Tag: plugin vulnerability
26 articles

GiveWP Plugin Flaw Lets Hackers Execute Server Commands
A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.

Attackers Exploit miniOrange SAML Flaws to Hijack WordPress Admin Access
A critical vulnerability in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress allows hackers to hijack admin access with just a few clicks, giving them the keys to your site's kingdom. This flaw lets unauthenticated attackers log in as any existing user, including administrators, by exploiting a weakness in signature verification.

Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks
Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

Elementor Pro Flaw Enables RCE Attacks on WordPress Sites
A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, allows attackers to launch remote code execution (RCE) attacks on WordPress sites by exploiting a discrepancy in the plugin's File Upload module. This flaw affects Elementor Pro versions before 4.2.2 and can be triggered by a specially crafted multipart upload.

WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution
A critical vulnerability in the Forminator Forms WordPress plugin can let hackers upload malicious PHP files to your site, allowing them to take control and wreak havoc - all without needing a login. This flaw, tracked as CVE-2026-15748, has a near-perfect severity score of 9.8, making it a high-priority threat.

WordPress Plugin Flaw Enables Admin Takeover on 40,000 Sites
A critical vulnerability in the popular User Profile Builder plugin has put over 40,000 WordPress sites at risk of admin takeover, with a CVSS rating of 9.8; site owners should immediately update to version 3.16.5 or later to patch the flaw.

BdThemes Plugins Targeted in Supply Chain Attack
A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

BdThemes plugins compromised in supply-chain attack
A stealthy supply-chain attack on BdThemes plugins has turned into a high-stakes problem, putting over 350,000 active WordPress installations at risk. The breach affects popular plugins like Element Pack, Prime Slider, and others, prompting the WordPress Plugins team to swiftly pull them from download.

WordPress Plugins Backdoored in ShapedPlugin Supply Chain Attack
A recent supply chain attack on ShapedPlugin compromised the updates for several WordPress plugins, including Product Slider Pro for WooCommerce, injecting backdoor code that could give attackers full control of affected sites. This severe vulnerability, rated 10.0 on the CVSS scale, highlights the importance of staying vigilant about plugin updates and security.

Hackers Exploit Gravity SMTP Plugin Bug on 100,000 WordPress Sites
A critical bug in the Gravity SMTP plugin is being exploited by hackers on over 100,000 WordPress sites, putting sensitive information at risk. Update to version 2.1.5 or later to patch the vulnerability.

Hackers Exploit Everest Forms Pro Flaw to Hijack WordPress Sites
More than 29,300 attempted hacks have been blocked by Wordfence, revealing a surge in automated attacks exploiting a critical flaw in the Everest Forms Pro plugin, tracked as CVE-2026-3300. This alarming number highlights the urgent need for WordPress site owners to safeguard against this vulnerability.

Hackers Exploit Everest Forms Pro Flaw to Compromise WordPress Sites
A critical vulnerability in Everest Forms Pro, affecting over 4,000 active WordPress installations, has been exploited by hackers to gain remote code execution, allowing them to take control of sites without authorization. A patch has been released, but sites remain at risk if not updated to version 1.9.13 or later.

Everest Forms Pro Flaw Exploited for Remote Code Execution
A critical flaw in the Everest Forms Pro WordPress plugin, CVE-2026-3300, has been exploited over 29,300 times, allowing attackers to execute remote code on vulnerable sites. This vulnerability was caused by a simple calculation feature that was not properly sanitized, leaving sites open to unauthenticated attacks.

WP Maps Pro Flaw Exploited to Create Admin Accounts
A critical vulnerability in the popular WP Maps Pro plugin, used by over 15,000 WordPress sites, has been exploited to create admin accounts, putting countless websites at risk of complete takeover. This high-severity flaw, tracked as CVE-2026-8732, allows attackers to escalate privileges and gain unrestricted access.

Hackers Exploit WP Maps Pro Bug to Hijack WordPress Sites
In just 24 hours, over 3,600 hacking attempts were made to exploit a critical flaw in the WP Maps Pro plugin, allowing attackers to create admin accounts and log in without a password. This vulnerability, affecting version 6.1.0 and older, puts countless WordPress sites at risk.

LiteSpeed Plugin Flaw Exploited to Run Scripts as Root
A critical flaw in the LiteSpeed plugin, CVE-2026-48172, is being actively exploited to give cPanel users unlimited power, allowing them to run scripts as root. This severe vulnerability, rated 10.0 on the CVSS scale, puts your online security at risk and demands immediate attention.

Funnel Builder Flaw Exploited for WooCommerce Checkout Skimming
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited, allowing attackers to inject malicious JavaScript into WooCommerce checkout pages and skim sensitive customer info. Over 40,000 online stores using the plugin may be at risk.

Funnel Builder Plugin Exploited to Inject Credit Card Skimmers
A vulnerability in the popular Funnel Builder plugin, used on over 40,000 websites, has been exploited to inject credit card skimmers into WooCommerce checkout pages, putting sensitive payment data at risk. This flaw allows attackers to sneak malicious code into checkout pages, harvesting valuable information from unsuspecting customers.

Hackers exploit auth flaw in Burst Statistics WordPress plugin
A critical bug in the Burst Statistics WordPress plugin, affecting 200,000 sites, allows hackers to impersonate administrators and gain unauthorized access. This alarming vulnerability, already showing signs of exploitation, puts countless websites at risk.

Checkmarx Plugin Compromised with Infostealer in Supply-Chain Attack
A rogue version of Checkmarx's Jenkins Application Security Testing plugin was compromised by the TeamPCP hacker group, who left a taunting message in the about section, claiming another supply-chain attack success. The group has been linked to a string of similar breaches, delivering credential-stealing malware.

TeamPCP Breaches Checkmarx Jenkins Plugin Again
If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.

Checkmarx Plugin Sabotaged in Fresh TeamPCP Intrusion
Checkmarx issued a warning on May 9, 2026, that a tampered version of its Jenkins AST plugin had been released on the Jenkins Marketplace, posing a risk to continuous-integration pipelines. The company quickly responded by urging customers to update to a trusted version, 2.0.13-829.vc72453fa_1c16, to safeguard their systems.

WordPress Plugin Exposes 70,000 Sites to Backdoor Vulnerability
A shocking security vulnerability has been uncovered in a popular WordPress plugin, leaving over 70,000 sites open to backdoor attacks that can inject malicious code on demand. The issue was discovered in the Quick Page/Post Redirect plugin, which was infected with a hidden backdoor five years ago.

WordPress Plugin Suite Compromised, Malware Deployed on Thousands of Sites
Thousands of websites have been unwittingly turned into malware gateways due to a massive compromise of over 30 WordPress plugins in the EssentialPlugin package, highlighting a disturbing vulnerability in the internet ecosystem. This security breach has left countless sites exposed, raising urgent questions about accountability and prevention.