
[CIVN-2026-0451] SQL Injection Vulnerability in All-in-One WP Migration and Backup Plugin for WordPress
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
SQL Injection Vulnerability in All-in-One WP Migration and Backup Plugin for WordPress
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
All-in-One WP Migration and Backup versions 7.109 and prior
Overview
A SQL Injection vulnerability has been reported in All-in-One WP Migration and Backup plugin for WordPress, which could allow an unauthenticated remote attacker to inject malicious SQL statements, access sensitive database information, obtain the plugin¿s secret key, and potentially execute arbitrary code on affected WordPress installations.
Target Audience:
All organizations and administrators using affected versions of the All-in-One WP Migration and Backup plugin for WordPress.
Risk Assessment:
High risk of sensitive data exposure and compromise of affected WordPress installations.
Impact Assessment:
Potential for malicious SQL execution, disclosure of sensitive database information, compromise of the plugin¿s secret key, arbitrary code execution, and complete compromise of affected WordPress installations.
Description
All-in-One WP Migration and Backup is a WordPress plugin developed by ServMask, providing website migration, backup, export, and restoration capabilities for WordPress websites.
This vulnerability exists in the All-in-One WP Migration and Backup plugin due to improper neutralization of special elements used in an SQL Command, including insufficient escaping and improper handling of user-supplied input. An unauthenticated attacker could exploit this vulnerability by submitting specially crafted input that is stored and subsequently processed during archive restoration.
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to inject malicious SQL statements, access sensitive database information, obtain the plugin¿s secret key, and potentially execute arbitrary code on affected WordPress installations.
Solution
Apply appropriate security updates and mitigations as recommended below:
https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/
Vendor Information
ServMask
https://servmask.com/
References
https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/
CVE Name
CVE-2026-19949
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqiw7oACgkQ3jCgcSdc
ys9Y/BAAiSnxglYNTqnfOCu3W3UqzYGERLghR/DoiQvYPGgEK7Tk0gCk31cmes7c
eAI7RXLoHX7JpcNV99f4Iq2l3LfEAhM8YSes0KhN5mNCuCb8eB97VmByyC/GpyGd
eOXn176XbsOblZeP98rPegvFa6NKWyB29dLoiPgborF4bHGKLPJlFG5RpE8MQdO4
aCYsmIpFEQe9eSMIjVp4M4kaRkNssJqjZ6H0WitDh3mf0qzC5aQY/au3E1KBTaxL
kVnM+O8Tns5bVGAiB/0123KZ62aFcMqpbtrHfgjaW6/ZH4mytzBpb7UHYhQ1rgON
ovFnQGkKC8yWI38DWScEUeQd3hY6DUTjoFO1fET/KcxBB1bSYIvRA8pVM8uh0WWQ
3UCbKqidFqXm88UWLsXuP1XSWHSjtEtc+gHc+rDhT0ROthqkZlFwomVCOvWGrVFN
OG/VRbdkWxMK/YX5ySKFND1YGYk9zteDKfct8Ry+KfKhYTvHEAnycc/0C12QFTbC
fXFClv8s7b29yaZ9QXXzBYSCoC89hoPSTkBnWn3/T8nG/yvQUOk8vgi/HvuUevZn
RvtaMtzOWEoEZ2HGGcMgaYpgxH2AE09JQz64khbjswAPMHqwWdHP3eS0NT45vNiE
YfZe19hmN1/fDWYeuSj+gYPTMANWFt52NUe7Cylukgm5UBnlsU0=
=yGxK
—–END PGP SIGNATURE—–


