Skip to main content
Security

WordPress migration plugin flaw leaves millions of sites exposed

WordPress migration plugin flaw leaves millions of sites exposed Image: Primary
Wordfence reported that CVE-2026-19949, a second-order SQL-injection flaw in All-in-One WP Migration and Backup through version 7.109, can lead to remote code execution and takeover of affected WordPress sites. An unauthenticated attacker can plant data through trackbacks that executes when an administrator exports and imports a site, potentially exposing the plugin's import key and enabling a malicious archive. ServMask fixed the issue in version 7.110, but the report says about 3.25 million sites remain on vulnerable releases.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security AI
Security AI

Google opens Fairwind cyber-defense program to selected partners

Google said it launched the Fairwind Program for a trusted group of Google Cloud customers, government agencies and cybersecurity partners. The program initially provides access to Gemini 3.8 Flash Cyber and the CodeMender harness...

Security
Security

Act Security acquires Cloud Copilot and releases Amphi toolkit

Act Security has acquired Cloud Copilot, an open-source project for analyzing AWS access permissions, and is using it as the basis for a new toolkit called Amphi. The company said Amphi offers seven tools to test and analyze AWS ...

Security
Security

Anthropic and OpenAI report new controls for advanced cyber models

Anthropic and OpenAI reported new access limits and safeguards around advanced cybersecurity models. Anthropic said Claude Mythos 5.1 is limited to trusted-access programs and support work in cybersecurity and life sciences, while...

Security
Security

Bogus download sites deploy malware that disables Windows protections

Microsoft reported an active malware campaign using counterfeit software-download sites to distribute malicious installers, primarily affecting China-based operations of multinational organizations and Chinese-speaking users. The ...