{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/all-in-one-wp-migration-and-backup--7.109/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-19949"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CVE-2026-19949\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["All-in-One WP Migration and Backup (\u003c= 7.109)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ServMask"],"content_html":"\u003cp\u003eThe All-in-One WP Migration and Backup plugin for WordPress (up to version 7.109) contains a critical SQL injection vulnerability identified as CVE-2026-19949. The vulnerability exists within the archive restore functionality, where insufficient escaping of user-supplied parameters and improper preparation of SQL queries allow an unauthenticated attacker to manipulate database interactions. By injecting malicious SQL statements, an attacker can extract sensitive information directly from the WordPress database. A primary target for this exfiltration is the 'ai1wm_secret_key'. Once this key is obtained, it can be leveraged to bypass authentication or manipulate plugin operations, ultimately enabling remote code execution (RCE) on the host environment. This flaw presents a significant risk to WordPress installations utilizing this plugin, as it provides a clear path from initial unauthenticated access to full system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary data from the WordPress database. The exfiltration of the 'ai1wm_secret_key' can lead to complete site takeover via remote code execution, posing a risk of data theft, site defacement, or persistent unauthorized access across affected WordPress installations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the 'All-in-One WP Migration and Backup' plugin to the latest version (v7.110 or later) that contains the patch for CVE-2026-19949.\u003c/li\u003e\n\u003cli\u003eAudit WordPress database logs for unusual SQL patterns or unexpected queries originating from the webserver process user.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected administrative actions or plugin configuration changes following the restoration of site archives.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block POST requests containing common SQL injection payloads targeted at the plugin's restore endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T16:17:01Z","date_published":"2026-08-25T14:08:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-19949/","summary":"An unauthenticated SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin allows attackers to exfiltrate database contents, including secret keys, to facilitate remote code execution.","title":"SQL Injection in All-in-One WP Migration and Backup Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-19949/"}],"language":"en","title":"CraftedSignal Threat Feed - All-in-One WP Migration and Backup (\u003c= 7.109)","version":"https://jsonfeed.org/version/1.1"}