Skip to main content

Tag: plugin vulnerability

26 articles

WordPress website backend on a laptop screen in a neutral office setting.

GiveWP Plugin Flaw Lets Hackers Execute Server Commands

A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.

Analyst 207
WordPress login screen on laptop with blurred office background.

Attackers Exploit miniOrange SAML Flaws to Hijack WordPress Admin Access

A critical vulnerability in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress allows hackers to hijack admin access with just a few clicks, giving them the keys to your site's kingdom. This flaw lets unauthenticated attackers log in as any existing user, including administrators, by exploiting a weakness in signature verification.

Analyst 207
Laptop screen shows WordPress backend dashboard with security settings.

Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks

Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

Analyst 207
Laptop screen with blurred CMS dashboard and out-of-focus keyboard on minimalist desk.

Elementor Pro Flaw Enables RCE Attacks on WordPress Sites

A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, allows attackers to launch remote code execution (RCE) attacks on WordPress sites by exploiting a discrepancy in the plugin's File Upload module. This flaw affects Elementor Pro versions before 4.2.2 and can be triggered by a specially crafted multipart upload.

Analyst 207
Laptop screen showing WordPress backend with file upload, in a cluttered office with city view.

WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution

A critical vulnerability in the Forminator Forms WordPress plugin can let hackers upload malicious PHP files to your site, allowing them to take control and wreak havoc - all without needing a login. This flaw, tracked as CVE-2026-15748, has a near-perfect severity score of 9.8, making it a high-priority threat.

Analyst 207
Laptop screen displays WordPress dashboard on a desk in a home office.

WordPress Plugin Flaw Enables Admin Takeover on 40,000 Sites

A critical vulnerability in the popular User Profile Builder plugin has put over 40,000 WordPress sites at risk of admin takeover, with a CVSS rating of 9.8; site owners should immediately update to version 3.16.5 or later to patch the flaw.

Analyst 207
WordPress admin dashboard on a laptop screen with a cityscape background and office items nearby.

BdThemes Plugins Targeted in Supply Chain Attack

A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

Analyst 207
WordPress plugin developer's workspace with flagged plugins on screen.

BdThemes plugins compromised in supply-chain attack

A stealthy supply-chain attack on BdThemes plugins has turned into a high-stakes problem, putting over 350,000 active WordPress installations at risk. The breach affects popular plugins like Element Pack, Prime Slider, and others, prompting the WordPress Plugins team to swiftly pull them from download.

Analyst 207
WordPress admin dashboard on laptop with plugin installation page, surrounded by cluttered workspace and office background.

WordPress Plugins Backdoored in ShapedPlugin Supply Chain Attack

A recent supply chain attack on ShapedPlugin compromised the updates for several WordPress plugins, including Product Slider Pro for WooCommerce, injecting backdoor code that could give attackers full control of affected sites. This severe vulnerability, rated 10.0 on the CVSS scale, highlights the importance of staying vigilant about plugin updates and security.

Analyst 207
Cluttered office desk with laptop showing empty interface, symbolizing WordPress site vulnerability.

Hackers Exploit Gravity SMTP Plugin Bug on 100,000 WordPress Sites

A critical bug in the Gravity SMTP plugin is being exploited by hackers on over 100,000 WordPress sites, putting sensitive information at risk. Update to version 2.1.5 or later to patch the vulnerability.

Analyst 207
A WordPress dashboard screen with a cracked laptop keyboard in the foreground, symbolizing site vulnerability.

Hackers Exploit Everest Forms Pro Flaw to Hijack WordPress Sites

More than 29,300 attempted hacks have been blocked by Wordfence, revealing a surge in automated attacks exploiting a critical flaw in the Everest Forms Pro plugin, tracked as CVE-2026-3300. This alarming number highlights the urgent need for WordPress site owners to safeguard against this vulnerability.

Analyst 207
WordPress website backend dashboard on a laptop screen in a quiet workspace.

Hackers Exploit Everest Forms Pro Flaw to Compromise WordPress Sites

A critical vulnerability in Everest Forms Pro, affecting over 4,000 active WordPress installations, has been exploited by hackers to gain remote code execution, allowing them to take control of sites without authorization. A patch has been released, but sites remain at risk if not updated to version 1.9.13 or later.

Analyst 207
WordPress site backend on laptop with Everest Forms Pro plugin visible.

Everest Forms Pro Flaw Exploited for Remote Code Execution

A critical flaw in the Everest Forms Pro WordPress plugin, CVE-2026-3300, has been exploited over 29,300 times, allowing attackers to execute remote code on vulnerable sites. This vulnerability was caused by a simple calculation feature that was not properly sanitized, leaving sites open to unauthenticated attacks.

