CVE-2026-19949: Hive Blocks the All-in-One WP Migration SQLi by Default
An unauthenticated second-order SQL injection in All-in-One WP Migration (up to 7.109) hides in trackbacks and fires on backup restore. Hive's default firewall blocks the ingress path on every plan, and a targeted trackback rule shipped today.
Read more