← All articles Security

Critical WordPress Backup Plugin Flaw Risks Site Takeover

If your business uses WordPress, there is a reasonable chance your site is running the All-in-One WP Migration and Backup plugin. With over five million

Published Jason Boyd

If your business uses WordPress, there is a reasonable chance your site is running the All-in-One WP Migration and Backup plugin. With over five million active installations, it is one of the most widely used tools for moving sites between hosts and keeping backup copies of everything a business has built. It is also, right now, carrying a confirmed high-severity security flaw that gives an attacker full administrative control of your website without needing a username or password.

The vulnerability is tracked as CVE-2024-11015 and affects versions of the plugin up to and including 7.109. A working proof-of-concept exploit is already available publicly, which means the risk is immediate and requires no particular sophistication on the part of an attacker. Anyone with the motivation and access to that exploit can attempt it against any unpatched site. The fix exists: version 7.110 resolves the issue. Only around a third of affected sites have applied it, leaving the majority of the five million installations exposed.

The specific flaw is a privilege escalation vulnerability. An attacker with a free subscriber-level account, or in some configurations no account at all, can escalate their access to full administrator. From that position they can install malicious code, exfiltrate your database, lock you out of your own site, redirect your visitors to fraudulent pages, or simply take everything offline. Every one of those outcomes has a business cost attached to it.

What a Site Takeover Actually Costs a Business

Downtime is the immediate consequence most people think of: customers cannot reach you, enquiries stop, and if you run an online shop, revenue stops with it. But downtime is often the least damaging part of a site takeover.

Your customer database is a more serious concern. If your site stores names, email addresses, phone numbers, or payment details, a breach may trigger obligations under UK GDPR. The Information Commissioner’s Office requires businesses to report certain personal data breaches within 72 hours of becoming aware of them. Failing to do so, or failing to have adequate security measures in place, can result in regulatory action, and a vulnerable, unpatched plugin is exactly the kind of security gap the ICO would expect a business to have addressed.

Consider also what attackers do with access once they have it. Injecting malware into your site means your visitors may be served malicious content without your knowledge. Google’s Safe Browsing programme flags sites distributing malware, which results in browser warnings appearing before visitors even reach your page, and recovering your search rankings and your domain’s reputation after that kind of flagging takes months, not days.

There is also the specific risk that comes from the plugin’s purpose. All-in-One WP Migration handles your site’s backup files. Those files contain your entire database, your configuration, and potentially credentials stored in your WordPress installation, so an attacker who gains access through this vulnerability has a direct route to all of that data in a single, packaged file.

The Version Number to Check Before You Do Anything Else

Log into your WordPress dashboard, go to Plugins, and look at the version number listed for All-in-One WP Migration. If it reads anything below 7.110, your site is currently vulnerable. Update it now. The patched version is available through the standard WordPress plugin update mechanism and has been since the fix was released.

If automatic updates are turned on for your plugins, check anyway, because automatic updates do not always fire immediately and confirmation that the update has actually applied is worth the thirty seconds it takes to verify.

Businesses that lack clear oversight of their own WordPress installation are exactly the ones most likely to be running outdated, vulnerable software without realising it. If you are not certain who manages your site’s plugins, or if you do not have direct access to the WordPress dashboard, that is itself a problem worth resolving.

One thing that often gets overlooked: updating the plugin closes the vulnerability, but it does not tell you whether the vulnerability was already exploited before you patched it. If your site has been running an affected version for any significant period, particularly since the public proof-of-concept became available, an update alone is not sufficient assurance. You would need a proper security audit to confirm that no malicious code, no backdoor, and no unauthorised administrator account was introduced before the patch was applied. A compromised site that has been patched but not audited may still be harbouring an attacker’s access point, quietly, for months, and that is the scenario businesses most often fail to account for. A compromised site that has been cleaned up and patched, by contrast, is recoverable.


If your site is running a version of All-in-One WP Migration below 7.110, contact me at The WordPress Guy to arrange an immediate plugin audit and security check. Given that a working exploit is already in circulation and the majority of affected sites remain unpatched, this is not something to schedule for next week. I will confirm your current patch status, check for signs of prior compromise, and ensure your site is secured against this specific vulnerability.

Related articles

All articles →

Security issues need permanent fixes, not surface-level patches. This is exactly the work I specialise in.

View security services →
Jason Boyd

Jason Boyd

Specialist WordPress Engineer · Former W3C Invited Expert · 20+ years

I fix the WordPress problems other developers walk away from. Backed by a 1st Class degree in Computer Science, an MSc in Cybersecurity, and over 20 years of specialist WordPress work, I diagnose issues at their root cause and resolve them permanently — for businesses that cannot afford guesswork or repeat failures.

Need hands-on help?

If this article describes your situation, I can diagnose the specifics and fix it properly. Send your brief and I'll respond the same working day.