supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The attack exploited a cross-site scripting (XSS) vulnerability in the vendor’s internal API, leading to th… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
vulnerability New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A high-severity cross-site scripting (XSS) vulnerability in WordPress's login screen allows attackers to execute PHP code on a server, potentially leading to database compromise and full system control. The vulnerability… The Hacker News · Aug 7, 2026 High CVE-2026-64638xsswordpresscve-2026-64638
vulnerability Multiples vulnérabilités dans WordPress (07 août 2026) Multiple vulnerabilities have been discovered in WordPress, including remote code execution and privilege escalation, potentially leading to data compromise. These flaws are primarily affecting older versions of the plat… CERT-FR · Aug 7, 2026 High CVE-2026-64638wordpressvulnerabilityssrf