Security0 views

Critical SQL Injection Vulnerability Discovered in All-in-One WP Migration Plugin

A critical vulnerability affecting the All-in-One WP Migration plugin has been discovered, putting millions of WordPress sites at risk. The plugin boasts over 5 million active installations, making this flaw a significant security concern for the WordPress ecosystem.

The vulnerability, tracked as CVE-2026-19949, is a SQL injection flaw that arises from improper handling of backslashes and quotation marks during file restoration. This vulnerability could allow attackers to gain complete control over vulnerable WordPress sites, potentially leading to data theft, malware injection, or site takeover.

The development team has released a patch in version 7.110 that addresses this issue. Site administrators should prioritize updating the plugin immediately to mitigate the risk. Given the widespread adoption of this plugin, it is critical that users apply this update without delay to protect their sites and data from potential exploitation.