Tag: wordpress
-
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell.…
-
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
Tags: ai, control, cyber, data-breach, intelligence, rce, remote-code-execution, threat, vulnerability, wordpressMore than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on August 23, 2026, by Wordfence Argus, an AI-assisted vulnerability research agent, and validated by the Wordfence Threat Intelligence team.…
-
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urged to update immediately due to the potential impacts of stored cross-site scripting, authenticated path traversal, authorization bypasses, and information disclosure flaws. This release…
-
Most WordPress pros still lack a breach recovery plan
Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/wordpress-security-survey-recovery-plan/
-
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/woocommerce-wholesale-lead-capture/
-
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.”This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution,” Wordfence said.The WordPress security company said it has blocked over First seen…
-
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/
-
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/
-
Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/
-
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of…
-
WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1. The Events Calendar is active on over 600,000 WordPress websites,…
-
4 in 5 Singapore Business Websites Have WordPress Vulnerabilities
A new Singapore Study has found that four in five websites run by local businesses carry at least one detectable WordPress vulnerabilities. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/wordpress-vulnerabilities-singapore-study/
-
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved.”New plugins are reviewed before they enter the directory, but updates ship continuously after that,” David Perez,…
-
How to Verify Email Addresses in WordPress With EasyDMARC
Originally published at How to Verify Email Addresses in WordPress With EasyDMARC by EasyDMARC. Collecting email addresses through WordPress is easy. Making sure those addresses are real and usable is a different challenge. A form can accept an address that… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-to-verify-email-addresses-in-wordpress-with-easydmarc/
-
WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review
WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API. This new control is designed to prevent vulnerable or malicious plugin updates from reaching millions of WordPress installations through dashboard-based, one-click updates. WordPress Blocks…
-
WordPress adds automated security checks to block risky plugin releases
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/wordpress-automated-plugin-security-review/
-
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A high-severity flaw in All-in-One WP Migration leaves 3.25 million WordPress sites exposed, with vulnerable versions potentially leading to site compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-all-in-one-wp-migration-cve-2026-19949/
-
Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary…
-
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.The vulnerabilities in question are – CVE-2026-14894 (CVSS score: 9.8) – A missing file type validation vulnerability in Super Forms Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type,…
-
Plugin-Schwachstelle betrifft mehr als 3 Millionen WordPress-Seiten
Eine Schwachstelle im Plugin All-in-One WP Migration and Backup gefährdet nach Angaben des WordPress-Sicherheitsunternehmens Defiant mehr als 3 Millionen Websites. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/wordpress-schwachstelle
-
Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/
-
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
Tags: backup, cve, cyber, exploit, flaw, injection, remote-code-execution, sql, vulnerability, wordpressA high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely used All-in-One WP Migration and Backup plugin developed by ServMask. Wordfence has rated the vulnerability 8.8 out of…
-
Lücke in Backup-Tool gefährdet Millionen von Websites
In einem WordPress-Plug-in mit über 5 Millionen Installationen klafft eine gefährliche Sicherheitslücke. Admins sollten dringend handeln. First seen on golem.de Jump to article: www.golem.de/news/wordpress-luecke-in-backup-tool-gefaehrdet-millionen-von-websites-2609-212585.html
-
WordPress backup plugin flaw exposes millions of sites to takeover attacks
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/
-
Pannen-Hacker enttarnt: ‘StopAndProtect”-Kampagne kapert Tausende WordPress-Seiten
Ein fataler Entwicklerfehler entlarvte ein globales Hacker-Netzwerk aus 2.000 WordPress-Seiten und 5.000 infizierten PCs. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/wordpress-stopandprotect
-
WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited
The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the world’s most widely used content management system. This initiative, known as the Core Security Initiative, responds to a significant rise in security-related reports over the past year. According to Rudy Faile, a member of…
-
Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated attacker execute commands on the server. Patchstack disclosed the flaw on August 28, after researcher…
-
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/
-
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). This vulnerability, tracked as CVE-2026-76581, has a CVSS score of 9.8 and affects WPMU DEV Dashboard versions 5.0.1 and earlier. The plugin…

