All-in-One WP Migration and Backup WordPress Plugin Fixes Flaw That Could Enable Site Takeover

The All-in-One WP Migration and Backup WordPress plugin has fixed vulnerability CVE-2026-19949. Operators should update to version 7.110 or later.

Vulnerability CVE-2026-19949 in the All-in-One WP Migration and Backup plugin could, in a specific multistage attack, lead to remote code execution on a WordPress site. The flaw affects versions 7.109 and earlier, with a fix available in version 7.110.

Wordfence lists the flaw as an unauthenticated second-order SQL injection vulnerability with a severity rating of 8.8. According to WordPress.org, the All-in-One WP Migration and Backup plugin has more than five million active installations. WordPress.org is already distributing the fixed version 7.110.

How CVE-2026-19949 Works in All-in-One WP Migration

The exploitation scenario is not immediate. In the described scenario, an attacker can prepare an archive containing malicious data. It is executed only later, when an administrator restores the archive through the plugin. The flaw’s classification as unauthenticated should therefore be understood in this context: executing the malicious SQL itself requires a subsequent administrator action during backup restoration.

According to information from Wordfence, successful exploitation could allow an attacker to obtain the value of ai1wm_secret_key. The attacker could then achieve remote code execution, potentially taking over the compromised site.

The CVE-2026-19949 Fix Is in Version 7.110

Operators of WordPress sites using All-in-One WP Migration and Backup should verify the installed version and promptly upgrade to version 7.110 or later. The risk affects active installations running version 7.109 and earlier.

  • open the Plugins section in the WordPress administration area,
  • check the All-in-One WP Migration and Backup version,
  • install update 7.110 or later,
  • when restoring backups, use only archives from a trusted source.

Special attention should be paid to archives obtained outside the site’s own controlled backup process. Restoring an archive by an administrator is the step required to activate the described attack.

Active Exploitation Has Not Been Confirmed

Available information does not confirm evidence that CVE-2026-19949 is being actively exploited in the wild. Secondary sources cite estimates of the number of unupdated sites, but this is not an independently verified figure and is based on an assumed update rate.

Further developments will depend mainly on whether Wordfence, ServMask or WordPress.org publish information about exploitation and whether additional recommendations emerge for administrators who cannot perform the update immediately.

Sources

  • Wordfence Threat Intelligence – CVE-2026-19949 record, affected versions through 7.109, severity 8.8 and the fix in version 7.110.
  • WordPress.org – Currently distributed version 7.110 and more than 5 million active installations.
  • BleepingComputer – Description of the multistage exploitation scenario, the fix date and the estimate of unupdated installations.

Verified and updated: 09/03/2026 13:32

Sharing