Critical SQL Injection in All-in-One WP Migration Plugin Risks Millions of Sites
An unauthenticated SQL injection vulnerability in the All-in-One WP Migration and Backup plugin allows remote code execution and full site takeover. Millions of WordPress installations using this popular backup plugin are exposed to potential attacks. The flaw requires no authentication, making it especially dangerous.
The flaw resides in the All-in-One WP Migration and Backup plugin, a widely used tool for transferring WordPress sites between hosts. Because the vulnerability requires no authentication, any unauthenticated attacker can exploit it remotely, potentially executing arbitrary code on the server. Successful exploitation grants full administrative control over the affected WordPress installation, allowing attackers to deface sites, inject malicious content, or steal sensitive data. The plugin's popularity means the exposure is broad, spanning personal blogs, small businesses, and larger organizations that rely on it for routine site migrations and backups. Given that backup plugins often hold elevated database privileges, the risk extends beyond the web root to underlying server infrastructure.
This vulnerability could affect millions of website owners who rely on the plugin for routine backups, including small businesses, bloggers, and organizations with limited security resources. If exploited at scale, attackers may deface sites, redirect visitors to malicious pages, or harvest customer data, eroding trust in affected online services. The unauthenticated nature of the flaw means even poorly maintained sites are exposed, potentially amplifying the damage across the WordPress ecosystem.