All-in-One WP Migration ≤7.109: second-order SQLi to RCE (CVE-2026-19949)
Wordfence (CNA) published CVE-2026-19949 for ServMask's All-in-One WP Migration and Backup WordPress plugin: unauthenticated second-order SQL injection in archive restore through 7.109. Jack Taylor reported it; Wordfence notified ServMask on 15 August 2026; fixed in 7.110 on 20 August 2026; CVE disclosed about 25 August. Incorrect parsing of escaped backslashes and quotes while rewriting database content lets an attacker plant SQL via trackbacks that runs when an admin restores a backup — core plugin use. Injected SQL can leak ai1wm_secret_key (e.g. via a public comment), then import a malicious .wpress archive for code execution and site takeover. Wordfence/BleepingComputer (2 September) cite about five million active installs and roughly 35% on the fixed build (~3.25 million still vulnerable). CVSS 3.1 8.8 High (Wordfence CNA). Patch to 7.110 or later; treat dormant installs that may be reactivated as in-scope.
- Product
- ServMask All-in-One WP Migration and Backup (WordPress)
- Versions
- Affected through 7.109; fixed in 7.110 (20 Aug 2026)
- CVSS
- (High, CVSS 3.1, Wordfence CNA)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- 7.110 or later; rotate ai1wm_secret_key / admin credentials if restore was done on a vulnerable build
Primary: Wordfence CVE-2026-19949 (CNA) · Vendor: NVD (CVE-2026-19949) · CVE: CVE-2026-19949 · BleepingComputer (2 Sep 2026)
