Contact

What the latest WordPress flaw means for your site

A backup plugin used on five million WordPress sites shipped a serious flaw, and two thirds had not patched when the details went public. What happened, what to do this week, and how we build sites without this problem.

If your website runs on WordPress, there is a decent chance it uses a plugin called All-in-One WP Migration and Backup. More than five million sites do. In August its maker quietly fixed a serious security hole, and in early September researchers published the details: the flaw, tracked as CVE-2026-19949, could let an attacker plant a payload through an ordinary looking request and later take control of the site outright. SecurityWeek's write-up has the technical version.

Here is the part worth sitting with. The fix has existed since August 20. On the day the details went public, roughly two thirds of those five million installs had not applied it.

Why this keeps happening

WordPress itself is not the villain. The core software is maintained by serious people and powers roughly four in ten websites, which is exactly why it draws this much attention from attackers. The risk lives in the plugins. Every WordPress site is really a bundle of software from a dozen different authors, each shipping on their own schedule, each with their own idea of what careful looks like. The overwhelming majority of WordPress security advisories are about plugins and themes, not WordPress itself.

And the pattern in this story is the pattern in most of them: the hole was fixed before the world knew it existed. Sites did not stay exposed because the problem was unsolvable. They stayed exposed because nobody was watching the updates. Most small business sites are not hacked by brilliance. They are hacked through a known hole, with a fix available, that nobody applied.

The one-hour checkup

If your site runs WordPress, this is worth an hour this week:

  • Log in and update WordPress, your theme, and every plugin. If All-in-One WP Migration and Backup is on the list, make sure it shows version 7.110 or newer.
  • Delete the plugins you deactivated long ago. Deactivated is not removed, and only removed code is truly out of the picture.
  • Check each remaining plugin's "last updated" date in the plugin directory. A plugin nobody has touched in years deserves a maintained replacement.
  • Turn on automatic updates where a plugin supports them, and take a backup first.
  • Decide whose job this is. If the honest answer is nobody, that is the real vulnerability.

How we build instead

The websites we build and care for do not have a plugin marketplace to babysit. Pages are written as plain, fast code and served from a global edge network. There is no wp-admin door on the internet for someone to find, bank grade security headers ship on by default, and keeping everything current is our job, not yours. Fewer moving parts means fewer doors. We say this with a straight face because it is exactly how our own site is built.

And if WordPress is where you are and where you want to stay, that is fine too. We can take over the care of an existing site: updates handled, abandoned plugins retired, backups tested.

Either way, a good first step costs nothing. Our free Website Report Card grades any site in five areas, security included, with a real measurement behind each grade. Or ask us about this one directly; the first conversation is free.

Free 15-minute call

Pick a time. We call you.

No forms worth dreading and nothing to prepare. Tell us where it hurts, we tell you what we would do about it, and you keep the plan either way.

  • Talk to the founder, not a sales team
  • Plain English, no obligation
  • Live availability, Eastern time

We call the number above at your time. No email required, nothing to install.