Millions of WordPress sites may already have a malicious line that does nothing noticeable yet. The vulnerability of CVE-2026-19949 allows the anonymous attacker to leave such code in the database in advance, and the trap is triggered later when the administrator himself launches the usual site recovery operation.
The problem is found in the popular plugin All-in-One WP Migration and Backup, which is used to create backups and transfer sites between servers. The plugin has more than five million active installations. Vulnerable all versions up to 7.109 inclusive, the correction appeared in version 7.110.
The main feature of the error is the second-order SQL injection mechanism. The attacker does not need to immediately force the server to execute a malicious command. First, the prepared data is stored in the database as ordinary content, and the dangerous become only later, when the other part of the program reads the records and mishandles them.
In the case of All-in-One WP Migration, the attacker can send specially prepared trackback requests to the WordPress record receiving ping notifications. Authorization is not required for such an operation. Malware values fall into the comment table and can stay there until the next export cycle and site recovery.
The creation of a backup is not yet launching an attack. A dangerous moment occurs when the administrator exports the site and then imports or restores the resulting archive. The plugin begins to rewrite the addresses and prefixes of the tables inside the SQL-dump, incorrectly determines the boundaries of the lines with the reverse slacks and as a result turns the data stored by the attacker into the executable SQL code.
The chain allows you to pull the secret key out of the database ai1wm_secret_key and write it in a publicly available commentary. After receiving the key, the attacker passes the verification of the import function and downloads his own archive .wpress. The archive can be placed with a malicious mandatory WordPress plugin, which is launched at the next page load. The end result is remote code execution and full site capture.
Specialist Jack Taylor conveyed the error information on August 14. The developer ServMask received details on August 15, confirmed the problem two days later and on August 20 released version 7.110. The vulnerability was rated 8.8 out of 10 on CVSS. As of September 2, only about 35% of users installed the corrected version, so approximately 3.25 million sites could still work on vulnerable builds.
The technical analysis emphasizes the unusual delay between the first action of the attacker and the actual hack. Malicious recording is able to remain invisible in the database for a long time, and then work during routine recovery or migration, when the administrator itself activates a vulnerable area of code.
Website owners are advised to install All-in-One WP Migration and Backup 7.110 or more version until the next archive is restored. Simply disabling the old version reduces the current attack surface, but does not guarantee the security of the already stored data if the plugin later turns on again and launch the import.
The problem is found in the popular plugin All-in-One WP Migration and Backup, which is used to create backups and transfer sites between servers. The plugin has more than five million active installations. Vulnerable all versions up to 7.109 inclusive, the correction appeared in version 7.110.
The main feature of the error is the second-order SQL injection mechanism. The attacker does not need to immediately force the server to execute a malicious command. First, the prepared data is stored in the database as ordinary content, and the dangerous become only later, when the other part of the program reads the records and mishandles them.
In the case of All-in-One WP Migration, the attacker can send specially prepared trackback requests to the WordPress record receiving ping notifications. Authorization is not required for such an operation. Malware values fall into the comment table and can stay there until the next export cycle and site recovery.
The creation of a backup is not yet launching an attack. A dangerous moment occurs when the administrator exports the site and then imports or restores the resulting archive. The plugin begins to rewrite the addresses and prefixes of the tables inside the SQL-dump, incorrectly determines the boundaries of the lines with the reverse slacks and as a result turns the data stored by the attacker into the executable SQL code.
The chain allows you to pull the secret key out of the database ai1wm_secret_key and write it in a publicly available commentary. After receiving the key, the attacker passes the verification of the import function and downloads his own archive .wpress. The archive can be placed with a malicious mandatory WordPress plugin, which is launched at the next page load. The end result is remote code execution and full site capture.
Specialist Jack Taylor conveyed the error information on August 14. The developer ServMask received details on August 15, confirmed the problem two days later and on August 20 released version 7.110. The vulnerability was rated 8.8 out of 10 on CVSS. As of September 2, only about 35% of users installed the corrected version, so approximately 3.25 million sites could still work on vulnerable builds.
The technical analysis emphasizes the unusual delay between the first action of the attacker and the actual hack. Malicious recording is able to remain invisible in the database for a long time, and then work during routine recovery or migration, when the administrator itself activates a vulnerable area of code.
Website owners are advised to install All-in-One WP Migration and Backup 7.110 or more version until the next archive is restored. Simply disabling the old version reduces the current attack surface, but does not guarantee the security of the already stored data if the plugin later turns on again and launch the import.