SQL injection vulnerability in WordPress backup plugin exposes millions of sites to takeover attacks
All-in-One WP Migration and Backup plugin for WordPress has a high-severity SQL injection vulnerability that could allow attackers to take control of affected websites.
Intelligence analysis by Qwen 2.5 (3B)

A security flaw in the All-in-One WP Migration and Backup plugin for WordPress could expose millions of sites to takeover attacks, as reported by security researchers.
A security flaw in the WordPress backup plugin could let bad guys take control of your website. They do this by tricking the plugin into running bad code, and if they get in, they can do whatever they want on your site.
Analysis
{"heading_1":"The SQL Injection Vulnerability","paragraph_1":"The All-in-One WP Migration and Backup plugin for WordPress contains a SQL injection vulnerability that could allow attackers to execute remote code and take control of affected websites.","paragraph_2":"The vulnerability is a second-order SQL injection that impacts All-in-One WP Migration and Backup versions through 7.109, and it can be exploited by unauthenticated attackers through WordPress trackbacks.","paragraph_3":"The vulnerability can expose the plugin's secret import key (ai1wm_secret_key) through a public comment, allowing attackers to obtain it and import a malicious '.wpress' archive containing executable code.","paragraph_4":"Wordfence researchers reported the vulnerability to the plugin's developers, ServMask, on August 15, and the vulnerability was fixed in version 7.110 of the plugin on August 20.","paragraph_5":"The vulnerability affects millions of active installations of the All-in-One WP Migration and Backup plugin, with only approximately 35% of the plugin's user base having updated to the latest version."}
Key points
- All-in-One WP Migration and Backup plugin has a high-severity SQL injection vulnerability
- The vulnerability impacts millions of active installations of the plugin
- Only 35% of the plugin's user base has updated to the latest version
- The vulnerability can be exploited by unauthenticated attackers through WordPress trackbacks
- The vulnerability can expose the plugin's secret import key and allow attackers to import a malicious '.wpress' archive containing executable code
Once the vulnerability is fixed, the risk of attacks will decrease, and users will be more secure.
If the vulnerability is not fixed, attackers could still exploit it, leading to complete control of the affected websites.



