Vulnerabilities Forminator WordPress Plugin Vulnerability Exposes 400,000 Websites to Takeover A vulnerability in the Forminator WordPress plugin allows attackers to delete arbitrary files and take over impacted websites. Ionut ArghireJuly 2, 2025
Vulnerabilities Second OttoKit Vulnerability Exploited to Hack WordPress Sites Threat actors are targeting a critical-severity vulnerability in the OttoKit WordPress plugin to gain administrative privileges. Ionut ArghireMay 7, 2025
Vulnerabilities Vulnerability in OttoKit WordPress Plugin Exploited in the Wild A vulnerability in the OttoKit WordPress plugin with over 100,000 active installations has been exploited in the wild. Ionut ArghireApril 11, 2025
Malware & Threats Threat Actors Deploy WordPress Malware in ‘mu-plugins’ Directory Sucuri has discovered multiple malware families deployed in the WordPress mu-plugins directory to evade routine security checks. Ionut ArghireMarch 31, 2025
Vulnerabilities Hunk Companion, WP Query Console Vulnerabilities Chained to Hack WordPress Sites Two vulnerabilities in the Hunk Companion and WP Query Console WordPress plugins allow attackers to backdoor websites. Ionut ArghireDecember 12, 2024
Vulnerabilities Critical Vulnerabilities Found in Anti-Spam Plugin Used by 200,000 WordPress Sites Two vulnerabilities in the Anti-Spam by CleanTalk WordPress plugin allowed attackers to execute arbitrary code remotely. Ionut ArghireNovember 26, 2024
Vulnerabilities Critical Plugin Flaw Exposed 4 Million WordPress Websites to Takeover Over 4 million WordPress websites were impacted by a critical Really Simple Security plugin vulnerability providing full administrative access. Ionut ArghireNovember 15, 2024
Vulnerabilities Critical Vulnerability Patched in 101 Releases of WordPress Plugin Jetpack Automattic has rolled out updates for 101 Jetpack versions released over the past eight years to resolve a critical vulnerability. Ionut ArghireOctober 15, 2024