Skip to main content

Tag: rest api

9 articles

Laptop screen displays a website's content management system dashboard on a plain surface with blurred code in the…

WordPress Exploitation Surges as Public Exploit Fuels Remote Code Execution

A surge in WordPress exploitations is underway as hackers leverage a public exploit to enable remote code execution on vulnerable sites, posing a threat to organizations of all sizes and industries. The flaw, dubbed "wp2shell," allows unauthenticated attacks on default WordPress installations, sparking widespread scanning and compromise.

Analyst 207
WordPress dashboard on a laptop screen in a modern office setting with a blurred cityscape background.

WordPress Exploits Spread as Attackers Chain Critical Vulnerabilities

Within hours of public disclosure, hackers leveraged AI models to exploit two critical WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, that when combined enable unauthenticated remote code execution. This potent pairing allows attackers to wreak havoc on websites, highlighting the urgent need for updates.

Analyst 207
Blurred laptop screen displays abstract website backend with faint code.

Vulnerabilities Exposed in AI-Assisted Cyber Attacks

Beware: a potent pair of WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to allow anonymous remote code execution - and attackers are already exploiting them in the wild. Patch immediately to avoid devastating consequences.

Analyst 207
Vulnerable WordPress site setup with laptop, router, and modem on a minimalist desk.

WordPress Sites Targeted as Public Exploits Emerge for wp2shell Flaws

A critical vulnerability in WordPress Core, dubbed "wp2shell," has been discovered, allowing hackers to remotely execute code on affected sites - putting your online presence at risk if you haven't updated yet. Immediate action is urged for site operators to protect against this high-severity threat.

Analyst 207
Laptop on a minimalist desk with a potted plant and stack of paper in soft natural light.

WordPress Discloses Core Flaw Enabling Unauthenticated Code Execution

WordPress has patched a critical flaw that allowed hackers to execute code remotely without authentication, releasing versions 6.9.5 and 7.0.2 to fix the vulnerability. The update addresses a REST API batch-route confusion and SQL injection issue that could be triggered by a simple HTTP request.

Analyst 207
WordPress dashboard screen with a highlighted API key field and a warning symbol nearby.

Hackers Exploit Gravity SMTP Plugin Bug to Expose API Keys

Malicious hackers are racing to exploit a vulnerability in the Gravity SMTP plugin, which has been installed on around 100,000 WordPress sites, to get their hands on sensitive API keys. Over 17 million exploit attempts have already been blocked by Wordfence, highlighting the urgent need for site owners to update to version 2.1.5.

Analyst 207
Cluttered office desk with laptop showing empty interface, symbolizing WordPress site vulnerability.

Hackers Exploit Gravity SMTP Plugin Bug on 100,000 WordPress Sites

A critical bug in the Gravity SMTP plugin is being exploited by hackers on over 100,000 WordPress sites, putting sensitive information at risk. Update to version 2.1.5 or later to patch the vulnerability.

Analyst 207
IT professionals work in a network operations center with a laptop displaying a blurred REST API endpoint.

Cisco Secure Workload Flaw Exposes Site Admin Privileges

A critical vulnerability in Cisco Secure Workload, known as CVE-2026-20223, allows hackers to gain Site Admin privileges without authentication, putting sensitive information and configuration changes at risk. Cisco has warned of this maximum-severity flaw and advised on remediation steps.

Analyst 207
Laptop screen displays WordPress website backend in brightly-lit office setting.

Hackers exploit auth flaw in Burst Statistics WordPress plugin

A critical bug in the Burst Statistics WordPress plugin, affecting 200,000 sites, allows hackers to impersonate administrators and gain unauthorized access. This alarming vulnerability, already showing signs of exploitation, puts countless websites at risk.

Analyst 207