Explore our Insights

Critical Flaw in All-in-One WP Migration: What Every WordPress Site Owner Should Do Right Now

A backup plugin is meant to be your safety net. So it is a nasty irony that one of the most popular backup plugins on WordPress can, right now, be used to hand your entire website to an attacker.

If your site runs All-in-One WP Migration and Backup, this one is worth five minutes of your attention today. Below is the plain-English version: what has happened, whether it is being exploited, and exactly what to do about it.

The short version

  • A serious security flaw (tracked as CVE-2026-19949) was found in the All-in-One WP Migration and Backup plugin.
  • It affects every version up to and including 7.109, and is fixed in version 7.110.
  • The plugin is active on more than 5 million sites. When the flaw went public, roughly 3.25 million of them had not yet updated.
  • In the worst case, an attacker can chain the flaw into a full site takeover.
  • The fix is simple: update the plugin to 7.110 or later. Do it today.

What actually is the flaw?

Here is how it works in principle, without handing anyone a how-to guide.

The vulnerability is what security folks call a second-order SQL injection. The clever, and nasty, part is that the attack happens in two separate stages that can be days or weeks apart.

First, an attacker plants a booby-trapped piece of text through a normal public channel on your site, such as a trackback or comment. Nothing happens straight away. It just sits there in your database looking like ordinary content, so it does not trip any alarms.

The trap springs later, when a site administrator runs a completely routine action: restoring or exporting a backup with the plugin. During that process the plugin rewrites bits of your database, and the booby-trapped text breaks out of where it should be contained and runs as a database command. From there, an attacker can lift the plugin’s secret key and, ultimately, upload malicious code that gives them control of the site.

In short: a trusted, everyday maintenance task becomes the trigger for an attack that was set up in advance. That is why the flaw is rated 8.8 out of 10 for severity.

Is it being actively exploited?

This is the question that matters most, so here is the honest picture as it stands.

There is no confirmed evidence of this being exploited in the wild yet. It is not on the US government’s Known Exploited Vulnerabilities list, and the major security vendors reporting on it have not seen live attacks at the time of writing.

The catch: working exploit code is already circulating publicly. That usually shortens the runway before opportunistic attacks begin, especially with millions of sites still unpatched. The flaw was responsibly reported through the Wordfence bug bounty programme, and the fix has been available since 20 August 2026, so the window to get ahead of this is open right now.

Translation for busy owners: do not panic, but do not sit on it either. Patch this week.

What you need to do

Five practical steps, in order of priority.

  1. Update the plugin to 7.110 or later. In your WordPress dashboard go to Plugins, find All-in-One WP Migration and Backup, and update. This is the definitive fix.
  2. Double-check the version afterwards. Auto-updates are not always switched on, so confirm it now reads 7.110 or higher.
  3. If you genuinely cannot update, remove the plugin for now. A merely deactivated copy can still be a risk if it is ever switched back on to run a restore. Deleting it is safer until you can update.
  4. Do not run a backup restore or export until you have updated. That admin action is the trigger, so patch first, then restore.
  5. Have a quick look for anything odd. Unexpected admin users, plugins you do not recognise, or strange files are worth flagging. If you spot something, get help before doing anything else.

On a 4UCS managed plan? Here is how we protect you

If we look after your WordPress hosting, you are not standing on your own two feet here.

Our platform runs Imunify360 at the server level, which gives every site we host a layer of defence that sits underneath WordPress itself. That includes real-time Proactive Defence and malware scanning built to detect and block the PHP webshells and backdoors that an attack like this ultimately tries to install, plus a web application firewall that filters common injection attempts before they reach your site.

We want to be straight with you, though, because that is how we do things. This particular flaw is a second-order injection, which is deliberately designed to slip past request-level filtering by looking harmless until later. So the definitive fix is still updating the plugin to 7.110. That is exactly why we are already identifying any sites on our fleet still running a vulnerable version and getting them updated, on top of the server-level protection that is always running in the background.

If we manage your site and you would like us to confirm it is patched, just ask. We are happy to check it for you.

Frequently asked questions

Do I need to do anything if I do not use this plugin?

No. This flaw is specific to the All-in-One WP Migration and Backup plugin. If it is not installed, you are not affected by this one. It is still a good reminder to keep every plugin you do use up to date.

I updated the plugin. Am I safe now?

Updating to 7.110 or later closes the hole. If your site ran a backup restore or export while it was on an older version, it is worth a quick security check to be sure nothing was slipped in beforehand.

