WordPress News: Critical Migration Plugin Flaw Patched (Week of 8 September 2026)

This week's news has one clear headline: a nasty SQL injection flaw in one of the most popular WordPress backup plugins, already patched but still worth checking today. Beyond that, an older form builder exploit is still doing rounds, WooCommerce shipped a solid update, and WordPress itself announced it is getting more serious about catching security bugs before they become your problem.
Update your backup plugin today
Wordfence disclosed an unauthenticated SQL injection vulnerability (CVE-2026-19949) in All-in-One WP Migration and Backup, a plugin with more than 5 million active installs. The flaw lets an attacker plant malicious data through ordinary blog comments, which then executes as SQL when an admin restores a backup archive, potentially leaking a secret key and leading to full site takeover. The vendor patched it in version 7.110 on 20 August, and Wordfence Premium users were already protected. Free Wordfence users only get the equivalent firewall rule on 15 September.
What this means for you: if this plugin is installed on your site, check right now that you're on version 7.110 or later. Don't wait for the free protection window to close. If you're not sure how to check plugin versions safely, this is exactly the kind of thing a proper maintenance plan handles automatically. It's also a good moment to make sure your backup strategy doesn't rely on a single plugin; see our guide on doing WordPress backups properly.
Check you actually updated Super Forms
Wordfence also published fresh attack data this week on an older flaw in the Super Forms plugin. The vulnerability itself was patched back in July, but attackers are still hammering away at unpatched sites; Wordfence's firewall has now blocked over 250,000 exploit attempts, with a fresh wave of activity in late August. The attack lets an unauthenticated visitor upload a working PHP file disguised as an image, no login required.
What this means for you: if you run Super Forms, confirm you're on version 6.3.314 or newer. If you patched back in July and haven't touched it since, you're fine. If you're not certain, that uncertainty is the risk: unpatched sites are still being targeted like a lone moon base with the shield generator switched off. Sites that have been compromised often show a rogue PHP file with an odd name sitting in the uploads folder; if that rings any bells, start with our hacked site recovery guide and review our security best practices afterward.
WooCommerce store owners get faster pages and an EU compliance tool
WooCommerce 11.1 shipped this week, and it's a genuinely useful release. Product variation image galleries are now built in and turned on automatically, no extra plugin required. Stores selling to EU customers get a native "right of withdrawal" form, letting shoppers cancel an order within a set window, which helps with compliance under the EU's Consumer Rights Directive (though it won't guarantee compliance on its own; talk to your legal advisor about your specific obligations). Under the hood, the REST and Store API are reported to be 30 to 42 percent faster, and virtual-product checkouts no longer demand a billing address.
What this means for you: if you sell to EU customers, turn on Order Withdrawal under WooCommerce > Settings > Advanced > Features and decide how you want to route those requests internally. Everyone else gets the speed improvements and the new galleries for free with the update. As with any WooCommerce update, test it on a staging copy of your store before pushing it to your live site.
WordPress is finally getting proactive about security
WordPress announced a new Core Security Initiative this week, acknowledging that AI has made it dramatically easier for attackers to find and exploit vulnerabilities. The plan has three parts: a faster, more reliable security release process, a push to clear the backlog of known security issues, and using AI itself to hunt for vulnerabilities before criminals do. Details on execution are still emerging, so we'd treat the "how" cautiously for now, but the intent is a welcome one.
What this means for you: nothing to do here, this is a behind-the-scenes process change. It's a reassuring sign that the core project is taking the AI-accelerated threat landscape seriously, but it doesn't remove the need for you to keep your own plugins and themes patched.
It's worth saying plainly: none of this week's news suggests WordPress is broken as a platform. Millions of sites run on it safely every day. The pattern is the same one we point out most weeks: the risk almost always sits in third-party plugins, not WordPress core itself, and a bit of routine housekeeping closes most of the gap.
That's the roundup for this week. Two real security stories, a useful WooCommerce release, and a promising signal from the core team. If patching plugins the day a fix ships isn't something you have time for, that's precisely what a maintenance plan is for: updates and monitoring handled automatically, so nothing sits unpatched for weeks.
May the Code Be With You.
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