Analyst 207
WordPress dashboard on a laptop screen amidst a cluttered home office, symbolizing vulnerability.

WP Maps Pro Flaw Exploited to Create Admin Accounts

A critical vulnerability in the popular WP Maps Pro plugin, used by over 15,000 WordPress sites, has been exploited to create admin accounts, putting countless websites at risk of complete takeover. This high-severity flaw, tracked as CVE-2026-8732, allows attackers to escalate privileges and gain unrestricted access.

Analyst 207
Person typing on laptop with blurred map interface on screen, symbolizing WordPress site security breach.

Hackers Exploit WP Maps Pro Bug to Hijack WordPress Sites

In just 24 hours, over 3,600 hacking attempts were made to exploit a critical flaw in the WP Maps Pro plugin, allowing attackers to create admin accounts and log in without a password. This vulnerability, affecting version 6.1.0 and older, puts countless WordPress sites at risk.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with a sense of urgency.

LiteSpeed Plugin Flaw Exploited to Run Scripts as Root

A critical flaw in the LiteSpeed plugin, CVE-2026-48172, is being actively exploited to give cPanel users unlimited power, allowing them to run scripts as root. This severe vulnerability, rated 10.0 on the CVSS scale, puts your online security at risk and demands immediate attention.

Analyst 207
Retail checkout counter with a WooCommerce point-of-sale terminal in the foreground and blurred store shelves in the…

Funnel Builder Flaw Exploited for WooCommerce Checkout Skimming

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited, allowing attackers to inject malicious JavaScript into WooCommerce checkout pages and skim sensitive customer info. Over 40,000 online stores using the plugin may be at risk.

Analyst 207
Retail checkout counter with payment terminal and WooCommerce logo, laptop screen blurred with loading animation, hinting…

Funnel Builder Plugin Exploited to Inject Credit Card Skimmers

A vulnerability in the popular Funnel Builder plugin, used on over 40,000 websites, has been exploited to inject credit card skimmers into WooCommerce checkout pages, putting sensitive payment data at risk. This flaw allows attackers to sneak malicious code into checkout pages, harvesting valuable information from unsuspecting customers.

Analyst 207
Laptop screen displays WordPress website backend in brightly-lit office setting.

Hackers exploit auth flaw in Burst Statistics WordPress plugin

A critical bug in the Burst Statistics WordPress plugin, affecting 200,000 sites, allows hackers to impersonate administrators and gain unauthorized access. This alarming vulnerability, already showing signs of exploitation, puts countless websites at risk.

Analyst 207
Jenkins plugin page on a computer screen shows a warning message with a blurred software development workspace background.

Checkmarx Plugin Compromised with Infostealer in Supply-Chain Attack

A rogue version of Checkmarx's Jenkins Application Security Testing plugin was compromised by the TeamPCP hacker group, who left a taunting message in the about section, claiming another supply-chain attack success. The group has been linked to a string of similar breaches, delivering credential-stealing malware.

Analyst 207
Laptop screen displays Jenkins plugin interface with code environment, beside blurred smartphone and sticky notes.

TeamPCP Breaches Checkmarx Jenkins Plugin Again

If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.

Analyst 207
Software development team works at a continuous-integration workstation with laptop and monitor displaying a plugin…

Checkmarx Plugin Sabotaged in Fresh TeamPCP Intrusion

Checkmarx issued a warning on May 9, 2026, that a tampered version of its Jenkins AST plugin had been released on the Jenkins Marketplace, posing a risk to continuous-integration pipelines. The company quickly responded by urging customers to update to a trusted version, 2.0.13-829.vc72453fa_1c16, to safeguard their systems.

Analyst 207
WordPress site administrator working on laptop in dimly lit server room.

WordPress Plugin Exposes 70,000 Sites to Backdoor Vulnerability

A shocking security vulnerability has been uncovered in a popular WordPress plugin, leaving over 70,000 sites open to backdoor attacks that can inject malicious code on demand. The issue was discovered in the Quick Page/Post Redirect plugin, which was infected with a hidden backdoor five years ago.

Analyst 207
Broken padlock hangs from laptop amidst shattered glass and cityscape of compromised websites.

WordPress Plugin Suite Compromised, Malware Deployed on Thousands of Sites

Thousands of websites have been unwittingly turned into malware gateways due to a massive compromise of over 30 WordPress plugins in the EssentialPlugin package, highlighting a disturbing vulnerability in the internet ecosystem. This security breach has left countless sites exposed, raising urgent questions about accountability and prevention.

Analyst 207