Skip to main content
CyberSingle-sourceHighDeveloping
7.1

Critical SQLi in WordPress backup plugin enables unauthenticated site takeover

A critical SQL injection vulnerability in the All-in-One WP Migration and Backup plugin allows unauthenticated attackers to execute remote code and fully compromise affected WordPress sites. The flaw affects millions of installations, and while no active exploitation has been confirmed, the attack surface is vast. This is a high-severity supply-chain risk for the WordPress ecosystem, potentially enabling mass website defacement, data theft, and malware distribution.

BleepingComputerabout 19 hours agoengCredibility 55%View source

Score Breakdown

Mosaic Score7.1
Confidence0.5
Significance0.8
Source credibility0.6
Source

Related signals

8 found