Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: High-Severity WordPress Plugin Vulnerability - CVE-2026-19949

Wordfence has identified a high‑severity vulnerability (CVE-2026-19949) in the All‑in‑One WP Migration and Backup WordPress plugin, affecting over 5 million websites worldwide. This vulnerability could allow attackers to gain unauthorized access and potentially take full control of vulnerable sites.
 
Affected Systems:
  • All-in-One WP Migration and Backup Wordpress Plugin: Versions 7.109 and earlier
 
Security Risks
 
The identified vulnerability could allow an attacker to inject malicious content into an affected website, which may later be processed during backup or restoration operations. This could expose sensitive information, enable remote code execution, and ultimately lead to complete compromise of the WordPress site.
 
For additional information on WordPress plugin security updates and available patches, please refer to the official WordPress Plugin Security Releases.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Update as soon as possible to the latest supported version of the affected WordPress plugin to address the vulnerability and reduce the risk of exploitation.
 
 The released software version for upgrade is:
  • All-in-One WP Migration and Backup WordPress Plugin: Upgrade to version 7.110 and above
 
2. Before updating or patching, please ensure that you have the latest backup that can easily be restored.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

08 September 2026

© 2026 National Cyber Security Authority