A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites.
The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. TranslatePress...
A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover attacks.
The flaw has a CVSS severity score of 9.8. It can allow unauthenticated attackers to upload malicious...
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers.
Tracked as CVE-2026-32475, the vulnerability affects Elementor Pro versions up to and including 4.2.1 and...
A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially enabling them to take full control of vulnerable websites.
The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1.56.1 and...
A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors.
Wordfence Threat Intelligence was notified of the incident on August 7, 2026, after discovering that attackers had poisoned a remote...
A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access.
The malicious version, 10.8.7, affects a plugin with roughly 20,000 active installations and is tracked as CVE-2026-18072, with a...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution.
This flaw, tracked as CVE-2026-63030,...
A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP, significantly increasing their exposure to cyberattacks.
The findings highlight a growing security gap in the global web ecosystem, where millions...
A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution.
The flaw, tracked as CVE-2026-8713 with a CVSS...
Hackers are actively abusing a sensitive information exposure flaw in the Gravity SMTP WordPress plugin, aggressively targeting over 100,000 sites to harvest configuration data and live email credentials.
The vulnerability, tracked as CVE‑2026‑4020 and rated 5.3 (Medium), affects all Gravity...