WordPress security series · Part 3 of 5
Backups are meant to be the thing that saves you. In September 2026, one of the most popular WordPress backup plugins showed how they can also be the way in.
What happened
Security researchers disclosed a flaw in All-in-One WP Migration and Backup, a plugin running on more than five million WordPress sites. An attacker could plant malicious data on a site without logging in. It sat there, doing nothing, until an administrator ran a routine backup export or restore. Then it fired, and the attacker could take over the site.
A fixed version was released on 20 August 2026. When the flaw went public in early September, around 65% of sites using the plugin, roughly 3.25 million, still had not updated.
The lesson is not “this plugin is bad”. It was fixed. The lesson is that the most routine job on your website can be the trigger, and nobody on your team would have known.
Backups still matter. How you keep them matters more.
The Australian Cyber Security Centre’s guidance on regular backups makes two points most small businesses skip. Everyday accounts should not be able to change or delete backups. And you should regularly test that the entire backup restores, not just a spot check.
A sound setup looks like this:
- Three copies of your site, in at least two different places, with one kept off-site.
- The off-site copy locked away from anyone who breaks into the website itself.
- A full test restore on a schedule, so the first test is not the day you need it.
If your only backup lives on the same server as your website, an attacker who gets in owns both.
The question to ask this week
“When did we last restore the site from backup, and did it work?”
If the answer contains the word “should”, you do not have a backup. You have a subscription.
Next step
Our WordPress Hosting Australia plans keep backups this way, and the off-machine copy ends up on a drive that is disconnected from everything. If you think you have already been hit, Incident response (from $700 inc GST) gets you clean and tells you how they got in.
Common questions
Should I stop using backup plugins?
What is the 3-2-1 backup rule?
How often should I test a restore?
The five-part series
- Five Hours: The Gap Between a WordPress Flaw and an Attack
- Abandoned Plugins: The WordPress Risk You Can’t See
- When Your Backup Plugin Becomes the Way In — you are here
- Your Website Isn’t the Target. It’s the Tool. (13 October)
- A Hacked Website Is Now a Compliance Problem (27 October)
Based on the full article: Your WordPress Site Is Probably Already a Problem.