of .wpress archives from unknown sources, followed by the spawning of new PHP files and child processes.\n\nTo mitigate this risk, administrators should update to version 7.110 or later and disable or strictly validate unnecessary public inputs like trackbacks. Additionally, secret keys should be rotated to enhance security. Upon successful exploitation, attackers can read sensitive information from the WordPress database, leak the secret key, execute arbitrary code, and take complete control of the site. This can lead to web defacement, credential theft, malware distribution, and attacks against visitors.",
  "summary": "1. Basic Information Article Title : WordPress backup plugin flaw exposes millions of sites to takeover attacks Publisher : BleepingComputer Publication Date : 2026-09-02 Original Source : BleepingComputer Related Sources : Wordfence technical analysis , Wordfence vulnerability record Related Malware / Threat Groups / CVEs / Products : CVE-2026-19949, WordPress, All-in-One WP Migration and Backup…",
  "key_points": [
    "All-in-One WP Migration plugin has SQL injection vulnerability CVE-2026-19949",
    "Attackers exploit second-order SQL code via public input channels to gain remote code execution",
    "Updated to version 7.110 or later to mitigate risk"
  ],
  "editors_take": "This vulnerability allows attackers to gain complete control of a website by exploiting a flaw in the All-in-One WP Migration and Backup plugin, enabling them to execute arbitrary code and read sensitive information.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}