How do I know which version I am running?

In your WordPress dashboard, go to Plugins and look at the version number listed under All-in-One WP Migration and Backup. Anything below 7.110 needs updating.

Why does a backup plugin have access to do this much damage?

Backup and migration plugins need deep access to your database and files to do their job, which is precisely why a flaw in one can be so serious. It is a good argument for only running plugins you trust, and keeping them patched.

Need a hand?

Keeping on top of WordPress security is a constant job, and it is exactly the sort of thing we take off your plate. If you would like us to review your site, confirm your plugins are patched, or take the whole worry off your hands with managed hosting, we would love to help.

Get in touch with the 4U Computer Solutions team on 0800 48 2667, and we will get it sorted.

Sources

  • BleepingComputer, WordPress backup plugin flaw exposes millions of sites to takeover attacks (2 September 2026): bleepingcomputer.com
  • SecurityWeek, Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability (3 September 2026): securityweek.com
  • Patchstack vulnerability database, All-in-One WP Migration and Backup unauthenticated second-order SQL injectionpatchstack.com
  • CVE-2026-19949, National Vulnerability Database: nvd.nist.gov

3 Things Every Business Should Be Backing Up | Business Data Backup Tips

Most businesses know they should be backing up their data.

The problem is that many are not entirely sure what they should be backing up, where those backups are stored, or whether they would actually work when needed.

And unfortunately, the worst time to find out your backup plan has a few holes in it is right after something has gone wrong.

A good backup strategy is not just about protecting files. It is about keeping your business running when technology decides to have a dramatic moment.

Here are three important things every business should be backing up.

1. Business Files and Documents

This is the obvious one, but it is still worth mentioning.

Your business files are often the backbone of your day-to-day operations. This can include:

  • Client records
  • Quotes and invoices
  • Spreadsheets
  • Contracts
  • Policies and procedures
  • Project files
  • Photos, designs, and marketing materials
  • Shared folders used by your team

If these files disappeared tomorrow, how much trouble would your business be in?

For many businesses, the answer is: quite a lot.

Cloud storage tools such as OneDrive, SharePoint, Google Drive, and Dropbox are useful, but it is important to understand that syncing is not always the same as backing up.

We’ve all accidentally deleted the wrong file. Usually it’s the one you actually needed five minutes later.

If a file is accidentally deleted, overwritten, corrupted, or affected by ransomware, that change may sync across all connected devices. In other words, your very efficient cloud storage can efficiently copy the problem everywhere. Handy, but not ideal.

That is why businesses should have proper backups in place, not just file syncing.

A strong backup setup should allow you to recover previous versions of files, restore deleted items, and access critical business data if a device fails or an account becomes unavailable.

2. Email and Microsoft 365 Data

Email has become the filing cabinet of modern business.

Quotes, invoices, customer conversations, meeting notes, approvals, supplier information… it’s all there. Add in your OneDrive files, Teams conversations, SharePoint documents, and suddenly Microsoft 365 contains a huge portion of your business.

Because it’s stored in the cloud, many people assume it’s automatically backed up forever.

The reality is a little more complicated.

Microsoft provides excellent availability for its services, but businesses are still responsible for protecting their own data. If emails or files are accidentally deleted, accounts are compromised, or important information is removed, recovery options can be limited depending on how long it’s been.

That’s why many businesses choose to have a dedicated Microsoft 365 backup.

It provides another layer of protection for your emails, OneDrive, SharePoint, Teams, and other Microsoft 365 data, giving you greater flexibility if you ever need to recover something important.

If your Microsoft 365 licensing is managed through 4U Computer Solutions, we can also provide Microsoft 365 backup services, helping protect one of the most valuable parts of your business.

After all, “I know that email exists somewhere…” isn’t a search function.

3. Devices, Servers, and Line-of-Business Systems

The third area businesses should consider is the systems they rely on to actually operate.

Depending on your business, this could include:

  • Desktop computers
  • Laptops
  • Servers
  • Accounting software
  • Job management systems
  • Databases
  • Point-of-sale systems
  • Industry-specific applications

Some of these systems may store data locally, while others may rely on cloud services. Either way, it is worth knowing exactly where the important information lives and how it can be restored.

For example, if a key computer failed, could another staff member continue working? If your server went down, how long would it take to get back online? If your accounting or job management data became unavailable, what would that mean for your team?

Backups are not only about disaster recovery. They also help with everyday problems, such as accidental deletion, hardware failure, software corruption, or staff changes.

