Critical SQL Injection Vulnerability Patched in All-in-One WP Migration: What You Need to Know
If your WordPress website relies on the All-in-One WP Migration and Backup plugin, used by over 5 million sites worldwide, you need to be aware of a serious security vulnerability recently discovered and patched.
At BG Cyber Connect, we take proactive security seriously. We are pleased to confirm that we have already updated all client sites using this plugin to the latest secure version. Here is what you need to know about this vulnerability and how we keep your business protected.
Understanding the Vulnerability
On August 14, 2026, security researcher Jack Taylor discovered and responsibly reported an Unauthenticated Second-Order SQL Injection vulnerability in the All-in-One WP Migration and Backup plugin. The Wordfence Bug Bounty Program awarded him $5,761.00 for this critical discovery.
What makes this vulnerability dangerous:
- It allows unauthenticated attackers (no login required) to inject malicious SQL code
- The attack is “second-order,” meaning the malicious input is stored during one action and only becomes dangerous when processed later.
- If successfully exploited, attackers can leak the plugin’s secret key
- With the secret key, they can achieve remote code execution, leading to complete site takeover
How the attack works:
The vulnerability exploits WordPress core’s trackback functionality, which does not require authentication. An attacker submits two specially crafted trackbacks to a public post. These trackbacks are stored in the comments table.
When a site administrator performs a backup export and then imports the site (a normal operation for this plugin), the stored malicious data becomes active. The plugin’s database processing logic fails to handle the payload correctly, allowing the attacker’s code to execute.
Through a multi-step process, the attacker can:
- Leak the plugin’s secret key from the database
- Read the leaked key via the site’s public comments REST API (no authentication required)
- Use the key to drive the plugin’s import action directly
The result: an attacker who has never logged into your site can take complete control.
The Timeline: A Responsible Disclosure
The plugin developer, ServMask, responded promptly to the report:
| Date | Event |
|---|---|
| August 14, 2026 | Vulnerability discovered and reported |
| August 15, 2026 | Full disclosure details provided to ServMask |
| August 16, 2026 | Wordfence Premium users received firewall protection |
| August 17, 2026 | Developer acknowledged the report |
| August 20, 2026 | Patched version (7.110) released |
“We would like to commend the ServMask team for their prompt response and timely patch.”
— Wordfence Security Team
What This Means for Your Business
This vulnerability affects any WordPress site running All-in-One WP Migration and Backup versions before 7.110. If your site is on an older version, you are at risk of:
- Unauthenticated site takeover by attackers
- Data leakage including sensitive plugin keys
- Complete compromise of your website, customer data, and business operations
How BG Cyber Connect Protects Your Business
At BG Cyber Connect, we believe in proactive, layered security. When critical vulnerabilities like this emerge, we act immediately to protect our clients.
We are pleased to confirm:
✅ All BGCC client sites using the All-in-One WP Migration plugin have been updated to the patched version (7.110 or later).
✅ We continue to monitor for new vulnerabilities and apply critical security patches as they become available.
✅ Our clients benefit from ongoing security vigilance, not just reactive fixes.
What You Can Do to Stay Protected
If you manage your own WordPress site and use this plugin, take these steps immediately:
- Update the plugin to version 7.110 or later
- Log in to your WordPress dashboard
- Navigate to Plugins → Installed Plugins
- Find “All-in-One WP Migration and Backup” and click “Update Now”
- Check your site’s comments for suspicious trackback entries. While the vulnerability has been patched, any existing malicious entries should be removed.
- Enable a Web Application Firewall (WAF) to protect against exploit attempts. Wordfence Premium users received protection on August 16, and free users will receive it on September 15, 2026.
- Consider professional security monitoring. Keeping your site secure requires constant vigilance—something we specialise in at BGCC.
The Bottom Line
This vulnerability serves as a reminder: even the most popular, well-maintained plugins can contain critical flaws. Proactive patch management and professional security oversight are not optional—they are essential for protecting your business.
We are proud to have acted swiftly to protect our clients, ensuring that every site we manage is secure against this threat.
Need Help Securing Your WordPress Site?
Don’t leave your website’s security to chance. Contact BG Cyber Connect for a comprehensive security assessment and ongoing protection.
Contact BGCC for a Free Security Assessment
Explore our WordPress security services:
BGCC Cybersecurity Solutions


