vulnerability Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE Multiple critical vulnerabilities have been discovered in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could lead to complete site takeover, allowing attackers to gain administrator access and execute arbitrary code, highlighting a significant… The Hacker News · 22h ago Critical CVE-2026-76581CVE-2026-18431CVE-2026-19632wordpressvulnerabilityplugin
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
vulnerability CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw CISA has issued a critical three-day patch deadline for a vulnerability in the Perfect 10 plugin for Joomla, which is being actively exploited by attackers. This plugin flaw allows attackers to gain unauthorized access t… The Register · 5d ago Critical CVE-2026-21962joomlavulnerabilityplugin
vulnerability Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access Attackers are exploiting two unauthenticated vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain administrator access to vulnerable sites. The vulnerabilities stem from f… The Hacker News · 5d ago High CVE-2026-61979CVE-2026-15981wordpresssamlauthentication
vulnerability Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads A critical security flaw in Forminator Forms (WordPress plugin) and User Profile Builder (WordPress plugin) allows unauthenticated attackers to execute arbitrary code on vulnerable sites. The Forminator vulnerability (CV… The Hacker News · Aug 17, 2026 Critical CVE-2026-15748CVE-2026-15826wordpressvulnerabilityremote code execution
vulnerability DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories A series of vulnerabilities, dubbed "DifyTap," have been discovered in the Dify AI application building platform, allowing attackers to potentially access and exfiltrate sensitive data, including AI chat histories. The f… Dark Reading · Jun 22, 2026 High CVE-2026-41947CVE-2026-41948CVE-2026-41949aisecurityvulnerability
supply-chain ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack A supply chain attack compromised multiple WordPress plugins from ShapedPlugin, injecting backdoor code into Pro plugin releases distributed through official update channels. The malicious plugins, affecting versions of… The Hacker News · Jun 22, 2026 Critical CVE-2026-49777CVE-2026-10735wordpresssupply chainbackdoor
vulnerability Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys A vulnerability in the Gravity SMTP WordPress plugin has been exploited by attackers, allowing them to extract sensitive data such as API keys and configuration details from approximately 100,000 sites. The flaw, tracked… The Hacker News · Jun 20, 2026 Medium CVE-2026-4020USwordpressapicredentials
supply-chain ShapedPlugin update flow hacked to infect WordPress sites A supply-chain attack targeting WordPress plugins from ShapedPlugin resulted in malicious updates containing a backdoor designed to steal sensitive data from affected websites. The attack exploited a compromised build pi… BleepingComputer · Jun 18, 2026 High CVE-2026-10735CVE-2026-49777wordpresssupply chainbackdoor
threat-intel Malicious JetBrains Marketplace plugins steal AI API keys from developers A coordinated malware campaign involving 15 malicious plugins for the JetBrains Marketplace was discovered, designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and code review… BleepingComputer · Jun 16, 2026 High USapi-keycredential-theftide
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
vulnerability Critical Everest Forms Pro flaw exploited to take over WordPress sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited by attackers to gain complete control over affected websites. This flaw allows for arbitrary code execution,… BleepingComputer · Jun 6, 2026 Critical CVE-2026-3300wordpresspluginvulnerability
vulnerability Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts A critical security flaw (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been actively exploited to create administrator accounts on vulnerable websites. The vulnerability stems from a flaw in the plugin's tempor… The Hacker News · Jun 1, 2026 Critical CVE-2026-8732wordpresspluginvulnerability