A backup plan should consider both the data itself and the time it would take to recover it.

Because while having a backup is great, waiting three days to restore it while everyone stands around making cups of tea is not much of a business continuity plan.

Backup Is Only Useful If It Can Be Restored

One of the most important parts of any backup strategy is testing.

A backup that has never been tested is more of a hopeful theory than a reliable plan.

Businesses should regularly check:

  • What is being backed up
  • How often backups run
  • Where backups are stored
  • How long backups are kept
  • How quickly data can be restored
  • Who is responsible for checking them

It is also worth having backups stored separately from the original data. If your only backup is connected to the same computer, account, or network, it may be affected by the same issue that caused the data loss in the first place.

A good backup strategy usually includes multiple layers, such as local backups, cloud backups, and secure off-site storage.

Think of backups like insurance. You hope you never need them, but you’ll be very pleased they’re there if you do.

Need Help Reviewing Your Backups?

Every business is different, so there is no one-size-fits-all backup plan.

A small office using Microsoft 365 will have different needs from a business running local servers, specialist software, or large amounts of customer data.

At 4U Computer Solutions, we help businesses understand what data needs protecting, where it is stored, and how it can be recovered if something goes wrong.

If you are not sure whether your current backup setup is doing what it should, get in touch with our team. We can review your existing systems and help identify any gaps before they become a much bigger problem.

And remember, there are two kinds of businesses: those that back up their data, and those that are about to start.

Using AI at Work Without Accidentally Sharing Your Business Secrets

AI tools like ChatGPT, Gemini, and Copilot are quickly becoming part of everyday business life.

They’re helping people write emails, summarise documents, brainstorm ideas, and save time on repetitive tasks. Used well, they’re a fantastic productivity tool.

Used poorly? They can become a very efficient way to share information you never intended to leave your business.

Before you ask AI to help with your next task, it’s worth understanding what information should stay out of the prompt box.

Why Businesses Need to Be Careful

Many public AI tools process the information you provide through their cloud platforms. Depending on the service and settings being used, that information may be stored, reviewed, or used to improve future services.

That’s not necessarily a problem: until someone copies confidential business information into a chatbot.

We’ve seen examples of businesses accidentally sharing:

  • Customer information
  • Financial data
  • Internal procedures
  • Pricing information
  • Contracts and agreements
  • Source code and technical documentation

It only takes one well-meaning employee trying to save a few minutes for sensitive information to end up somewhere it shouldn’t.

Think of public AI tools like a meeting room full of strangers. Useful? Absolutely. The ideal place to discuss payroll information? Probably not.

Create Some Ground Rules for AI

You don’t need a 40-page policy document that nobody reads.

A simple set of guidelines can go a long way.

Your team should know:

  • What information is considered confidential
  • What data should never be entered into public AI tools
  • Which AI platforms are approved for business use
  • When to ask for guidance before using AI

For many businesses, a simple rule works well:

If you wouldn’t post it on your company Facebook page, don’t paste it into a public AI tool.

Choosing the Right AI Tool for Your Business

Not all AI tools are created equal.

Many businesses start by using free public AI platforms because they’re easy to access and require little setup. While these tools can be useful, they may not offer the same level of administrative control, security, or integration that businesses need.

If your organisation already uses Microsoft 365, it’s worth exploring the AI options available within the Microsoft ecosystem.

Microsoft Copilot integrates with Microsoft 365 applications such as Outlook, Word, Teams, and Excel, allowing staff to work more efficiently within the tools they already use every day.

For businesses looking to embrace AI while maintaining greater control over their environment, a managed solution may be a better fit than relying solely on public AI tools.

The right choice depends on your business needs, how AI will be used, and the type of information your staff are working with.

Consider Data Protection Tools

As AI becomes more common in the workplace, security tools are evolving alongside it.

Solutions such as Microsoft Purview and other Data Loss Prevention (DLP) platforms can help identify and block sensitive information before it leaves your organisation.

These tools can detect things like:

  • Personal information
  • Financial records
  • Customer data
  • Confidential documents

They’re not necessary for every business, but for organisations handling sensitive information, they can provide an extra layer of protection.

Train People, Not Just Technology

Technology can help reduce risk, but people are still the most important part of the equation.

Regular conversations about AI usage, privacy, and data security help employees understand where the boundaries are.

Rather than banning AI altogether, focus on teaching staff how to use it safely.

