All-in-One WP Migration: if you used it to move your site, update it or delete it

The plugin most people use to move a WordPress site has a serious flaw in the part that restores a backup, fixed in version 7.110. If you installed it for a move and never opened it again, it is still there.

A faded website window and a dark one, joined by a dotted coral arrow with a moving box above it, a small plugin piece on the corner of each, the right one with a coral warning badge, on a warm cream background

At the end of August, a security flaw was published in All-in-One WP Migration and Backup, the plugin most people use to move a WordPress site to a new host. It is a SQL injection in the part of the plugin that restores a backup, and it can be taken as far as a full takeover of the site. The plugin has more than five million installations; the flaw is CVE-2026-19949.

Every version up to and including 7.109 is affected. Version 7.110, released on 20 August, fixes it.

Why a moving tool is the problem#

Most people install this plugin for one job. They export the site on the old host, import it on the new one, and never open the plugin again. It stays installed on both copies long after the move is finished, and unless automatic updates are switched on for it, it gets updated only when someone remembers it is there.

That forgotten copy is the one to deal with.

What to do#

Open Plugins in your WordPress dashboard and look for All-in-One WP Migration.

  • If you no longer use it, deactivate it and delete it. You can install it again the day you need it.
  • If you use it for backups, update it to 7.110 or later today.
  • If the old copy of your site is still online at your previous host, it has the same plugin. Update it there too, or take that copy down.

If you're moving to us#

You don't need the plugin at all. Migration is free on every paid plan: we move your site and its database for you, usually within a day, and you install nothing.

What we do on our side#

Every site on our servers sits behind a web application firewall with its WordPress rules switched on, so known attack patterns are blocked before they reach your site. That is a second layer, not a fix. A blocked attack leaves the hole where it was; only 7.110 closes it.

The update itself happens inside your site, so someone has to make it there: you, or us if you ask. Not sure whether the plugin is installed, or which version you have? Ask us and we'll check.