WordPress backup plugin flaw exposes millions of sites to takeover attacks
Executive Summary
An SQL injection flaw in the All‑in‑One WP Migration and Backup plugin for WordPress allows unauthenticated attackers to inject malicious SQL, leading to remote code execution and full site takeover. The vulnerability affects millions of sites, enabling attackers to gain administrative control without credentials.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-02T19:28:46+00:00 - Category: threat-intel
Original Description: An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
"Let us revere, let us worship, but erect and open-eyed, the highest, not the lowest; the future, not the past!"
— Charlotte Gilman