← Back to feed
vendor Wordfence Blog

5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin

Wordfence Blog WordPress

On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordP...

Read the full story Wordfence Blog →

Related Coverage

vendor PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core Wordfence Blog · Sep 22 vendor Unmasking EvilTokens: Getting to the root of device code phishing Microsoft Security Blog · Sep 22 vendor Inside a Malicious, Stealthy WordPress Must Use Plugin Wordfence Blog · Sep 22