WordPress News Articles

Recent news articles refferecing the vendors vulnerabilities.

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

SC WordPress malware rebuilds its backdoor from files, the database, and shared memory; fewer than 20 wpForo exploit attempts were seen since July 3.

1 week ago

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure - SwapUpdate

Ravie LakshmananSep 24, 2026Vulnerability / Web Security

2 weeks ago

Critical Contact Form 7 Vulnerability CVE-2026-87902 Actively Exploited in WordPress 6.6

WordPress sites face active exploitation of critical CVE-2026-87902 in Contact Form 7 (v5.9.2–5.9.5) on WordPress 6.6.x, enabling unauthenticated attackers to upload PHP backdoors via directory traversal and gain full control. Immediate patching to plugin 5.9.6+ and core 6.6.2 is essential.

2 weeks ago

CVE-2026-87902: Critical Vulnerability in WordPress

We explain in simple terms why the CVE-2026-87902 vulnerability is dangerous, and how to protect your company against it.

2 weeks ago

WordPress Patch Became Exploit Blueprint: CVE-2026-87902 Webshells Hit 350K Sites

CVE-2026-87902: Hackers deployed PHP webshells on WordPress servers within 48 hours of the September 22 security patch, with attack traffic surging tenfold as more than 350,000 sites remain

2 weeks ago

WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution

Hackers are actively exploiting CVE-2026-87902, a critical WordPress flaw that can lead to remote code execution. Here’s what admins should do.

2 weeks ago

Hackers Actively Exploiting Wordpress Vulnerability to Execute Malicious Code

The critical WordPress vulnerability is actively exploited to write malicious PHP files on vulnerable servers.

2 weeks ago

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Attackers are exploiting WordPress CVE-2026-87902 to include pearcmd.php and write PHP files when specific theme and server conditions are met.

2 weeks ago

WordPress patches a critical severity security vulnerability

The hole, which allows an unauthenticated attacker to perform remote code execution, is especially dangerous because many enterprises are not aware of all of their WordPress sites.

2 weeks ago

Critical WordPress Vulnerability Exploited Immediately After Disclosure

Hackers started exploiting CVE-2026-87902, a critical WordPress flaw leading to RCE, within hours of public disclosure.

2 weeks ago

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.

2 weeks ago

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) - IT Security News

2026-09-23 11:09 WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the...

2 weeks ago

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) - Help Net Security

WordPress 7.1.2 security release fixes a critical flaw (CVE-2026-87902) letting unauthenticated attackers load local PHP files and run code.

2 weeks ago

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code execution.

3 weeks ago

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Hackers are exploiting a vulnerability (CVE-2026-32475) in the Elementor Pro plugin to hack WordPress sites.

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Attackers are exploiting Super Forms and Elementor Pro flaws to upload PHP files and execute code on WordPress sites.

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server.

Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities

An exposed staging server reveals ownCloud pre-signed URL abuse against a Philippine nuclear agency and exploitation of a naval contractor's WordPress website.

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers are scanning for two miniOrange SAML flaws, including CVE-2026-15981, that can bypass login and grant WordPress admin access.

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.

Forminator's Critical Upload Flaw Puts 600,000 WordPress Sites at Risk of Instant Takeover

A critical unauthenticated arbitrary file upload vulnerability in the Forminator WordPress plugin threatens over 600,000 sites with remote code execution. CVE-2026-15748 allows attackers to bypass file type checks via forged form fields when both upload and select elements are present. Sites using c...

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

CVE-2026-15748, a critical arbitrary file upload in the Forminator Forms WordPress plugin, could be exploited for code execution.

No more news articles to load.