Product
An unauthenticated SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin allows attackers to exfiltrate database contents, including secret keys, to facilitate remote code execution.