← Back to Feed
WordPress backup plugin flaw exposes millions of sites to takeover attacks
September 2, 2026 · BleepingComputer · Severity: HIGH
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.
Key Takeaways
- SQL injection in All-in-One WP Migration plugin allows unauthenticated remote code execution on WordPress sites.
- Millions of websites using the backup plugin are at risk of full takeover by attackers.
- Site owners must update the plugin immediately to patch the critical SQL injection vulnerability.