GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

Popular WordPress Backup Plugin Flaw Puts Millions of Sites at Risk

An unauthenticated SQL injection bug in All-in-One WP Migration and Backup could let attackers hijack sites and run malicious code.

Security researchers have discovered a serious SQL injection vulnerability in All-in-One WP Migration and Backup, a widely used WordPress plugin for exporting and restoring site data. The flaw allows attackers to send malicious database queries without needing to log in first, potentially letting them extract sensitive data or gain administrative access.

Because the plugin is installed on millions of WordPress sites for backup and migration purposes, the vulnerability creates a large attack surface. Successful exploitation could lead to full remote code execution, giving attackers the ability to plant malware, deface sites, or pivot into hosting infrastructure.

A patched version has reportedly been released, and site owners are urged to update immediately. As with many WordPress plugin flaws, the danger lies less in complexity and more in scale - once exploit code circulates, automated bots tend to scan the web for unpatched installs within days.

Why it matters: WordPress powers a huge share of the web, and plugin vulnerabilities like this are a recurring soft spot because updates often lag behind disclosure. Backup and migration tools are especially juicy targets since they inherently have deep database access, making them a high-value single point of failure for site security.

Sources: BleepingComputer