
What Changed
BleepingComputer reports that CVE-2026-19949 affects All-in-One WP Migration and Backup through version 7.109. Wordfence describes it as a second-order SQL injection bug caused by incorrect parsing of escaped backslashes and quotation marks while the plugin rewrites database content during archive restoration.
The exploit path is more specific than a generic 'RCE in WordPress' headline suggests. An unauthenticated attacker can plant crafted data through WordPress trackbacks, wait for an administrator to export and import the site, then use the resulting SQL execution to expose the plugin's secret import key and upload a malicious .wpress archive.
Why This Matters Operationally
The important operational point is that the triggering action is routine for the plugin's core purpose. The payload may sit dormant until an admin runs a restore or migration task, which means some teams may underestimate the risk because exploitation is not always immediate or noisy.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Built from 100+ trusted cybersecurity sources.
Built from 100+ trusted cybersecurity sources.
Scale matters too. BleepingComputer says the plugin has more than five million active installations, while Wordfence estimates only about 35% of the user base has updated to the fixed release, leaving roughly 3.25 million sites on vulnerable versions.
What Defenders Should Verify First
- Identify every WordPress site running All-in-One WP Migration and Backup and confirm whether any are still on version 7.109 or earlier instead of the fixed 7.110 release.
- Review whether trackbacks are enabled or otherwise reachable, and whether the site regularly performs imports or restorations that could trigger dormant malicious data.
- Inspect administrator activity, plugin changes, scheduled tasks, and unexpected content or user creation for signs the secret import key may have been exposed and used.
- Treat temporarily deactivated vulnerable copies as still relevant if admins commonly re-enable the plugin for occasional migrations or restores.
Source Context
CyberExperts used BleepingComputer's reporting and the Wordfence technical explanation it cites to preserve the key details readers need first: CVE-2026-19949, the second-order SQL injection mechanism, the import-key exposure step, the fixed version 7.110, and the large still-unpatched install base.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief