WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in All-in-One WP Migration and Backup

Trusted by 60M+ sites: The gold standard for WordPress migration and backup. Migrate, backup, and restore your WordPress site with one click.

15Reported vulnerabilities
8.8Highest CVSS score
7.109Latest version
5,000,000+Active installs

What to do now

Update All-in-One WP Migration and Backup to 7.110 or later. 15 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 11, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-1476 Medium 6.5 47.1% 7.58 and earlier 7.59 May 10, 2022
CVE-2022-2546 Medium 4.7 1.2% Before 7.63 7.63 February 2, 2023
CVE-2026-19949 High 8.8 0.5% 0 to 7.109 (inclusive) 7.110 August 25, 2026
WF-66b91fe9-ceb3-485c-bf5f-a672656d4e86 High 8.8 2.0.2 and earlier 2.0.3 November 5, 2014
CVE-2024-9162 High 7.2 2.7% 0 to 7.86 (inclusive)
0 to 7.86 (inclusive)
7.87 October 28, 2024
CVE-2024-10942 High 7.5 0.6% 0 to 7.89 (inclusive) 7.90 March 13, 2025
WF-95cd2bae-4ab7-4a0c-bb71-c17b119eaaa9 High 7.5 2.0.4 and earlier 2.0.5 March 19, 2015
CVE-2026-17533 High 7.2 0.3% Before 7.108 7.108 August 20, 2026
WF-9c9feabc-6a8d-4367-8ea2-cc5284dbc041 Medium 6.1 Before 6.46 6.46 June 20, 2017
WF-f373a1d5-3d7e-4a0a-af03-28ca6ce6a170 Medium 5.9 Before 7.15 7.15 January 20, 2020
CVE-2026-12898 Medium 5.3 1.4% 7.105 and earlier 7.106 June 29, 2026
CVE-2024-8852 Medium 5.3 1.2% 0 to 7.86 (inclusive)
0 to 7.86 (inclusive)
7.87 October 22, 2024
WF-66519150-7719-4598-8302-b3437719f0a0 Medium 5.5 7.62 and earlier 7.63 August 15, 2022
WF-10a0abd6-1905-4a90-8488-29d44df7aeb9 Medium 5.5 Before 7.0 7.0 July 18, 2019
CVE-2025-8490 Medium 4.4 0.2% 0 to 7.97 (inclusive) 7.98 August 27, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.