Collected every two hours from specialised publications — each link leads to the original article.
Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector.First documente…
Heads up, WordPress admins! Ensure updating your websites at the earliest as a severe remote…New WordPress Update Addressed A POP Chain RCE Vulnerability on La…
WordPress has released version 6.4.2 with a patch for a critical security flaw that could be exploited by threat actors by combining it with another bug to exe…
Thank you to Ruth Webb for contributing this article.WordPress stands tall as one of the most popular content management systems (CMS), empowering millions of …
Heads up, WordPress admins! Researchers have caught a zero-day vulnerability in the Ultimate Member WordPress…Ultimate Member Plugin Zero-Day Risks 200K+ WordP…
A critical security flaw has been disclosed in miniOrange'sSocial Login and Register pluginfor WordPress that could enable a malicious actor to log in as any u…
Several security vulnerabilities have been addressed in Wordpress, a popular content management framework. WordPress Core is vulnerable to Directory Traversal …
The popular and one of the most-used WordPress plugins, Jetpack recently addressed a critical security…Jetpack Plugin Patched A Critical Vulnerability Triggeri…
WordPress is one of the most popular content management systems in the world due to the ability it gives non-technical, inexperienced users to create professio…
A security vulnerability has been disclosed in the popular WordPress pluginEssential Addons for Elementorthat could be potentially exploited to achieve elevate…
A security vulnerability has been disclosed in the popular WordPress pluginEssential Addons for Elementorthat could be potentially exploited to achieve elevate…
Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw.The issue, assigned the…
Researchers found active exploitation of the Eval PHP WordPress plugin to deploy backdoors on target…Hackers Abuse Outdated Eval PHP WordPress Plugin To Deploy…
Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware calledBalada Injectorsince 2017.The massive ca…
Unknown threat actors are actively exploiting a recently patched security vulnerability in the Elementor Pro website builder plugin for WordPress.The flaw, des…
A serious authentication vulnerability existed in the WordPress plugin WooCommerce Payments, exploiting which could allow…Critical Vulnerability Fixed In WooCo…
Researchers discovered multiple vulnerabilities in the LearnPress WordPress plugin, allowing SQL injection and file inclusion…LearnPress Plugin Vulnerabilities…
Heads up, WordPress admins! Researchers have warned users of a new Linux malware that targets…Linux Malware Exploits 30 Vulnerabilities To Target WordPress Web…
WordPress sites are being targeted by a previously unknown strain of Linux malware that exploits flaws in over two dozen plugins and themes to compromise vulne…
Several security vulnerabilities have been discovered in Wordpress, a popular content management framework. Possible SQL injection and cross-site scripting (XS…
Several security vulnerabilities were discovered in Wordpress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XS…
A zero-day vulnerability in the WPGateway WordPress plugin recently surfaced online following active exploits. The…Actively Exploited Zero-Day Vulnerability Fo…
Researchers discovered a severe blind SSRF vulnerability in WordPress that could allow DDoS attacks. Notably,…Six-Year-Old Blind SSRF Vulnerability Risks WordP…
A severe zero-day vulnerability in the Backup Buddy plugin has been revealed. The researchers detected…Zero-Day Vulnerability Found In WordPress Plugin Backup …