Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: site-takeover (2 articles)Clear

WordPress backup plugin flaw lets attackers hijack sites through a poisoned import

A flaw in All-in-One WP Migration and Backup, a WordPress plugin installed on millions of sites, can let an unauthenticated attacker take over a site. Tracked as CVE-2026-19949, it is a second-order SQL injection caused by incorrect handling of escaped characters when the plugin rewrites database content during a restore. An attacker plants crafted data through WordPress trackbacks, which triggers when an administrator exports and imports the site, both routine plugin operations. The injection can leak the plugin's secret import key through a public comment, letting the attacker import a malicious backup archive containing executable code and seize full control. ServMask fixed it in version 7.110, but many sites remain unpatched.

Check
Update All-in-One WP Migration and Backup to 7.110 or later across all WordPress sites, and review sites for suspicious trackback comments, unexpected admin accounts, and unfamiliar files.
Affected
WordPress sites running All-in-One WP Migration and Backup through 7.109 (CVE-2026-19949); an unauthenticated attacker can plant SQL injection that leaks the plugin's secret key, enabling a malicious archive import and site takeover.
Fix
Patch the plugin, scan for web shells and unexpected files, audit administrator accounts, rotate WordPress secrets, disable trackbacks if not needed, and put a web application firewall in front of the site.

Critical WordPress plugin and theme flaws let unauthenticated attackers seize sites

Researchers at Wordfence and Patchstack disclosed a cluster of critical WordPress vulnerabilities, most scored 9.8, that let unauthenticated attackers take over sites or run code. In the WPMU DEV Dashboard plugin, CVE-2026-76581 is a single-sign-on authentication bypass that can hand an attacker an administrator session. The Avada theme's CVE-2026-18431 allows arbitrary file writes that lead to remote code execution. In the Pods plugin, CVE-2026-19598 lets an attacker escalate to administrator or overwrite any user's password, while TranslatePress's CVE-2026-19632 exposes the raw administrator password-reset link. Each independently enables full site compromise, and a separate GiveWP flaw in the same batch was covered earlier.

Check
Inventory your WordPress sites for the WPMU DEV Dashboard, Avada, Pods, and TranslatePress components, and update each to its patched version now, prioritizing internet-facing and multi-author sites.
Affected
Sites running vulnerable versions of WPMU DEV Dashboard, Avada, Pods, or TranslatePress (CVE-2026-76581, CVE-2026-18431, CVE-2026-19598, CVE-2026-19632); unauthenticated attackers can gain admin access, reset passwords, or execute code.
Fix
Patch every affected plugin and theme, audit for unexpected admin accounts, changed passwords, and new PHP files, front sites with a web application firewall, and rotate credentials on any exposed site.