WordPress News Articles

Recent news articles refferecing the vendors vulnerabilities.

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code execution.

4 days ago

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Hackers are exploiting a vulnerability (CVE-2026-32475) in the Elementor Pro plugin to hack WordPress sites.

2 weeks ago

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Attackers are exploiting Super Forms and Elementor Pro flaws to upload PHP files and execute code on WordPress sites.

2 weeks ago

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.

2 weeks ago

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

2 weeks ago

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server.

3 weeks ago

Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

An exposed staging server reveals ownCloud pre-signed URL abuse against a Philippine nuclear agency and exploitation of a naval contractor's WordPress website.

3 weeks ago

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers are scanning for two miniOrange SAML flaws, including CVE-2026-15981, that can bypass login and grant WordPress admin access.

4 weeks ago

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.

1 month ago

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.

1 month ago

Forminator's Critical Upload Flaw Puts 600,000 WordPress Sites at Risk of Instant Takeover

A critical unauthenticated arbitrary file upload vulnerability in the Forminator WordPress plugin threatens over 600,000 sites with remote code execution. CVE-2026-15748 allows attackers to bypass file type checks via forged form fields when both upload and select elements are present. Sites using c...

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

CVE-2026-15748, a critical arbitrary file upload in the Forminator Forms WordPress plugin, could be exploited for code execution.

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.

NITDA warns WordPress users over vulnerability that could give attackers website control

Nigeriaโ€™s National Information Technology Development Agency (NITDA) has warned WordPress users and administrators about a pre-authentication vulnerability that could allow attackers to execute malicious PHP code on affected websites.

WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution - IT Security News

2026-08-08 11:08 WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the...

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server.

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild - IT Security News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,โ€ฆRead ...

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

CISA warns that an actively exploited WordPress Core SQL injection flaw could compromise websites and potentially enable remote code execution.

Hackers Exploit Newly Patched WordPress Vulnerabilities

Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

No more news articles to load.