Critical Flaw in All-in-One WP Migration: What Every WordPress Site Owner Should Do Right Now

A backup plugin is meant to be your safety net. So it is a nasty irony that one of the most popular backup plugins on WordPress can, right now, be used to hand your entire website to an attacker.

If your site runs All-in-One WP Migration and Backup, this one is worth five minutes of your attention today. Below is the plain-English version: what has happened, whether it is being exploited, and exactly what to do about it.

The short version

  • A serious security flaw (tracked as CVE-2026-19949) was found in the All-in-One WP Migration and Backup plugin.
  • It affects every version up to and including 7.109, and is fixed in version 7.110.
  • The plugin is active on more than 5 million sites. When the flaw went public, roughly 3.25 million of them had not yet updated.
  • In the worst case, an attacker can chain the flaw into a full site takeover.
  • The fix is simple: update the plugin to 7.110 or later. Do it today.

What actually is the flaw?

Here is how it works in principle, without handing anyone a how-to guide.

The vulnerability is what security folks call a second-order SQL injection. The clever, and nasty, part is that the attack happens in two separate stages that can be days or weeks apart.

First, an attacker plants a booby-trapped piece of text through a normal public channel on your site, such as a trackback or comment. Nothing happens straight away. It just sits there in your database looking like ordinary content, so it does not trip any alarms.

The trap springs later, when a site administrator runs a completely routine action: restoring or exporting a backup with the plugin. During that process the plugin rewrites bits of your database, and the booby-trapped text breaks out of where it should be contained and runs as a database command. From there, an attacker can lift the plugin’s secret key and, ultimately, upload malicious code that gives them control of the site.

In short: a trusted, everyday maintenance task becomes the trigger for an attack that was set up in advance. That is why the flaw is rated 8.8 out of 10 for severity.

Is it being actively exploited?

This is the question that matters most, so here is the honest picture as it stands.

There is no confirmed evidence of this being exploited in the wild yet. It is not on the US government’s Known Exploited Vulnerabilities list, and the major security vendors reporting on it have not seen live attacks at the time of writing.

The catch: working exploit code is already circulating publicly. That usually shortens the runway before opportunistic attacks begin, especially with millions of sites still unpatched. The flaw was responsibly reported through the Wordfence bug bounty programme, and the fix has been available since 20 August 2026, so the window to get ahead of this is open right now.

Translation for busy owners: do not panic, but do not sit on it either. Patch this week.

What you need to do

Five practical steps, in order of priority.

  1. Update the plugin to 7.110 or later. In your WordPress dashboard go to Plugins, find All-in-One WP Migration and Backup, and update. This is the definitive fix.
  2. Double-check the version afterwards. Auto-updates are not always switched on, so confirm it now reads 7.110 or higher.
  3. If you genuinely cannot update, remove the plugin for now. A merely deactivated copy can still be a risk if it is ever switched back on to run a restore. Deleting it is safer until you can update.
  4. Do not run a backup restore or export until you have updated. That admin action is the trigger, so patch first, then restore.
  5. Have a quick look for anything odd. Unexpected admin users, plugins you do not recognise, or strange files are worth flagging. If you spot something, get help before doing anything else.

On a 4UCS managed plan? Here is how we protect you

If we look after your WordPress hosting, you are not standing on your own two feet here.

Our platform runs Imunify360 at the server level, which gives every site we host a layer of defence that sits underneath WordPress itself. That includes real-time Proactive Defence and malware scanning built to detect and block the PHP webshells and backdoors that an attack like this ultimately tries to install, plus a web application firewall that filters common injection attempts before they reach your site.

We want to be straight with you, though, because that is how we do things. This particular flaw is a second-order injection, which is deliberately designed to slip past request-level filtering by looking harmless until later. So the definitive fix is still updating the plugin to 7.110. That is exactly why we are already identifying any sites on our fleet still running a vulnerable version and getting them updated, on top of the server-level protection that is always running in the background.

If we manage your site and you would like us to confirm it is patched, just ask. We are happy to check it for you.

Frequently asked questions

Do I need to do anything if I do not use this plugin?

No. This flaw is specific to the All-in-One WP Migration and Backup plugin. If it is not installed, you are not affected by this one. It is still a good reminder to keep every plugin you do use up to date.

I updated the plugin. Am I safe now?

Updating to 7.110 or later closes the hole. If your site ran a backup restore or export while it was on an older version, it is worth a quick security check to be sure nothing was slipped in beforehand.

How do I know which version I am running?

In your WordPress dashboard, go to Plugins and look at the version number listed under All-in-One WP Migration and Backup. Anything below 7.110 needs updating.

Why does a backup plugin have access to do this much damage?

Backup and migration plugins need deep access to your database and files to do their job, which is precisely why a flaw in one can be so serious. It is a good argument for only running plugins you trust, and keeping them patched.

Need a hand?

Keeping on top of WordPress security is a constant job, and it is exactly the sort of thing we take off your plate. If you would like us to review your site, confirm your plugins are patched, or take the whole worry off your hands with managed hosting, we would love to help.

Get in touch with the 4U Computer Solutions team on 0800 48 2667, and we will get it sorted.

Sources

  • BleepingComputer, WordPress backup plugin flaw exposes millions of sites to takeover attacks (2 September 2026): bleepingcomputer.com
  • SecurityWeek, Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability (3 September 2026): securityweek.com
  • Patchstack vulnerability database, All-in-One WP Migration and Backup unauthenticated second-order SQL injectionpatchstack.com
  • CVE-2026-19949, National Vulnerability Database: nvd.nist.gov

4ucs-favicon

About 4U Computer Solutions

We’re a Taranaki-based managed service provider with long-standing experience supporting small and medium businesses across networking, servers, cloud, and security, backed by our own datacentre.

Technical Support Request

Fill out the form below.

Got a Question?

Fill out the form below.