vulnerability Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE Multiple critical vulnerabilities have been discovered in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could lead to complete site takeover, allowing attackers to gain administrator access and execute arbitrary code, highlighting a significant… The Hacker News · 1d ago Critical CVE-2026-76581CVE-2026-18431CVE-2026-19632wordpressvulnerabilityplugin
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
vulnerability Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access Attackers are exploiting two unauthenticated vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain administrator access to vulnerable sites. The vulnerabilities stem from f… The Hacker News · 5d ago High CVE-2026-61979CVE-2026-15981wordpresssamlauthentication
vulnerability Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a d… The Hacker News · Aug 20, 2026 High CVE-2026-32475CVE-2026-65640wordpressvulnerabilityremote-code-execution
threat-intel StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data A sophisticated cybercrime operation, dubbed StopAndProtect, is leveraging over 6,000 compromised WordPress sites globally to distribute malware, steal data, and deploy ransomware. The attackers use a multi-stage attack… The Hacker News · Aug 19, 2026 High USRUINwordpressmalwareransomware
vulnerability 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw A critical vulnerability in the Forminator Forms plugin for WordPress is exposing over 300,000 websites to potential remote code execution attacks. The flaw stems from inadequate file type validation, allowing attackers… SecurityWeek · Aug 18, 2026 Critical CVE-2026-15748wordpressvulnerabilityrce
vulnerability Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads A critical security flaw in Forminator Forms (WordPress plugin) and User Profile Builder (WordPress plugin) allows unauthenticated attackers to execute arbitrary code on vulnerable sites. The Forminator vulnerability (CV… The Hacker News · Aug 17, 2026 Critical CVE-2026-15748CVE-2026-15826wordpressvulnerabilityremote code execution
vulnerability WordPress 7.0.4 Patches Remote Code Execution Vulnerability WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability. This flaw, tracked as CVE-2026-65640, allows authenticated attackers to execute code by uploading malicious PostScript… SecurityWeek · Aug 13, 2026 High CVE-2026-65640wordpressvulnerabilityremote code execution
vulnerability Vulnérabilité dans WordPress (13 août 2026) A remote code execution vulnerability has been identified in older versions of WordPress, allowing attackers to execute arbitrary code. This affects WordPress versions prior to 7.0.4, and requires immediate patching to p… CERT-FR · Aug 13, 2026 Critical CVE-2026-65640wordpressrcevulnerability
supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The att… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss
vulnerability New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A high-severity cross-site scripting (XSS) vulnerability in WordPress's login screen allows attackers to execute PHP code on a server, potentially leading to database compromise and full system control. The vulnerability… The Hacker News · Aug 7, 2026 High CVE-2026-64638xsswordpresscve-2026-64638
vulnerability Multiples vulnérabilités dans WordPress (07 août 2026) Multiple vulnerabilities have been discovered in WordPress, including remote code execution and privilege escalation, potentially leading to data compromise. These flaws are primarily affecting older versions of the plat… CERT-FR · Aug 7, 2026 High CVE-2026-64638wordpressvulnerabilityssrf
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
threat-intel Fuite revendiquée au Rassemblement national ? A pirate claims to have compromised the website of the French far-right party, Rassemblement National (formerly Front National), and is offering a recent SQL dump for sale. The dump, allegedly containing 95 tables, inclu… ZATAZ · Jul 21, 2026 High FRdata breachsql dumpwordpress
threat-intel Attackers pummel critical WordPress vuln to create all sorts of mischief This article covers a range of cybersecurity and technology news, including a vulnerability exploited to create mischief, a Russian phishing campaign mimicking Signal support, and a significant acquisition in the cyberse… The Register · Jul 20, 2026 Medium CVE-2026-63030CVE-2026-60137vulnerabilityphishingransomware
threat-intel 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover A newly discovered exploit chain, dubbed ‘WP2Shell,’ is rapidly being used to compromise millions of WordPress sites. Attackers are chaining together a SQL injection vulnerability (CVE-2026-60137) and a logic flaw in the… Dark Reading · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030sql injectionremote code executionwordpress
threat-intel WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) A critical WordPress webshell vulnerability (CVE-2026-63030) is being actively exploited. This vulnerability, stemming from a SQL injection flaw in the WordPress Core REST API, allows unauthenticated remote code executio… SANS Internet Storm Center · Jul 20, 2026 Critical CVE-2026-63030sql injectionwebshellwordpress
threat-intel WP2Shell WordPress Vulnerabilities Exploited in the Wild Two recently patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. Attackers are leveraging these flaws to gain remote code execution on WordPress site… SecurityWeek · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability