DEV Community

BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

ServMask Patches Critical SQL Injection in All-in-One WP Migration Plugin

Summary

ServMask patched a high-severity SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin. The flaw allows unauthenticated attackers to leak secret keys and execute remote code when an administrator restores a site archive.

Take Action:

If you use the All-in-One WP Migration and Backup plugin, update it to version 7.110 or later ASAP. Even if the plugin is currently inactive, since it becomes dangerous the moment someone turns it on for a migration. Until you've patched, don't run any import or export, turn off trackbacks and pings on public posts, and check your comments for suspicious entries.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)