For example:

Instead of entering a customer’s full details into an AI tool, remove identifying information first.

Instead of uploading a confidential document, provide a simplified example.

The goal isn’t to stop people using AI. It’s to help them use it responsibly.

AI Isn’t Going Away

Whether we like it or not, AI is becoming part of modern business.

The businesses that benefit most won’t be the ones that avoid it. They’ll be the ones that use it effectively while protecting their data, customers, and reputation.

Like any tool, AI works best when used with a bit of common sense.

After all, most people wouldn’t hand their client database to a random stranger in a café.

The same principle applies online.

Need Help Safely Implementing AI in Your Business?

At 4U Computer Solutions, we’re helping businesses understand how emerging technologies fit into their existing security practices.

If you’re exploring AI tools and want to make sure you’re protecting your business data at the same time, we’re happy to help.

Because while AI can save time, explaining to your customers why their information ended up somewhere it shouldn’t definitely won’t.

Data Breach Check: Has Your Business Email Been Exposed?

Most business owners assume their email accounts are secure until they discover their details have already been exposed in a data breach.

The good news? There’s a simple, free way to find out.

Check Your Email with Have I Been Pwned

A website called Have I Been Pwned (haveibeenpwned.com) allows you to check whether your email address has appeared in any known data breach.

Created and maintained by respected cybersecurity researcher Troy Hunt, the service is trusted worldwide and takes less than a minute to use.

We recommend starting with your primary work email address and then checking the key members of your team as well.

What the Results Can Tell You

If your email address appears in a breach, the site will show:

  • Which company or website experienced the breach
  • When the data breach occurred
  • What types of information were exposed

Depending on the incident, the leaked data may include:

  • Email addresses
  • Passwords (usually in a hashed format)
  • Personal details
  • Account information
  • Security questions and answers

Understanding what information has been exposed can help you assess your risk and take action before cybercriminals do.

Why This Matters

One of the biggest cybersecurity risks businesses face isn’t the data breach itself. It’s password reuse.

When attackers gain access to leaked usernames and passwords, they often use automated tools to test those credentials across hundreds of different services. This tactic, known as credential stuffing, is surprisingly effective because many people reuse the same password across multiple accounts.

A data breach on an unrelated website could potentially give attackers access to your business systems if the same password has been used elsewhere.

What To Do If Your Email Appears in a Breach

If your email address shows up in the results:

  1. Review which services were affected by the data breach.
  2. Change any passwords that may still be in use.
  3. Replace reused passwords with unique passwords for every account.
  4. Enable Multi-Factor Authentication (MFA) wherever possible.
  5. Check whether any business systems, Microsoft 365 accounts, or shared team logins could be affected.

These simple steps can significantly reduce the risk of unauthorised access to your business accounts.

The Hidden Risk for Small Businesses

Many business owners discover their email address has appeared in a data breach and assume the incident is old news.

Unfortunately, cybercriminals don’t see it that way.

Leaked credentials often remain in circulation for years and are regularly used in automated attacks against Microsoft 365, Google Workspace, online banking, cloud storage, and other business services.

Even if the original breach happened a decade ago, a reused password could still leave your business vulnerable today.

That’s why it’s important to look beyond the data breach itself and understand what impact it could have on your current systems.

Not Sure What Your Results Mean?

Finding your email in a data breach doesn’t necessarily mean your accounts have been compromised, but it does mean it’s worth taking a closer look.

At 4U Computer Solutions, we regularly help businesses identify potential security risks, improve password practices, and strengthen account security through measures such as Multi-Factor Authentication, Microsoft 365 security settings, and security best practices.

If you’ve run a check and aren’t sure whether the results are cause for concern, get in touch with our team. We can help you understand what you’ve found, identify any areas of risk, and recommend practical next steps to improve your security.

Sometimes the answer is as simple as changing a few passwords. Other times, it’s uncovering a security issue before it becomes a costly problem.

A quick check today could save a significant amount of stress, downtime, and expense tomorrow.

Want a Second Opinion?

If you’d like help reviewing your results or want advice on improving your business’s cybersecurity, contact the team at 4U Computer Solutions. We’re happy to provide practical guidance and help you make informed decisions about protecting your business.

4ucs-favicon

About 4U Computer Solutions

We’re a Taranaki-based managed service provider with long-standing experience supporting small and medium businesses across networking, servers, cloud, and security, backed by our own datacentre.

Technical Support Request

Fill out the form below.

Got a Question?

Fill out the form below.