Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
Summary
A high-severity SQL injection vulnerability, identified as CVE-2026-19949, has been discovered in a popular WordPress migration plugin. This flaw could potentially allow unauthenticated attackers to achieve remote code execution on affected websites, impacting over 3 million sites.
IFF Assessment
FOE
The discovery of a high-severity SQL injection vulnerability that allows for remote code execution represents a significant threat to websites.
Severity
8.8
High
Defender Context
Defenders need to be aware of this critical vulnerability affecting a widely used WordPress plugin. Prompt patching or mitigation is essential to prevent potential website compromises and data breaches. This highlights the ongoing risk posed by vulnerabilities in popular content management system plugins.