discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

SQL injection vulnerability in WordPress backup plugin exposes millions of sites to takeover attacks

All-in-One WP Migration and Backup plugin for WordPress has a high-severity SQL injection vulnerability that could allow attackers to take control of affected websites.

By Bill Toulas·Sep 2·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

SQL injection vulnerability in WordPress backup plugin exposes millions of sites to takeover attacks
Image: bleepingcomputer.com

A security flaw in the All-in-One WP Migration and Backup plugin for WordPress could expose millions of sites to takeover attacks, as reported by security researchers.

Why it matters

This vulnerability affects millions of WordPress sites and could lead to complete control of affected websites, highlighting the importance of keeping software up to date.

A security flaw in the WordPress backup plugin could let bad guys take control of your website. They do this by tricking the plugin into running bad code, and if they get in, they can do whatever they want on your site.

Analysis

{"heading_1":"The SQL Injection Vulnerability","paragraph_1":"The All-in-One WP Migration and Backup plugin for WordPress contains a SQL injection vulnerability that could allow attackers to execute remote code and take control of affected websites.","paragraph_2":"The vulnerability is a second-order SQL injection that impacts All-in-One WP Migration and Backup versions through 7.109, and it can be exploited by unauthenticated attackers through WordPress trackbacks.","paragraph_3":"The vulnerability can expose the plugin's secret import key (ai1wm_secret_key) through a public comment, allowing attackers to obtain it and import a malicious '.wpress' archive containing executable code.","paragraph_4":"Wordfence researchers reported the vulnerability to the plugin's developers, ServMask, on August 15, and the vulnerability was fixed in version 7.110 of the plugin on August 20.","paragraph_5":"The vulnerability affects millions of active installations of the All-in-One WP Migration and Backup plugin, with only approximately 35% of the plugin's user base having updated to the latest version."}

Key points

  • All-in-One WP Migration and Backup plugin has a high-severity SQL injection vulnerability
  • The vulnerability impacts millions of active installations of the plugin
  • Only 35% of the plugin's user base has updated to the latest version
  • The vulnerability can be exploited by unauthenticated attackers through WordPress trackbacks
  • The vulnerability can expose the plugin's secret import key and allow attackers to import a malicious '.wpress' archive containing executable code
The Upside

Once the vulnerability is fixed, the risk of attacks will decrease, and users will be more secure.

The Downside

If the vulnerability is not fixed, attackers could still exploit it, leading to complete control of the affected websites.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpresssql-injectionvulnerabilitytakeover-attacks

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 2, 2026

Source

bleepingcomputer.com

Share

Topics

securitywordpresssql-injectionvulnerabilitytakeover-attacks

Related

More from this desk

Sep 3·bleepingcomputer.com

Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs

Microsoft Teams and Outlook fail to launch on ARM-based Windows PCs after recent updates. Issue affects Surface Laptop 7 and Surface Pro 11 running Windows 11 24H2 or later.

Sep 2·bleepingcomputer.com

Hackers Exploit Sangoma Switchvox Flaw to Deploy Reverse Shells

Hackers are exploiting a vulnerability in Sangoma Switchvox VoIP platform, leading to remote code execution and reverse shell deployment.

Sep 2·thehackernews.com

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Malware campaign uses fake websites to distribute malicious software, compromising multiple organizations and industries in China.

Sep 2·bleepingcomputer.com

Hackers Exploit Critical JFrog Artifactory Flaw to Forge Admin Tokens

Hackers exploit JFrog Artifactory flaw to create admin tokens, gaining administrative access. JFrog addresses the issue with new versions.