Collected every two hours from specialised publications — each link leads to the original article.
Cybersecurity researchers have discovered a previously undocumented malware targeting Android devices that uses compromised WordPress sites as relays for its a…
WordPress admins using the Forminator plugin on their websites must rush to update their sites…Multiple Vulnerabilities Found In Forminator WordPress Plugin on…
WordPress 6.4.4 Security Release Security updates included in this release A cross-site scripting (XSS) vulnerability affecting the Avatar block type; reported…
WordPress admins using the LayerSlider plugin on their websites must update their sites with the…LayerSlider WordPress Plugin Vulnerability Affected Thousands …
A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashe…
Heads up, WordPress admins! A new malware campaign is actively preying on WordPress websites, generating…Sign1 Malware Targeted Over 2500 WordPress Sites In Re…
Heads up, WordPress admins! It’s time to update your WordPress websites with the latest Popup…Popup Builder Plugin Flaw Exploited To Infect WordPress Sites on …
A new malware campaign is leveraging a high-severity security flaw in the Popup Builder plugin for WordPress to inject malicious JavaScript code.According to S…
According to a recent post from Sucuri, their website scanner detected an active distributed brute-force…WordPress Sites Exploited To Brute-Force Passwords Via…
Two security vulnerabilities have been discovered in Wordpress, a popular content management framework, a PHP File Upload bypass via the plugin installer and a…
A security vulnerability has been disclosed in the LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges.Tr…
A critical security flaw has been disclosed in a popular WordPress plugin called Ultimate Member that has more than 200,000 active installations.The vulnerabil…
A critical security flaw in the Bricks theme for WordPress is being actively exploited by threat actors to run arbitrary PHP code on susceptible installations.…
Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector.First documente…
Heads up, WordPress admins! Ensure updating your websites at the earliest as a severe remote…New WordPress Update Addressed A POP Chain RCE Vulnerability on La…
WordPress has released version 6.4.2 with a patch for a critical security flaw that could be exploited by threat actors by combining it with another bug to exe…
Cybersecurity researchers have shed light on a new sophisticated strain of malware that masquerades as a WordPress plugin to stealthily create administrator ac…
Thank you to Ruth Webb for contributing this article.WordPress stands tall as one of the most popular content management systems (CMS), empowering millions of …
The WordPress security plugin All-in-One Security (AIOS) silently logged users’ sign-in activities and passwords in…AIOS WordPress Plugin Found Logging Passwor…
Heads up, WordPress admins! Researchers have caught a zero-day vulnerability in the Ultimate Member WordPress…Ultimate Member Plugin Zero-Day Risks 200K+ WordP…
A critical security flaw has been disclosed in miniOrange'sSocial Login and Register pluginfor WordPress that could enable a malicious actor to log in as any u…
Several security vulnerabilities have been addressed in Wordpress, a popular content management framework. WordPress Core is vulnerable to Directory Traversal …
The popular and one of the most-used WordPress plugins, Jetpack recently addressed a critical security…Jetpack Plugin Patched A Critical Vulnerability Triggeri…
WordPress is one of the most popular content management systems in the world due to the ability it gives non-technical, inexperienced users to create professio…