CyberHighSingle-sourceDeveloping
7.1
Critical SQLi in WordPress backup plugin enables unauthenticated site takeover
BleepingComputer·1 day ago
A high-severity SQL injection vulnerability (CVE-2026-19949) in a widely used WordPress migration plugin could let unauthenticated attackers achieve remote code execution, affecting over 3 million sites. The flaw is unpatched or partially patched, with no active exploitation reported yet. This represents a significant supply-chain risk to the WordPress ecosystem, potentially enabling mass website compromise.
Entities