CVE Tools
Back to feed
PoC public All-in-One WP Migration and Backup web-app WordPress Defiant rce

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Security firm Defiant has issued a warning regarding a high-severity flaw in the All-in-One WP Migration and Backup plugin, which leaves approximately 3.2 million WordPress sites exposed to remote code execution attacks. Identified as CVE-2026-19949 with a CVSS score of 8.8, this second-order SQL injection vulnerability resides in the archive restore feature due to inadequate input escaping.

An unauthenticated attacker can exploit this by submitting specific trackbacks that allow them to steal a secret key and subsequently upload a malicious plugin, resulting in full site compromise. The issue affects all versions prior to 7.110, so administrators should update their plugins to the latest release to mitigate the risk.