Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.1

Critical SQLi in WordPress Migration Plugin Exposes 3M+ Sites to RCE

A high-severity SQL injection vulnerability (CVE-2026-19949) in a widely used WordPress migration plugin could let unauthenticated attackers achieve remote code execution, affecting over 3 million sites. The flaw is unpatched or partially patched, with no active exploitation reported yet. This represents a significant supply-chain risk to the WordPress ecosystem, potentially enabling mass website compromise.

SecurityWeekabout 9 hours agoengCredibility 56%View source

Score Breakdown

Mosaic Score7.1
Confidence0.5
Significance0.8
Source credibility0.6
Source

Related signals

8 found