Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress Plugin Flaw Puts Millions at Risk

Critical WordPress Plugin Flaw Puts Millions at Risk

Posted on September 3, 2026 By CWS

A significant security flaw has been discovered in the All-in-One WP Migration and Backup plugin, posing a threat to over 5 million WordPress sites. Identified as CVE-2026-19949, this vulnerability allows unauthorized users to potentially take control of affected websites. The issue has been addressed in the latest version, 7.110.

Discovery and Reporting

The vulnerability was brought to light on August 14, 2026, by Jack Taylor, a security researcher participating in the Wordfence Bug Bounty Program. Taylor was rewarded $5,761 for his discovery, which has been assigned a high CVSS score of 8.8, indicating its severity.

The All-in-One WP Migration and Backup tool is extensively used for exporting, importing, and migrating WordPress sites. It compiles website files and database data into .wpress archive files, making site migration easier for users.

Technical Details of the Vulnerability

This flaw exists in plugin versions up to 7.109 and involves an unauthenticated second-order SQL injection in the archive restoration process. Unlike typical SQL injections, the harmful SQL code isn’t executed immediately. Instead, attackers can inject a specially crafted payload using the WordPress trackback feature, which doesn’t require user authentication when a public post is set to accept pings.

The attack progresses when an administrator exports and subsequently restores the site using the plugin. The restoration process alters URLs and database prefixes, where a bug in handling backslashes and quoted strings in regular expressions can lead to the execution of the payload.

Potential Impact and Mitigation

Once activated, this vulnerability lets attackers access the plugin’s ai1wm_secret_key, a crucial element for protecting the plugin’s import functionality. By extracting this key through the WordPress REST API, attackers could upload malicious .wpress archives, potentially leading to a full site compromise.

The exploit necessitates an administrator’s involvement to execute import and export actions after the malicious payload is placed, a common routine in site management. Wordfence has already deployed a firewall rule for its premium users, with free users scheduled to receive protection starting September 15, 2026.

ServMask, the developer of the plugin, has acknowledged the issue and released a patch on August 20, 2026. Site administrators using the plugin should promptly update to the latest version, disable unnecessary trackbacks, and scrutinize comments and plugins for any unauthorized changes.

As a precaution, users are encouraged to stay vigilant and perform regular security audits to protect their websites from potential future vulnerabilities.

Cyber Security News Tags:All-in-One WP Migration, cyber attack, Cybersecurity, data breach, plugin vulnerability, security patch, ServMask, site safety, SQL attack, SQL injection, web development, website protection, website security, Wordfence, WordPress

Post navigation

Previous Post: Massive Driver License Data Breach on Dark Web
Next Post: Node.js Exploited in Sophisticated Cyber Attacks

Related Posts

Cloudflare Acquires Human Native to Strengthen AI Data Security Cloudflare Acquires Human Native to Strengthen AI Data Security Cyber Security News
UAC-0184 Malware Utilizes Bitsadmin and HTA for Stealthy Attacks UAC-0184 Malware Utilizes Bitsadmin and HTA for Stealthy Attacks Cyber Security News
Evilmouse: A  Device Breaches System Security Evilmouse: A $44 Device Breaches System Security Cyber Security News
Microsoft Unveils European Security Initiative to Target Cybercriminal Networks Microsoft Unveils European Security Initiative to Target Cybercriminal Networks Cyber Security News
Beware of GTA 6 Scam Sites Exploiting Gamers Beware of GTA 6 Scam Sites Exploiting Gamers Cyber Security News
Global Crackdown on Crimenetwork Reveals Thousands of Users Global Crackdown on Crimenetwork Reveals Thousands of Users Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark