Skip to content
← Back

AIOWPM · CVE-2026-19949

PythonPHPDockerWordPressMySQL

Educational lab for CVE-2026-19949 in All-in-One WP Migration and Backup. Reproduces the SQL literal parsing flaw during restoration, with an independently derived payload demonstrating ai1wm_secret_key disclosure and subsequent remote code execution. Planting requires no authentication, but the chain needs an administrator to export and restore the site. Includes Docker, a Python CLI, root-cause analysis and a comparison of vulnerable version 7.109 with patch 7.110. Vulnerability discovery is credited to Jack Taylor; this project contributes the documented reproduction and derived payload.

Screenshots