WordPress News Articles
Recent news articles refferecing the vendors vulnerabilities.
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.
3 days ago
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.
3 days ago
Forminator's Critical Upload Flaw Puts 600,000 WordPress Sites at Risk of Instant Takeover
A critical unauthenticated arbitrary file upload vulnerability in the Forminator WordPress plugin threatens over 600,000 sites with remote code execution. CVE-2026-15748 allows attackers to bypass file type checks via forged form fields when both upload and select elements are present. Sites using c...
5 days ago
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
CVE-2026-15748, a critical arbitrary file upload in the Forminator Forms WordPress plugin, could be exploited for code execution.
5 days ago
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.
5 days ago
NITDA warns WordPress users over vulnerability that could give attackers website control
Nigeriaâs National Information Technology Development Agency (NITDA) has warned WordPress users and administrators about a pre-authentication vulnerability that could allow attackers to execute malicious PHP code on affected websites.
1 week ago
WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution - IT Security News
2026-08-08 11:08 WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the...
2 weeks ago
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution
A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server.
2 weeks ago

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.
2 weeks ago
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild - IT Security News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,âŚRead ...
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
CISA warns that an actively exploited WordPress Core SQL injection flaw could compromise websites and potentially enable remote code execution.

Hackers Exploit Newly Patched WordPress Vulnerabilities
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
CVE-2026-63030 and CVE-2026-60137: Mitigating a Critical Unauthenticated RCE Chain in WordPress - IT Security News
This post doesnât have text content, please click on the link below to view the original article. This article has been indexed from Blog Read the original article: CVE-2026-63030 and CVE-2026-60137: Mitigating a Critical Unauthenticated RCE Chain in WordPressRead more â
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) - IT Security News
Last week, Searchlight Cyber released details about a vulnerability they are calling âwp2shellâ. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell isâŚRead more â
Critical wp2shell RCE Vulnerability â Complete Coverage Including PoC and Active Exploitation Details - IT Security News
A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed âwp2shellâ has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CV...
WordPress Remote Code Execution Flaws Get Public Exploits | eSecurity Planet
PoCs are now available for the two WordPress vulnerabilities that power the wp2shell RCE attack chain.
Researchers Build WordPress Exploit Using OpenAI's GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAIâs latest model to develop an exploit chain
Imperva Customers Protected Against âwp2shellâ Pre-Authentication RCE in WordPress Core - IT Security News
TL;DR: A critical pre-authentication Remote Code Execution (RCE) vulnerability, dubbed âwp2shellâ (CVE-2026-63030), has been identified in WordPress Core. This vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable WordPress installation without any preconditions,...
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical
WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 - IT Security News
The CVE-2026-63030 â âwp2shellâ: Why Millions of WordPress Sites Are Vulnerable and Emergency to Patch If you run⌠The post WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 appeared first on Hackers Online Club. This article hasâŚRead more â