WordPress News Articles
Recent news articles refferecing the vendors vulnerabilities.
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code execution.
4 days ago
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Hackers are exploiting a vulnerability (CVE-2026-32475) in the Elementor Pro plugin to hack WordPress sites.
2 weeks ago
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Attackers are exploiting Super Forms and Elementor Pro flaws to upload PHP files and execute code on WordPress sites.
2 weeks ago
Critical Elementor Pro flaw exploited to take over WordPress sites
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server.
2 weeks ago
WordPress backup plugin flaw exposes millions of sites to takeover attacks
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.
2 weeks ago
Critical Avada WordPress theme flaw enables zero-click RCE
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server.
3 weeks ago
Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
An exposed staging server reveals ownCloud pre-signed URL abuse against a Philippine nuclear agency and exploitation of a naval contractor's WordPress website.
3 weeks ago
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Attackers are scanning for two miniOrange SAML flaws, including CVE-2026-15981, that can bypass login and grant WordPress admin access.
4 weeks ago
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.
1 month ago
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.
1 month ago
Forminator's Critical Upload Flaw Puts 600,000 WordPress Sites at Risk of Instant Takeover
A critical unauthenticated arbitrary file upload vulnerability in the Forminator WordPress plugin threatens over 600,000 sites with remote code execution. CVE-2026-15748 allows attackers to bypass file type checks via forged form fields when both upload and select elements are present. Sites using c...
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
CVE-2026-15748, a critical arbitrary file upload in the Forminator Forms WordPress plugin, could be exploited for code execution.
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.
NITDA warns WordPress users over vulnerability that could give attackers website control
Nigeriaโs National Information Technology Development Agency (NITDA) has warned WordPress users and administrators about a pre-authentication vulnerability that could allow attackers to execute malicious PHP code on affected websites.
WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution - IT Security News
2026-08-08 11:08 WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the...
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution
A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server.

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild - IT Security News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,โฆRead ...
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
CISA warns that an actively exploited WordPress Core SQL injection flaw could compromise websites and potentially enable remote code execution.

Hackers Exploit Newly Patched WordPress Vulnerabilities
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.