WordPress

Critical WordPress Vulnerability Exploited Immediately After Disclosure

Critical WordPress Vulnerability Exploited Immediately After Disclosure 2026-09-24 at 10:12 By Ionut Arghire Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical WordPress Vulnerability Exploited Immediately After Disclosure Read More »

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) 2026-09-23 at 12:01 By Sinisa Markovic WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active […]

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) Read More »

WordPress Patches ‘Click2Shell’ Vulnerability

WordPress Patches ‘Click2Shell’ Vulnerability 2026-09-22 at 13:22 By Ionut Arghire The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Patches ‘Click2Shell’ Vulnerability Read More »

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites 2026-09-18 at 12:46 By Ionut Arghire Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Read More »

Most WordPress pros still lack a breach recovery plan

Most WordPress pros still lack a breach recovery plan 2026-09-18 at 07:30 By Anamarija Pogorelec Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners […]

Most WordPress pros still lack a breach recovery plan Read More »

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover 2026-09-16 at 14:32 By Ionut Arghire Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover Read More »

WordPress adds automated security checks to block risky plugin releases

WordPress adds automated security checks to block risky plugin releases 2026-09-10 at 13:06 By Anamarija Pogorelec WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, […]

WordPress adds automated security checks to block risky plugin releases Read More »

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites 2026-09-05 at 16:00 By Ionut Arghire Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek. This article […]

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Read More »

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability 2026-09-03 at 13:40 By Ionut Arghire The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability Read More »

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities 2026-08-25 at 16:33 By Eduard Kovacs CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Read More »

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

WordPress 7.0.4 Patches Remote Code Execution Vulnerability 2026-08-13 at 15:53 By Ionut Arghire Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress 7.0.4 Patches Remote Code Execution Vulnerability Read More »

WP2Shell WordPress Vulnerabilities Exploited in the Wild

WP2Shell WordPress Vulnerabilities Exploited in the Wild 2026-07-20 at 08:21 By Eduard Kovacs Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WP2Shell WordPress Vulnerabilities Exploited in the Wild Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 […]

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data 2026-06-22 at 14:45 By Ionut Arghire Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Read More »

15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 

15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown  2026-06-19 at 09:46 By Ionut Arghire Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown  Read More »

Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned

Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned 2026-06-18 at 17:21 By Zeljka Zorz SocGholish, an operation that’s been delivering malware to users via fake software updates, has suffered a major blow: the international law enforcement coalition behind Operation Endgame has taken down 106 of its servers and domains, and cleaned up nearly […]

Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned Read More »

Everest Forms Vulnerability Exploited to Hack WordPress Sites

Everest Forms Vulnerability Exploited to Hack WordPress Sites 2026-06-08 at 16:16 By Ionut Arghire The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Everest Forms Vulnerability Exploited to Hack WordPress Sites Read More »

Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs

Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs 2026-06-03 at 20:19 By Ionut Arghire Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs Read More »

$20 per zero-day is already the WordPress plugin reality

$20 per zero-day is already the WordPress plugin reality 2026-05-22 at 17:05 By Mirko Zorz Vulnerability researchers have spent the past year arguing about whether AI agents can find real bugs at scale or whether they mostly generate noise. A pipeline built in three days by researchers from TrendAI and CHT Security supplies an answer, […]

$20 per zero-day is already the WordPress plugin reality Read More »

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover 2026-04-08 at 15:06 By Ionut Arghire The vulnerability allows hackers to upload arbitrary files to a site’s server and achieve remote code execution. The post Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover appeared first on SecurityWeek. This article is an […]

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover Read More »

Scroll to Top