CyberHighSingle-sourceAccelerating
7.1
Critical SQLi in WordPress Migration Plugin Exposes 3M+ Sites to RCE
SecurityWeek·about 9 hours ago
A critical SQL injection vulnerability in the All-in-One WP Migration and Backup plugin allows unauthenticated attackers to execute remote code and fully compromise affected WordPress sites. The flaw affects millions of installations, and while no active exploitation has been confirmed, the attack surface is vast. This is a high-severity supply-chain risk for the WordPress ecosystem, potentially enabling mass website defacement, data theft, and malware distribution.
Entities