wordpress
124 articles with this tag
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
INFO
CRITICAL
CRITICAL
MEDIUM
MEDIUM
LOW
MEDIUM
CRITICAL
MEDIUM
MEDIUM
CRITICAL
MEDIUM
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
CRITICAL
CRITICAL
CRITICAL
CRITICAL
INFO
CRITICAL
CRITICAL
MEDIUM
CRITICAL
HIGH
CRITICAL
CRITICAL
MEDIUM
MEDIUM
INFO
CRITICAL
MEDIUM
CRITICAL
INFO
HIGH
LOW
HIGH
CRITICAL
CRITICAL
CRITICAL
LOW
CRITICAL
HIGH
HIGH
INFO
MEDIUM
HIGH
HIGH
CRITICAL
CRITICAL
LOW
MEDIUM
INFO
CRITICAL
HIGH
CRITICAL
CRITICAL
MEDIUM
MEDIUM
INFO
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)
WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
What happens if you visit a WordPress site hacked through wp2shell?
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
Attackers pummel critical WordPress vuln to create all sorts of mischief
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
Researchers Build WordPress Exploit Using OpenAI's GPT
Patch now: WordPress REST API bug allows remote code execution
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
Multiples vulnérabilités dans WordPress (20 juillet 2026)
Multiples vulnérabilités dans WordPress (20 juillet 2026)
WP2Shell WordPress Vulnerabilities Exploited in the Wild
wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched.
wp2shell (CVE-2026-63030) update: public working exploit now available for the WordPress core pre-auth RCE
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
NCSC-2026-0250 [1.00] [H/M] Kwetsbaarheden verholpen in WordPress door Automattic
wp2shell: Pre Authentication RCE in WordPress Core
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)
We built a vulnerability vending machine: AI tokens in, zero-days out
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
[webapps] WordPress Bricks Builder Theme - RCE
[webapps] KeepInMind 0.8.4.2 - Stored XSS
[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)
22nd June – Threat Intelligence Report
WordPress plugin Gravity SMTP exploited for sensitive information disclosure
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
ShapedPlugin update flow hacked to infect WordPress sites
PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels
OptinMonster WordPress plugin hacked in CDN supply-chain attack
Attackers Hijack Popular WordPress Plugins to Deploy Backdoors
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)
Hackers exploit critical Everest Forms Pro vulnerability for website control
Everest Forms Vulnerability Exploited to Hack WordPress Sites
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Quarterly WordPress Threat Intelligence Report – Q1 2026
WordPress Kirki plugin vulnerability allows account takeover
Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 25, 2026 to May 31, 2026)
Attackers Actively Exploiting Critical Vulnerability in Everest Forms Pro Plugin
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Attackers Actively Exploiting Critical Vulnerability in Burst Statistics Plugin
Critical vulnerability in WP Maps Pro allows rogue administrator account creation
[webapps] WordPress OrderConvo 14 - Path Traversal
WordPress malware campaign hides payloads in Steam profiles
Wordfence Bug Bounty Program Monthly Report – March 2026
[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 18, 2026 to May 24, 2026)
[webapps] cPanel - CRLF Injection
$20 per zero-day is already the WordPress plugin reality
[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Cross-Site Scripting
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 11, 2026 to May 17, 2026)
How a Webmail Log File Became a Root-Level Backdoor
WordPress Funnel Builder vulnerability exploited to steal payment data
Funnel Builder WordPress plugin bug exploited to steal credit cards
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 4, 2026 to May 10, 2026)
200,000 WordPress Sites at Risk from Critical Authentication Bypass Vulnerability in Burst Statistics Plugin
Avada Builder Flaws Expose One Million WordPress Sites
1,000,000 WordPress Sites Affected by Arbitrary File Read and SQL Injection Vulnerabilities in Avada Builder WordPress Plugin
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 27, 2026 to May 3, 2026)
Arbitrary code pushed by long concealed backdoor in widely used WordPress redirect add-on
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)
Popular WordPress redirect plugin hid dormant backdoor for years
Critical vulnerability in WordPress Breeze Cache plugin exploited
Hackers exploit file upload bug in Breeze Cache WordPress plugin
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)
[webapps] WordPress Plugin 5.2.0 - Broken Access Control
The Increasing Role of AI in Vulnerability Research
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026)
Critical Vulnerability in Ninja Forms Exposes WordPress Sites
Hackers exploit critical flaw in Ninja Forms WordPress plugin
[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Cross-Site Scripting
[webapps] WordPress Madara - Local File Inclusion
Cloudflare’s new CMS is not a WordPress killer, it’s a WordPress alternative
Wordfence Bug Bounty Program Monthly Report – February 2026
Wordfence Intelligence Weekly WordPress Vulnerability Report (March 16, 2026 to March 22, 2026)
800,000 WordPress Sites Affected by Arbitrary File Read Vulnerability in Smart Slider 3 WordPress Plugin
ClickFix treibt neue Infostealer-Kampagnen an
Hacked sites deliver Vidar infostealer to Windows users
Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign
Multiples vulnérabilités dans WordPress (11 mars 2026)
30,000 WordPress Sites Affected by Authentication Bypass Vulnerability in Tutor LMS Pro WordPress Plugin
WordPress membership plugin bug exploited to create admin accounts