Collected every two hours from specialised publications — each link leads to the original article.
A security vulnerability has been disclosed in the popular WordPress pluginEssential Addons for Elementorthat could be potentially exploited to achieve elevate…
A security vulnerability has been disclosed in the popular WordPress pluginEssential Addons for Elementorthat could be potentially exploited to achieve elevate…
Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw.The issue, assigned the…
Researchers found active exploitation of the Eval PHP WordPress plugin to deploy backdoors on target…Hackers Abuse Outdated Eval PHP WordPress Plugin To Deploy…
Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware calledBalada Injectorsince 2017.The massive ca…
Unknown threat actors are actively exploiting a recently patched security vulnerability in the Elementor Pro website builder plugin for WordPress.The flaw, des…
A serious authentication vulnerability existed in the WordPress plugin WooCommerce Payments, exploiting which could allow…Critical Vulnerability Fixed In WooCo…
Researchers discovered multiple vulnerabilities in the LearnPress WordPress plugin, allowing SQL injection and file inclusion…LearnPress Plugin Vulnerabilities…
Heads up, WordPress admins! Researchers have warned users of a new Linux malware that targets…Linux Malware Exploits 30 Vulnerabilities To Target WordPress Web…
WordPress sites are being targeted by a previously unknown strain of Linux malware that exploits flaws in over two dozen plugins and themes to compromise vulne…
The wordpress package released in DSA-5279-1 had incorrect dependencies that could not be satisfied in Debian stable: this update corrects the problem. For ref…
Several security vulnerabilities have been discovered in Wordpress, a popular content management framework. Possible SQL injection and cross-site scripting (XS…
Several security vulnerabilities were discovered in Wordpress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XS…
**Wordpress 5.9.4 Security Release**
[WordPress 6.0.2 Security and Maintenance Release](https://wordpress.org/news/2022/08/wordpress-6-0-2-security-and- maintenance-release/)
A zero-day vulnerability in the WPGateway WordPress plugin recently surfaced online following active exploits. The…Actively Exploited Zero-Day Vulnerability Fo…
Researchers discovered a severe blind SSRF vulnerability in WordPress that could allow DDoS attacks. Notably,…Six-Year-Old Blind SSRF Vulnerability Risks WordP…
A severe zero-day vulnerability in the Backup Buddy plugin has been revealed. The researchers detected…Zero-Day Vulnerability Found In WordPress Plugin Backup …
Researchers from Wordfence havesoundedthe alarm about a "sudden" spike in cyber attacks attempting to exploit an unpatched flaw in a WordPress plugin calledKas…
A security researcher has shared two CSP bypass scenarios affecting WordPress websites. Both methods involve…Researcher Discloses A WordPress CSP Bypass Public…
Researchers discovered multiple security vulnerabilities in the Jupiter WordPress theme. While vendors have patched the…Multiple Vulnerabilities Found In Jupit…
Several vulnerabilities like Prototype Pollution Vulnerability in a jQuery dependency and in the block editor, and Stored Cross Site Scripting Vulnerability we…
WordPress 5.9.2 Security & Maintenance Release
WordPress 5.8.4 Security Release