Popular WordPress Backup Plugin Flaw Puts Millions of Sites at Risk
Security researchers have discovered a serious SQL injection vulnerability in All-in-One WP Migration and Backup, a widely used WordPress plugin for exporting and restoring site data. The flaw allows attackers to send malicious database queries without needing to log in first, potentially letting them extract sensitive data or gain administrative access.
Because the plugin is installed on millions of WordPress sites for backup and migration purposes, the vulnerability creates a large attack surface. Successful exploitation could lead to full remote code execution, giving attackers the ability to plant malware, deface sites, or pivot into hosting infrastructure.
A patched version has reportedly been released, and site owners are urged to update immediately. As with many WordPress plugin flaws, the danger lies less in complexity and more in scale - once exploit code circulates, automated bots tend to scan the web for unpatched installs within days.