Bleepingcomputer iconBleepingcomputerSep 2, 2026

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

WordPress backup plugin flaw exposes millions of sites to takeover attacks

Share this story

Send the public story page.

Useful takeaways from this story.

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app