All-in-One WP Migration and Backup: unauthenticated SQL injection via archive restore
Unauthenticated SQL injection in All-in-One WP Migration and Backup plugin (versions through 7.109) allows database extraction and conditional RCE via the ai1wm_secret_key.
- Vendor
- ServMask
- Product
- All-in-One WP Migration and Backup (WordPress plugin)
- CVSS
- 8.8
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
The All-in-One WP Migration and Backup plugin for WordPress contains a SQL injection vulnerability in its archive restore functionality, affecting all versions through 7.109. The plugin passes a user-supplied parameter to an existing database query without sufficient escaping or preparation, allowing an unauthenticated attacker to append additional SQL and extract database contents.
Among the data an attacker can extract is the plugin’s internal ai1wm_secret_key. Per the NVD advisory, that key can be leveraged for remote code execution when a site administrator triggers an archive restore operation. The conditional nature of the attack path, requiring an active restore, accounts for the CVSS score of 8.8 (high) rather than critical.
The vulnerability affects approximately three million WordPress installations. Administrators should update to any plugin version above 7.109. Sites with WordPress automatic plugin updates enabled will receive the patch without manual intervention.
NVD published this advisory on August 25, 2026. Full coverage: All-in-One WP Migration Flaw Hits 3M WordPress Sites.
