Tag: wordpress
62 articles

GiveWP Plugin Flaw Lets Hackers Execute Server Commands
A critical flaw in the GiveWP WordPress donation plugin, known as CVE-2026-82222, allows hackers to run malicious commands on your server - and it's surprisingly easy to exploit. This maximum-severity vulnerability can be triggered by an unauthenticated attacker, putting your site at risk of a devastating takeover.

Avada WordPress Theme Flaw Enables Zero-Click Remote Code Execution
A critical vulnerability in the Avada WordPress theme, scored 9.8 out of 10, can be exploited through a zero-click remote code execution attack, allowing hackers to run malicious PHP code on affected sites without needing login credentials. This flaw enables attackers to take full control of a site, planting malware, stealing data, or creating rogue admin accounts.

Attackers Exploit miniOrange SAML Flaws to Hijack WordPress Admin Access
A critical vulnerability in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress allows hackers to hijack admin access with just a few clicks, giving them the keys to your site's kingdom. This flaw lets unauthenticated attackers log in as any existing user, including administrators, by exploiting a weakness in signature verification.

Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks
Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

Elementor Pro Flaw Enables RCE Attacks on WordPress Sites
A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, allows attackers to launch remote code execution (RCE) attacks on WordPress sites by exploiting a discrepancy in the plugin's File Upload module. This flaw affects Elementor Pro versions before 4.2.2 and can be triggered by a specially crafted multipart upload.

Elementor Pro Flaw Enables Unauthenticated Code Execution
A critical vulnerability in Elementor Pro, rated CVSS 9.0, allows hackers to execute malicious code remotely - and it's surprisingly easy to exploit, thanks to a logic flaw in the plugin's Forms module. This loophole lets attackers bypass security checks and write PHP files to a public uploads directory.

Hackers Exploit 2,000 WordPress Sites in StopAndProtect Malware Campaign
This sneaky malware campaign, known as StopAndProtect, has already hacked nearly 2,000 WordPress sites, using a powerful toolkit that encrypts files, steals sensitive documents, and even lets attackers chat with their victims in real-time. The damage is widespread, with over 6,000 unique IP addresses affected worldwide.

WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution
A critical vulnerability in the Forminator Forms WordPress plugin can let hackers upload malicious PHP files to your site, allowing them to take control and wreak havoc - all without needing a login. This flaw, tracked as CVE-2026-15748, has a near-perfect severity score of 9.8, making it a high-priority threat.

WordPress Plugin Flaw Enables Admin Takeover on 40,000 Sites
A critical vulnerability in the popular User Profile Builder plugin has put over 40,000 WordPress sites at risk of admin takeover, with a CVSS rating of 9.8; site owners should immediately update to version 3.16.5 or later to patch the flaw.

BdThemes Plugins Targeted in Supply Chain Attack
A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

BdThemes plugins compromised in supply-chain attack
A stealthy supply-chain attack on BdThemes plugins has turned into a high-stakes problem, putting over 350,000 active WordPress installations at risk. The breach affects popular plugins like Element Pack, Prime Slider, and others, prompting the WordPress Plugins team to swiftly pull them from download.

WordPress Plugins Targeted by Rogue Feed Exploits
Hackers have found a sneaky way to exploit WordPress plugins, using a promotional banner feed to plant rogue administrator accounts and webshells on live sites - all without modifying a single plugin file. The attack, traced back to an unescaped field in a banner notice, has already hit seven plugins from a popular Elementor add-on vendor.

WordPress Fixes Pre-Auth XSS Flaw That Enables PHP Code Execution
WordPress has patched a high-severity flaw that could let attackers inject malicious code into your site - and it's crucial you update ASAP, as 41.2% of all websites are potentially vulnerable.

WordPress Sites Targeted as Hackers Exploit Critical wp2shell Flaws
Hackers are actively exploiting critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to inject malicious plugins and PHP webshells, putting countless sites at risk. Attackers are using mass-scanning and plugin upload abuse to gain control, making it essential for WordPress users to take immediate action.

WordPress Exploitation Surges as Public Exploit Fuels Remote Code Execution
A surge in WordPress exploitations is underway as hackers leverage a public exploit to enable remote code execution on vulnerable sites, posing a threat to organizations of all sizes and industries. The flaw, dubbed "wp2shell," allows unauthenticated attacks on default WordPress installations, sparking widespread scanning and compromise.

WordPress Exploits Spread as Attackers Chain Critical Vulnerabilities
Within hours of public disclosure, hackers leveraged AI models to exploit two critical WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, that when combined enable unauthenticated remote code execution. This potent pairing allows attackers to wreak havoc on websites, highlighting the urgent need for updates.

WordPress Discloses Core Flaw Enabling Unauthenticated Code Execution
WordPress has patched a critical flaw that allowed hackers to execute code remotely without authentication, releasing versions 6.9.5 and 7.0.2 to fix the vulnerability. The update addresses a REST API batch-route confusion and SQL injection issue that could be triggered by a simple HTTP request.

AI-Powered Tool Discovers Zero-Day in WordPress Plugin
Meet the AI-powered tool that just discovered a zero-day vulnerability in a popular WordPress plugin, and learn how its automated pipeline can detect and exploit weaknesses in code. This game-changing technology can extract sensitive data, like password hashes and secret tokens, from live databases.

WordPress Plugins Backdoored in ShapedPlugin Supply Chain Attack
A recent supply chain attack on ShapedPlugin compromised the updates for several WordPress plugins, including Product Slider Pro for WooCommerce, injecting backdoor code that could give attackers full control of affected sites. This severe vulnerability, rated 10.0 on the CVSS scale, highlights the importance of staying vigilant about plugin updates and security.

Hackers Exploit Gravity SMTP Plugin Bug to Expose API Keys
Malicious hackers are racing to exploit a vulnerability in the Gravity SMTP plugin, which has been installed on around 100,000 WordPress sites, to get their hands on sensitive API keys. Over 17 million exploit attempts have already been blocked by Wordfence, highlighting the urgent need for site owners to update to version 2.1.5.

Hackers Exploit Gravity SMTP Plugin Bug on 100,000 WordPress Sites
A critical bug in the Gravity SMTP plugin is being exploited by hackers on over 100,000 WordPress sites, putting sensitive information at risk. Update to version 2.1.5 or later to patch the vulnerability.

Law Enforcement Disrupts SocGholish Malware Network, Cleans 15,000 WordPress Sites
In a major win for cybersecurity, an international team of law enforcement agencies has dismantled a notorious malware network, freeing 15,000 WordPress sites from infection and dealing a significant blow to cybercriminals. This decisive action is just the beginning, with authorities vowing to continue the fight against botnets and cybercrime.

Law Enforcement Disrupts SocGholish Botnet Linked to Evil Corp
In a major win for cybersecurity, an international coalition of law enforcement agencies has dismantled the notorious SocGholish botnet, liberating nearly 15,000 compromised WordPress sites and taking down 106 servers and domains used by cybercriminals. This bold operation has effectively cut off the cybercrime gang's access to thousands of infected computer systems.

WordPress Plugins Compromised to Deploy Hidden Backdoors
Over 1.2 million WordPress sites are potentially at risk after a security breach compromised three popular plugins, allowing hackers to secretly install backdoors and gain admin access. The sneaky attack injects malicious code that only kicks in when a logged-in administrator visits the site, putting unsuspecting site owners in the dark.