Tech News
← Home  ·  All topics

All In One Wp Migration

1 GoKawiil brief on this topic

SQL injection bug in All-in-One WP Migration plugin leaves 3.25M sites vulnerable

Researcher Jack Taylor found a second-order SQL injection flaw, CVE-2026-19949, in the All-in-One WP Migration and Backup WordPress plugin, used on over five million sites. Attackers can plant malicious data via trackbacks that activates when an admin exports or imports a site, exposing a secret key that lets them upload a malicious archive containing executable code and seize control of the website.