5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin
Unauthenticated second-order SQL injection found in All-in-One WP Migration and Backup plugin with 5+ million active installs.
Wordfence received a submission on August 14, 2026 for an unauthenticated second-order SQL injection vulnerability in the All-in-One WP Migration and Backup WordPress plugin. The plugin has more than 5 million active installations. The disclosure text does not include a CVE id, a patch version, or evidence of exploitation.
- Vulnerability class: unauthenticated second-order SQL injection.
- Plugin has over 5 million active WordPress installations.
- Reported to Wordfence on August 14, 2026.
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations. The post 5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin appeared first on Wordfence.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.