Wordfence says CVE-2026-19949 affects All-in-One WP Migration and Backup through 7.109, and the vendor fixed it in 7.110, but only about 35% of the plugin’s five-million-plus installs have updated so far. The flaw was reported by security researcher Jack Taylor and disclosed through Wordfence.
The plugin misreads escaped backslashes and quotes while rebuilding database content during archive restoration. That lets crafted data planted earlier come back to life as SQL when an administrator restores a site, which can expose the secret import key and let an attacker load a malicious .wpress archive that can lead to full site takeover.
For WordPress sites that use this plugin to export and restore content, the exposure is not limited to the backup feature itself: a tampered archive can sit quietly until a routine admin restore turns it into code execution. That makes the restore workflow part of the trust boundary, and old archives can remain dangerous even after the plugin is patched.