Friday, August 28, 2026
Follow on LinkedIn

Wordpress

WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. TranslatePress...

WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks

A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover attacks. The flaw has a CVSS severity score of 9.8. It can allow unauthenticated attackers to upload malicious...

Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks

A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the vulnerability affects Elementor Pro versions up to and including 4.2.1 and...

Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks

A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially enabling them to take full control of vulnerable websites. The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1.56.1 and...

New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident on August 7, 2026, after discovering that attackers had poisoned a remote...

WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2

A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access. The malicious version, 10.8.7, affects a plugin with roughly 20,000 active installations and is tracked as CVE-2026-18072, with a...

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,...

70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks

A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP, significantly increasing their exposure to cyberattacks. The findings highlight a growing security gap in the global web ecosystem, where millions...

Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS...

Hackers Actively Exploiting WordPress SMTP Plugin With 100,000+ Installs to Access Sensitive Data

Hackers are actively abusing a sensitive information exposure flaw in the Gravity SMTP WordPress plugin, aggressively targeting over 100,000 sites to harvest configuration data and live email credentials. The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), affects all Gravity...

Latest News

Latest News