Security News

Critical Flaw in Popular WordPress Migration Plugin Puts 3 Million Sites at Risk

Security Week · 3 Sept 2026
Key Takeaway If your business website runs WordPress, check whether you use a migration plugin, update it immediately to the patched version, and remove any plugins you no longer actively need.

A serious security flaw, tracked as CVE-2026-19949, has been found in a WordPress migration plugin used on more than three million websites. The vulnerability is a SQL injection issue, meaning attackers can manipulate a website's database through poorly secured input fields. Because the flaw doesn't require attackers to log in first, any exposed site running a vulnerable version of the plugin could be targeted directly from the internet.

What makes this flaw particularly concerning is its potential to lead to remote code execution. In practical terms, this means an attacker could not only steal or alter data stored in the site's database but potentially take full control of the website, including installing malware, defacing content, or using the compromised site to launch further attacks on visitors and other systems.

Many small businesses rely on WordPress for their websites and may use migration plugins when moving hosting providers or setting up staging environments, often without realising these tools remain active and exposed afterward. Given the scale of affected installations, this vulnerability is likely to be actively targeted by attackers scanning the internet for vulnerable sites.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.