Collected every two hours from specialised publications — each link leads to the original article.
The maintainers of the Jetpack WordPress plugin have released a security update to remediate a critical vulnerability that could allow logged-in users to acces…
A new high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could enable malicious actors to execute arbitrary JavaSc…
Cybersecurity researchers have discovered yet another critical security flaw in the LiteSpeed Cache plugin for WordPress that could allow unauthenticated users…
WordPress admins should once again update their websites to receive plugin updates, particularly if they…WPML WP Plugin Vulnerability Risked 1M+ WordPress Webs…
WordPress admins using the Litespeed Cache plugin must update their sites with the latest plugin…LiteSpeed Cache Plugin Vulnerability Risked 5+ Million WordPre…
A maximum-severity security flaw has been disclosed in the WordPress GiveWP donation and fundraising plugin that exposes more than 100,000 websites to remote c…
WordPress admins running the Modern Events Calendar plugin on their websites must rush to update…Vulnerability In Modern Events Calendar WordPress Plugin Activ…
WordPress admins must update their websites with the latest ProfileGrid plugin release. A severe privilege…ProfileGrid WordPress Plugin Vulnerability Could All…
Heads up, WordPress admins! Researchers ask WordPress users to update their sites with the latest…Patch These Compromised WordPress Plugins Asap To Avoid Attac…
Researchers uncovered a new wave of malware attacks against WordPress websites, exploiting known XSS vulnerabilities…XSS Flaws In Multiple WordPress Plugins Ex…
Heads up WordPress admins. If you’ve been running Dessky Snippets plugin on your WordPress e-stores,…Dessky Snippets WordPress Plugin Exploited For Card Skimmi…
Cybersecurity researchers have warned that multiple high-severity security vulnerabilities in WordPress plugins are being actively exploited by threat actors t…
Several security vulnerabilities have been discovered in Wordpress, a popular content management framework, which may lead to exposure of sensitive information…
WordPress admins using the Forminator plugin on their websites must rush to update their sites…Multiple Vulnerabilities Found In Forminator WordPress Plugin on…
WordPress 6.4.4 Security Release Security updates included in this release A cross-site scripting (XSS) vulnerability affecting the Avatar block type; reported…
WordPress admins using the LayerSlider plugin on their websites must update their sites with the…LayerSlider WordPress Plugin Vulnerability Affected Thousands …
A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashe…
Heads up, WordPress admins! It’s time to update your WordPress websites with the latest Popup…Popup Builder Plugin Flaw Exploited To Infect WordPress Sites on …
A new malware campaign is leveraging a high-severity security flaw in the Popup Builder plugin for WordPress to inject malicious JavaScript code.According to S…
According to a recent post from Sucuri, their website scanner detected an active distributed brute-force…WordPress Sites Exploited To Brute-Force Passwords Via…
Two security vulnerabilities have been discovered in Wordpress, a popular content management framework, a PHP File Upload bypass via the plugin installer and a…
A security vulnerability has been disclosed in the LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges.Tr…
A critical security flaw has been disclosed in a popular WordPress plugin called Ultimate Member that has more than 200,000 active installations.The vulnerabil…
A critical security flaw in the Bricks theme for WordPress is being actively exploited by threat actors to run arbitrary PHP code on susceptible installations.…