WordPress News Articles
Recent news articles refferecing the vendors vulnerabilities.
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild - IT Security News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,âŚRead ...
2 weeks ago
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
CISA warns that an actively exploited WordPress Core SQL injection flaw could compromise websites and potentially enable remote code execution.
2 weeks ago

Hackers Exploit Newly Patched WordPress Vulnerabilities
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.
2 weeks ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and
2 weeks ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
2 weeks ago
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
2 weeks ago
CVE-2026-63030 and CVE-2026-60137: Mitigating a Critical Unauthenticated RCE Chain in WordPress - IT Security News
This post doesnât have text content, please click on the link below to view the original article. This article has been indexed from Blog Read the original article: CVE-2026-63030 and CVE-2026-60137: Mitigating a Critical Unauthenticated RCE Chain in WordPressRead more â
2 weeks ago
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) - IT Security News
Last week, Searchlight Cyber released details about a vulnerability they are calling âwp2shellâ. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell isâŚRead more â
2 weeks ago
Critical wp2shell RCE Vulnerability â Complete Coverage Including PoC and Active Exploitation Details - IT Security News
A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed âwp2shellâ has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CV...
2 weeks ago
WordPress Remote Code Execution Flaws Get Public Exploits | eSecurity Planet
PoCs are now available for the two WordPress vulnerabilities that power the wp2shell RCE attack chain.
2 weeks ago
Researchers Build WordPress Exploit Using OpenAI's GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAIâs latest model to develop an exploit chain
2 weeks ago
Imperva Customers Protected Against âwp2shellâ Pre-Authentication RCE in WordPress Core - IT Security News
TL;DR: A critical pre-authentication Remote Code Execution (RCE) vulnerability, dubbed âwp2shellâ (CVE-2026-63030), has been identified in WordPress Core. This vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable WordPress installation without any preconditions,...
2 weeks ago
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical
2 weeks ago
WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 - IT Security News
The CVE-2026-63030 â âwp2shellâ: Why Millions of WordPress Sites Are Vulnerable and Emergency to Patch If you run⌠The post WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 appeared first on Hackers Online Club. This article hasâŚRead more â
2 weeks ago
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain - IT Security News
On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increaseâŚRead more â
2 weeks ago
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Attackers are exploiting CVE-2026-4020 in Gravity SMTP to leak API keys, OAuth tokens, and system data from WordPress sites.
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Threat actors are actively exploiting CVE-2026-3300, a critical RCE vulnerability (CVSS 9.8) in Everest Forms Pro WordPress plugin (4,000+ installs).
Critical Kirki flaw exploited to hijack WordPress admin accounts
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators.
Critical WordPress Plugin Flaw Exposes 15,000 Sites to Instant Admin Takeover
A critical unauthenticated admin account creation flaw in WP Maps Pro (CVE-2026-8732) has triggered over 3,600 exploitation attempts in a single day across 15,000+ sites. The bug in the plugin's temporary access feature allows instant site takeover via a publicly exposed AJAX action. Updates and use...
WP Maps Pro WordPress flaw exploited to create admin accounts
CVE-2026-8732 in WP Maps Pro lets unauthenticated attackers create admin accounts on 15,000+ WordPress sites. Wordfence blocked 2,858 attacks in 24 hours.
WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites - IT Security News
The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read theâŚRea...
CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a Password - IT Security News
CVE-2026-8732 in WP Maps Pro lets unauthenticated attackers create WordPress admin accounts. 2,858 attacks blocked in 24 hours. WP Maps Pro plugin allows WordPress site owners to embed Google Maps and OpenStreetMap with markers, listings, and location search. Itâs aâŚRead more â