← Back to blog
September 4, 2026

The Persistence of the Unpatched Five Million

Photo by Tony Hand on Unsplash

In the hosting world, we have spent twenty years trying to convince people that 'set it and forget it' is a myth, yet the latest stats on plugin updates prove that millions of users are still waiting for a miracle instead of clicking a button.

ServMask recently pushed out version 7.110 of their ubiquitous All-in-One WP Migration and Backup plugin to address a critical unauthenticated SQL injection vulnerability. According to recent reports, roughly 65 percent of the five million active installations remain unpatched two weeks after the fix was released. That is roughly 3.2 million WordPress sites sitting on a live grenade, waiting for a malicious actor to pull the pin.

The flaw, tracked as CVE-2026-19949, isn't just a minor bug. It’s the kind of vulnerability that allows an attacker to bypass authentication entirely. For a plugin designed specifically to move entire databases and site files, the implications of leaving this door open are obvious and catastrophic.

The Logistics of Human Latency

This isn't a failure of the developer. ServMask did their part by shipping the code. This is a systemic failure of the managed hosting promise versus reality. We talk a big game about automated updates and security patching, yet 3.2 million sites are still running legacy versions of a tool they likely only needed for a single afternoon three years ago.

From a business perspective, this is where the hidden costs of 'low-touch' customers come to light. These unpatched sites are essentially future tickets in the support queue for hosting providers. When these sites inevitably get compromised, it won't be the plugin developer who gets the panicked 2:00 AM phone call; it will be the sysadmin at the hosting company who has to deal with the fallout of a breached server.

I have always found it fascinating that users will meticulously research which migration tool to use, but then treat the plugin like a permanent fixture of their site architecture, rather than a utility that should be deleted the moment the move is complete.

The Takeaway

Maintenance isn't a feature; it's the job. If you are a host with three million sites under your umbrella, the data suggests you have a massive cleanup project on your hands before the script kiddies automate the exploitation of this one.