An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

The plugin is used to back up, export, import, and move entire websites, including their databases, media, themes, and plugins, between servers or domains.

The security flaw is tracked as CVE-2026-19949 and received a high-severity score. It was discovered by security researcher Jack Taylor, who reported it in mid-August through Defiant's cybersecurity branch, Wordfence.

In a report yesterday, Wordfence researchers say that CVE-2026-19949 is a second-order SQL injection vulnerability that impacts All-in-One WP Migration and Backup versions throuhg 7.109.

The issue consists of incorrect parsing of escaped backslashes and quotation marks while the plugin rewrites database content during archive restoration.