TTO-2026-0903-002 · September 3, 2026 CriticalSupply Chain

All-in-One WP Migration CVE-2026-19949 Leaves 3.25 Million WordPress Sites Vulnerable — Backup Routine Detonates Hidden SQL Payload

wordpress.orgCVE-2026-19949 CVSS 8.8Second-order SQL injection5 million installs3.25 million unpatchedTrackback deliveryAdmin backup triggers exploitWAF bypassai1wm_secret_key exposedPatched Aug 20 version 7.110

Summary

A second-order SQL injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin installed on more than five million sites, allows unauthenticated attackers to plant a dormant payload via WordPress trackbacks that executes the moment an administrator performs a routine backup or site restore operation. CVE-2026-19949 was discovered by security researcher Jack Taylor and reported through Wordfence. Developer ServMask patched the vulnerability in version 7.110 on August 20, 2026, thirteen days before Wordfence published its public disclosure on September 2. As of September 3, approximately 35 percent of the plugin's user base has updated, leaving roughly 3.25 million sites running a vulnerable version. The vulnerability is a second-order SQL injection, meaning the malicious payload is not injected through a direct database query but is instead submitted as content that appears legitimate at the point of entry and only executes when a separate database operation processes it. An attacker plants crafted data through WordPress trackbacks, exploiting incorrect parsing of escaped backslashes and quotation marks during archive restoration. When an administrator subsequently exports or imports the site — a standard operation for a backup plugin — the injected SQL executes and exposes the plugin's secret import key, the ai1wm_secret_key. With this key, the attacker can import a malicious .wpress archive containing executable code, achieving remote code execution at the same privilege level as the WordPress application. Standard web application firewalls cannot block the attack because the payload is stored before execution, not injected live. A weaponized proof-of-concept exploit has been confirmed circulating in threat intelligence datasets.

Timeline

DateEvent
Mid-Aug 2026Researcher Jack Taylor discovers CVE-2026-19949 and reports through Wordfence
Aug 20, 2026ServMask releases All-in-One WP Migration and Backup version 7.110 — patches CVE-2026-19949
Sep 2, 2026Wordfence publishes full technical disclosure — weaponized PoC confirmed in threat intelligence datasets
Sep 3, 20263.25 million sites — 65% of install base — remain unpatched — standard WAF protection does not apply

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
wordpress.org60.45✓✓✓Live
WarmBadge Intelligence Snapshot · Captured: September 3, 2026 UTC

Context

wordpress.org scores 60.45 — a low-trust range score with a live consumer reputation signal for the official home of the world's most widely deployed content management system. The score reflects accumulated signals in WarmBadge's live intelligence. The architectural detail that makes CVE-2026-19949 operationally significant is the deferred trigger. An attacker can plant the payload weeks before exploitation occurs. The payload sits dormant in the database until an administrator runs a backup — an action that is not merely likely but is the entire purpose of the plugin. There is no unusual behavior to detect. The attack looks like a routine site operation until the moment the secret key is exposed. Organizations running All-in-One WP Migration and Backup should update to version 7.110 immediately and audit their trackback logs and comment records for crafted payloads before performing any backup or restore operations.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 3, 2026