Tag: wordpress
-
Wordfence Finds Critical Backdoor in ARVE WordPress Plugin
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites. First seen on hackread.com Jump to article: hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first flaw added to the KeV…
-
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first issue added to the catalog…
-
CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, infrastructure, injection, kev, sql, vulnerability, wordpressThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input…
-
Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites. The post Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-wordpress-core-vulnerabilities-active-exploitation/
-
Critical wp2shell WordPress flaws exploited to install webshells
Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/
-
Lücken in WordPress: Millionen von Websites sind laufenden Angriffen ausgesetzt
Tags: wordpressAngreifer attackieren WordPress-Instanzen über kritische Sicherheitslücken. Schätzungen zufolge sind rund 90 Millionen Websites noch ungepatcht. First seen on golem.de Jump to article: www.golem.de/news/luecken-in-wordpress-laufende-schadcode-attacken-gefaehrden-millionen-von-websites-2607-211105.html
-
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.”By the early hours of Saturday morning (UTC), successful exploitation was already well First seen on thehackernews.com Jump…
-
‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover
-
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/
-
WordPress Remote Code Execution Flaws Get Public Exploits
PoCs are now available for the two WordPress vulnerabilities that power the wp2shell RCE attack chain. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/wordpress-remote-code-execution-flaws-get-public-exploits/
-
Researchers Build WordPress Exploit Using OpenAI’s GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/researchers-wordpress-exploit/
-
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
Tags: authentication, cyber, exploit, flaw, injection, rce, remote-code-execution, sql, vulnerability, wordpressA critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain using GPT-5.6 Sol Ultra during a multi-agent audit of the WordPress source code. GPT-5.6 Sol…
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations…
-
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/19/week-in-review-oauth-client-ids-spoofed-sonicwall-sma-appliances-targeted-in-zero-day-attacks/
-
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
-
Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/18/wordpress-vulnerabilities-wp2shell-cve-2026-60137-cve-2026-60137/
-
Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/18/wordpress-vulnerabilities-wp2shell-cve-2026-60137-cve-2026-60137/
-
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed >>wp2shell,<< that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites globally. The flaw represents one of the most significant CMS security disclosures in recent memory. The issue stems…
-
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable.Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.Adam Kues at Assetnote, Searchlight…
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.…
-
Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
Australia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwide, with many small and medium-sized Australian businesses already hit. Attackers are scanning websites for known vulnerabilities, deploying webshells…
-
Globale Angriffswelle auf WordPress und Joomla
Tags: wordpressDas australische Cybersicherheitszentrum ACSC warnt vor einer globalen Kampagne, bei der Angreifer Webshells über Sicherheitslücken in CMS-Systemen einschleusen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/globale-angriffswelle-auf-wordpress
-
Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access
A large-scale exploitation campaign is actively weaponising known vulnerabilities across multiple content management systems, with WordPress plugins forming the primary attack surface. Cyber actors are scanning the internet for vulnerable sites and chaining unauthenticated file upload, remote code execution (RCE), server-side request forgery (SSRF) and deserialization vulnerabilities to deploy webshells that grant persistent remote access.…
-
Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks
A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue in how organizations manage their backend infrastructure, particularly given that WordPress remains the leading content…
-
Veraltete Systeme: Hacker attackieren Millionen WordPress-Seiten
Laut Censys sind 86 Prozent aller WordPress-Seiten veraltet. Angreifer nutzen automatisierte Werkzeuge, um diese Sicherheitslücken gezielt auszunutzen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/wordpress-seiten-hacker
-
Plugins verteilen Schadcode über manipuliertes CDN-Skript – Supply-Chain-Angriff trifft 1,2 Millionen WordPress-Seiten
First seen on security-insider.de Jump to article: www.security-insider.de/wordpress-supply-chain-angriff-optinmonster-cdn-schadcode-a-b2cef61d808bf531e17d4f573af7f099/
-
WordPress plugin Gravity SMTP exploited for sensitive information disclosure
First seen on scworld.com Jump to article: www.scworld.com/brief/wordpress-plugin-gravity-smtp-exploited-for-sensitive-information-disclosure

