SQL injection bug in All-in-One WP Migration plugin leaves 3.25M sites vulnerable
Researcher Jack Taylor found a second-order SQL injection flaw, CVE-2026-19949, in the All-in-One WP Migration and Backup WordPress plugin, used on over five million sites. Attackers can plant malicious data via trackbacks that activates when an admin exports or imports a site, exposing a secret key that lets them upload a malicious archive containing executable code and seize control of the website.