WordPress News Articles

Recent news articles refferecing the vendors vulnerabilities.

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.

3 days ago

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.

3 days ago

Forminator's Critical Upload Flaw Puts 600,000 WordPress Sites at Risk of Instant Takeover

A critical unauthenticated arbitrary file upload vulnerability in the Forminator WordPress plugin threatens over 600,000 sites with remote code execution. CVE-2026-15748 allows attackers to bypass file type checks via forged form fields when both upload and select elements are present. Sites using c...

5 days ago

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

CVE-2026-15748, a critical arbitrary file upload in the Forminator Forms WordPress plugin, could be exploited for code execution.

5 days ago

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.

5 days ago

NITDA warns WordPress users over vulnerability that could give attackers website control

Nigeria’s National Information Technology Development Agency (NITDA) has warned WordPress users and administrators about a pre-authentication vulnerability that could allow attackers to execute malicious PHP code on affected websites.

1 week ago

WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution - IT Security News

2026-08-08 11:08 WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the...

2 weeks ago

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server.

2 weeks ago

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.

2 weeks ago

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild - IT Security News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,…Read ...

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

CISA warns that an actively exploited WordPress Core SQL injection flaw could compromise websites and potentially enable remote code execution.

Hackers Exploit Newly Patched WordPress Vulnerabilities

Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

CVE-2026-63030 and CVE-2026-60137: Mitigating a Critical Unauthenticated RCE Chain in WordPress - IT Security News

This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Blog Read the original article: CVE-2026-63030 and CVE-2026-60137: Mitigating a Critical Unauthenticated RCE Chain in WordPressRead more →

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) - IT Security News

Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is…Read more →

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details - IT Security News

A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CV...

WordPress Remote Code Execution Flaws Get Public Exploits  | eSecurity Planet

PoCs are now available for the two WordPress vulnerabilities that power the wp2shell RCE attack chain.

Researchers Build WordPress Exploit Using OpenAI's GPT

A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain

Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core - IT Security News

TL;DR: A critical pre-authentication Remote Code Execution (RCE) vulnerability, dubbed “wp2shell” (CVE-2026-63030), has been identified in WordPress Core. This vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable WordPress installation without any preconditions,...

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical

WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 - IT Security News

The CVE-2026-63030 – “wp2shell”: Why Millions of WordPress Sites Are Vulnerable and Emergency to Patch If you run… The post WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 appeared first on Hackers Online Club. This article has…Read more →

No more news articles to load.