Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek. more…Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?
Automattic CEO Matt Mullenweg has been abruptly put on a paid leave of absence from the company by its board of directors, despite his objections. But enterprise IT executives who rely on WordPress may find the shift doesn’t mean much as long as Mullenweg fully controls WordPress.org, which handles all of the product’s patches and […] more…Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek. more…WordPress Security Plugins: How to Choose the Right One
In short, WordPress security plugins are tools you add to your site to strengthen your settings, scan for malware, watch for file changes, and block suspicious activity from within WordPress. Most sites should use one, along with a firewall that filters traffic before WordPress even loads. Look for layered protection, good detection, clear handling of […] more…Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek. more…WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek. more…300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek. Incoming search termsnotn66 more…The Illusion of a Lock – How AI is changing the speed and scale of hands-on WordPress vulnerability research.
2026: the year the tools learned to hack In May 2026, OpenAI began testing an internal research model against a cybersecurity benchmark called ExploitGym. While the test environment was not supposed to have access to the open internet, there was, however, one narrow path out because the agents still needed a way to install software: […] more…WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek. more…How to Create a Secure WordPress Staging Site: Beginner’s Guide
Updating WordPress directly on a live website can cause avoidable problems. A plugin update might break checkout, or a theme change could create layout issues visitors see immediately. A WordPress staging site gives you a separate place to test changes before they reach your live website. Staging reduces operational risk, but it also creates another […] more…WP2Shell WordPress Vulnerabilities Exploited in the Wild
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. more…Why Delaying WordPress Updates Increases Security Risks
WordPress updates help close known vulnerabilities before automated attacks can find and exploit them. Once a patch is released, attackers often move quickly to scan for sites that have not yet updated. It’s easy to put off updates when everything seems to be working. But once a vulnerability is public, attackers do not need to […] more…Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on SecurityWeek. more…15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWeek. Incoming search termsswameka more…WordPress PBN Plugin Drops Dual Webshells via Database Injection
During a recent incident response engagement, our team uncovered a multi-stage WordPress infection that goes beyond the usual file-based malware. The attacker combined a fake plugin, a remote command-and-control server, and two PHP web shells stored directly inside the WordPress database. The campaign is operated by a Turkish-speaking threat actor and is built around a […] more…Everest Forms Vulnerability Exploited to Hack WordPress Sites
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek. more…More information
- PASS will be unavailable on 3/26
- Why is the Technology Industry Shirking its Security Responsibilities?
- Microsoft PowerPoint CVE-2017-8513 Remote Code Execution Vulnerability
- Fatboy ransomware adjusts demands based on local price of a Big Mac
- Apple Patches iOS Flaws Used in Kaspersky ‘Operation Triangulation’
- Necurs Returns With New Scarab Ransomware Campaign
- ‘Anti-virus is dead,’ says Symantec, as it revises partner programme
- CVS Group Restoring Systems Impacted by Cyberattack
- Could Apple Card finally become an international service?
- US lawmakers concerned by accuracy of facial recognition