MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-02 · via Bleeping Computer

Critical SQL Injection in All-in-One WP Migration Plugin Risks Millions of Sites

An unauthenticated SQL injection vulnerability in the All-in-One WP Migration and Backup plugin allows remote code execution and full site takeover. Millions of WordPress installations using this popular backup plugin are exposed to potential attacks. The flaw requires no authentication, making it especially dangerous.

Expanded Detail

The flaw resides in the All-in-One WP Migration and Backup plugin, a widely used tool for transferring WordPress sites between hosts. Because the vulnerability requires no authentication, any unauthenticated attacker can exploit it remotely, potentially executing arbitrary code on the server. Successful exploitation grants full administrative control over the affected WordPress installation, allowing attackers to deface sites, inject malicious content, or steal sensitive data. The plugin's popularity means the exposure is broad, spanning personal blogs, small businesses, and larger organizations that rely on it for routine site migrations and backups. Given that backup plugins often hold elevated database privileges, the risk extends beyond the web root to underlying server infrastructure.

Context

This vulnerability could affect millions of website owners who rely on the plugin for routine backups, including small businesses, bloggers, and organizations with limited security resources. If exploited at scale, attackers may deface sites, redirect visitors to malicious pages, or harvest customer data, eroding trust in affected online services. The unauthenticated nature of the flaw means even poorly maintained sites are exposed, potentially amplifying the damage across the WordPress ecosystem.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Bleeping Computer →
Related stories
Critical Langflow bug exploited to steal OpenAI and AWS secrets · Cybersecurity
SonicWall SMA 1000 zero-day exploited for unauthenticated takeover · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “WordPress backup plugin flaw exposes millions of sites to takeover attacks.” Browse more stories.