Start your day with intelligence. Get The OODA Daily Pulse.
WordPress plugin flaw leaves millions open to code execution.
A second‑order SQL injection bug in the All‑in‑One WP Migration and Backup plugin allows attackers to extract the secret key used during archive restores. By submitting crafted trackbacks, an attacker can push malicious input into stored SQL that later exposes the key in a public comment. With that key, an unauthenticated attacker can import a booby‑trapped archive containing a must‑use plugin that executes on the next page load. The issue affects all versions up to 7.109, and with only a third of sites updated, roughly 3.2 million installations remain vulnerable.
Read more: