Wordpress

WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected…

2 days ago

WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks

A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete…

4 days ago

Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks

A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and…

1 week ago

Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks

A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially…

2 weeks ago

New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors.…

3 weeks ago

WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2

A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator…

1 month ago

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in…

1 month ago

70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks

A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP,…

2 months ago

Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to…

2 months ago

Hackers Actively Exploiting WordPress SMTP Plugin With 100,000+ Installs to Access Sensitive Data

Hackers are actively abusing a sensitive information exposure flaw in the Gravity SMTP WordPress plugin, aggressively targeting over 100,000 sites…

2 months ago