Wordfence warns 3.25 million WordPress sites vulnerable to takeover via plugin flaw
Researchers identified a high-severity SQL injection vulnerability in All-in-One WP Migration and Backup versions through 7.109, tracked as CVE-2026-19949. Although a fix was released, only 35% of the five million active installations have updated, leaving approximately 3.25 million sites at risk of remote code execution.