Patch released WordPress web-app All-in-One WP Migration and Backup ServMask rce
WordPress backup plugin flaw exposes millions of sites to takeover attacks
CVE Tools coverage
ServMask has released version 7.110 of the All-in-One WP Migration and Backup plugin to fix a high-severity second-order SQL injection vulnerability identified as CVE-2026-19949. Discovered by researcher Jack Taylor and reported via Wordfence, this flaw affects versions through 7.109 and enables unauthenticated attackers to inject malicious code through WordPress trackbacks. The payload executes only when an administrator performs a backup or restore operation, potentially exposing secret keys and allowing full site takeover via a compromised archive. With over five million active installations, approximately 35% of users have already updated, leaving roughly 3.25 million sites still vulnerable.