Vulnerability
Published 2026-08-25
Verified 2026-09-19

All-in-One WP Migration ≤7.109: second-order SQLi to RCE (CVE-2026-19949)

Wordfence (CNA) published CVE-2026-19949 for ServMask's All-in-One WP Migration and Backup WordPress plugin: unauthenticated second-order SQL injection in archive restore through 7.109. Jack Taylor reported it; Wordfence notified ServMask on 15 August 2026; fixed in 7.110 on 20 August 2026; CVE disclosed about 25 August. Incorrect parsing of escaped backslashes and quotes while rewriting database content lets an attacker plant SQL via trackbacks that runs when an admin restores a backup — core plugin use. Injected SQL can leak ai1wm_secret_key (e.g. via a public comment), then import a malicious .wpress archive for code execution and site takeover. Wordfence/BleepingComputer (2 September) cite about five million active installs and roughly 35% on the fixed build (~3.25 million still vulnerable). CVSS 3.1 8.8 High (Wordfence CNA). Patch to 7.110 or later; treat dormant installs that may be reactivated as in-scope.

Product
ServMask All-in-One WP Migration and Backup (WordPress)
Versions
Affected through 7.109; fixed in 7.110 (20 Aug 2026)
CVSS
(High, CVSS 3.1, Wordfence CNA)
Exploited in Australia?
unknown
Patch to
7.110 or later; rotate ai1wm_secret_key / admin credentials if restore was done on a vulnerable build

Primary: Wordfence CVE-2026-19949 (CNA) · Vendor: NVD (CVE-2026-19949) · CVE: CVE-2026-19949 · BleepingComputer (2 Sep 2026)

vulnerabilities cloud