A flaw in All-in-One WP Migration and Backup, a WordPress plugin installed on millions of sites, can let an unauthenticated attacker take over a site. Tracked as CVE-2026-19949, it is a second-order SQL injection caused by incorrect handling of escaped characters when the plugin rewrites database content during a restore. An attacker plants crafted data through WordPress trackbacks, which triggers when an administrator exports and imports the site, both routine plugin operations. The injection can leak the plugin's secret import key through a public comment, letting the attacker import a malicious backup archive containing executable code and seize full control. ServMask fixed it in version 7.110, but many sites remain unpatched.
Researchers at Wordfence and Patchstack disclosed a cluster of critical WordPress vulnerabilities, most scored 9.8, that let unauthenticated attackers take over sites or run code. In the WPMU DEV Dashboard plugin, CVE-2026-76581 is a single-sign-on authentication bypass that can hand an attacker an administrator session. The Avada theme's CVE-2026-18431 allows arbitrary file writes that lead to remote code execution. In the Pods plugin, CVE-2026-19598 lets an attacker escalate to administrator or overwrite any user's password, while TranslatePress's CVE-2026-19632 exposes the raw administrator password-reset link. Each independently enables full site compromise, and a separate GiveWP flaw in the same batch was covered earlier.