← Back to Tech & Science

Critical SQL Injection Flaw in Popular WordPress Plugin Exposes Millions of Sites to Remote Takeover

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A severe security vulnerability discovered in the All-in-One WP Migration and Backup plugin for WordPress allows unauthenticated attackers to execute remote code and seize control of affected websites globally. The flaw, identified as an SQL injection error, stems from incorrect parsing of escaped backslashes and quotation marks during the archive restoration process. It impacts all versions of the plugin through 7.109, potentially exposing millions of sites worldwide that rely on the tool for site management and data transfer.

The vulnerability was disclosed by security researcher Jack Taylor, who detailed how an attacker could exploit the parsing error to inject malicious SQL commands. Unlike many web vulnerabilities that require user login credentials, this flaw permits exploitation without any authentication, significantly lowering the barrier for malicious actors. Successful exploitation grants attackers full administrative access, enabling them to deface sites, steal sensitive data, or deploy ransomware.

ServMask, the developer behind the All-in-One WP Migration plugin, has acknowledged the issue and is working on a patch. The company stated that the error occurs specifically when the plugin attempts to restore archived site data, a function frequently used by administrators moving content between servers or recovering from backups. Wordfence, a leading cybersecurity firm specializing in WordPress protection, has also confirmed the severity of the threat and issued alerts to its user base regarding the risk.

The timing of the disclosure is critical as the plugin remains one of the most widely installed migration tools in the WordPress ecosystem. With no authentication required, automated bots scanning for vulnerable targets can exploit the flaw immediately upon discovery. Security experts warn that until a fix is deployed and applied across all affected installations, sites remain at high risk of compromise.

Administrators using the plugin are urged to update immediately once a patched version is released or to disable the migration functionality temporarily if an update is not yet available. The specific mechanics of the exploit involve manipulating input fields during the restoration phase to bypass standard security filters. This allows malicious code to be interpreted as valid database commands, effectively giving the attacker direct access to the underlying server infrastructure.

As of now, no widespread exploitation has been publicly confirmed, though the nature of the vulnerability suggests that opportunistic attacks are likely imminent. The global impact depends on how quickly site owners can identify and remediate the issue across their networks. Questions remain regarding whether any active campaigns have already targeted specific high-profile sites or if the vulnerability is currently being used in automated sweeps. Until ServMask releases a definitive fix and users apply it, the window for potential compromise remains open.

Discussion

0 / 2000