[CIVN-2026-0451] SQL Injection Vulnerability in All-in-One WP Migration and Backup Plugin for WordPress

By Published On: September 10, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


SQL Injection Vulnerability in All-in-One WP Migration and Backup Plugin for WordPress


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


All-in-One WP Migration and Backup versions 7.109 and prior

Overview


A SQL Injection vulnerability has been reported in All-in-One WP Migration and Backup plugin for WordPress, which could allow an unauthenticated remote attacker to inject malicious SQL statements, access sensitive database information, obtain the plugin¿s secret key, and potentially execute arbitrary code on affected WordPress installations.


Target Audience:

All organizations and administrators using affected versions of the All-in-One WP Migration and Backup plugin for WordPress.


Risk Assessment:

High risk of sensitive data exposure and compromise of affected WordPress installations.


Impact Assessment:

Potential for malicious SQL execution, disclosure of sensitive database information, compromise of the plugin¿s secret key, arbitrary code execution, and complete compromise of affected WordPress installations.


Description


All-in-One WP Migration and Backup is a WordPress plugin developed by ServMask, providing website migration, backup, export, and restoration capabilities for WordPress websites.


This vulnerability exists in the All-in-One WP Migration and Backup plugin due to improper neutralization of special elements used in an SQL Command, including insufficient escaping and improper handling of user-supplied input. An unauthenticated attacker could exploit this vulnerability by submitting specially crafted input that is stored and subsequently processed during archive restoration.


Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to inject malicious SQL statements, access sensitive database information, obtain the plugin¿s secret key, and potentially execute arbitrary code on affected WordPress installations.


Solution


Apply appropriate security updates and mitigations as recommended below:

https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/



Vendor Information


ServMask

https://servmask.com/


References


 

https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/


CVE Name

CVE-2026-19949




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqiw7oACgkQ3jCgcSdc

ys9Y/BAAiSnxglYNTqnfOCu3W3UqzYGERLghR/DoiQvYPGgEK7Tk0gCk31cmes7c

eAI7RXLoHX7JpcNV99f4Iq2l3LfEAhM8YSes0KhN5mNCuCb8eB97VmByyC/GpyGd

eOXn176XbsOblZeP98rPegvFa6NKWyB29dLoiPgborF4bHGKLPJlFG5RpE8MQdO4

aCYsmIpFEQe9eSMIjVp4M4kaRkNssJqjZ6H0WitDh3mf0qzC5aQY/au3E1KBTaxL

kVnM+O8Tns5bVGAiB/0123KZ62aFcMqpbtrHfgjaW6/ZH4mytzBpb7UHYhQ1rgON

ovFnQGkKC8yWI38DWScEUeQd3hY6DUTjoFO1fET/KcxBB1bSYIvRA8pVM8uh0WWQ

3UCbKqidFqXm88UWLsXuP1XSWHSjtEtc+gHc+rDhT0ROthqkZlFwomVCOvWGrVFN

OG/VRbdkWxMK/YX5ySKFND1YGYk9zteDKfct8Ry+KfKhYTvHEAnycc/0C12QFTbC

fXFClv8s7b29yaZ9QXXzBYSCoC89hoPSTkBnWn3/T8nG/yvQUOk8vgi/HvuUevZn

RvtaMtzOWEoEZ2HGGcMgaYpgxH2AE09JQz64khbjswAPMHqwWdHP3eS0NT45vNiE

YfZe19hmN1/fDWYeuSj+gYPTMANWFt52NUe7Cylukgm5UBnlsU0=

=yGxK

—–END PGP SIGNATURE—–

Share this article