$ techbeacon▋
CVE & Exploits

Critical SQL Injection in Popular WordPress Migration Plugin Puts Millions at Risk

Critical SQL Injection in Popular WordPress Migration Plugin Puts Millions at Risk

Security researchers have identified a severe SQL injection flaw in the All-in-One WP Migration and Backup plugin for WordPress, a vulnerability that can be exploited without any credentials to run arbitrary code on vulnerable sites.

The plugin, which boasts millions of active installations, is widely used to move WordPress sites between servers and to create on‑demand backups. Its convenience has made it a staple for small businesses, freelancers, and larger enterprises alike.

According to the technical analysis, the flaw resides in a database query that fails to properly sanitize user‑supplied input passed to a specific API endpoint. By injecting crafted data, an attacker can manipulate the underlying SQL statement, ultimately achieving remote code execution on the host server.

The issue was first reported by BleepingComputer after a security researcher disclosed the findings to the plugin's developer, ServMask. The vendor responded by releasing an emergency update that addresses the vulnerable query and adds additional input validation. Users are urged to install the latest version immediately.

Because the exploit does not require authentication, threat actors can scan the internet for sites running the affected plugin and compromise them en masse. In the wild, compromised sites have been observed serving malicious JavaScript, redirecting visitors to phishing pages, and harvesting login credentials.

Site owners should verify that the plugin is updated to the patched release, review server logs for suspicious activity, and consider employing a web‑application firewall to block known attack patterns. Restoring clean backups and rotating compromised credentials are also recommended steps.

The discovery highlights the broader security challenges facing the WordPress ecosystem, where thousands of third‑party extensions extend core functionality. Experts say the incident underscores the need for rigorous code reviews, timely patch management, and continuous monitoring to protect the millions of websites that rely on the platform.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related