Vulnerabilities Critical WordPress Vulnerability Exploited Immediately After Disclosure Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. Ionut Arghire3 days ago
Vulnerabilities WordPress Patches ‘Click2Shell’ Vulnerability The bug lets attackers automatically install and preview themes and could lead to remote code execution. Ionut Arghire5 days ago
Malware & Threats Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. Ionut ArghireSeptember 18, 2026
Vulnerabilities Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. Ionut ArghireSeptember 16, 2026
Application Security Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. Ionut ArghireSeptember 5, 2026
Vulnerabilities Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. Ionut ArghireSeptember 3, 2026
Vulnerabilities WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. Eduard KovacsAugust 25, 2026
Vulnerabilities 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. Ionut ArghireAugust 18, 2026
Vulnerabilities WordPress 7.0.4 Patches Remote Code Execution Vulnerability Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. Ionut ArghireAugust 13, 2026
Vulnerabilities WP2Shell WordPress Vulnerabilities Exploited in the Wild Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. Eduard KovacsJuly 20, 2026
Vulnerabilities Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data. Ionut ArghireJune 22, 2026
Malware & Threats 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. Ionut ArghireJune 19, 2026
Vulnerabilities Everest Forms Vulnerability Exploited to Hack WordPress Sites The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. Ionut ArghireJune 8, 2026
Vulnerabilities Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. Ionut ArghireJune 3, 2026
Vulnerabilities Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover The vulnerability allows hackers to upload arbitrary files to a site’s server and achieve remote code execution. Ionut ArghireApril 8, 2026
Vulnerabilities Ally WordPress Plugin Flaw Exposes Over 200,000 Websites to Attacks The issue allows attackers to inject SQL queries and extract sensitive information from the database. Ionut ArghireMarch 12, 2026
Vulnerabilities Critical King Addons Vulnerability Exploited to Hack WordPress Sites A critical-severity vulnerability in the King Addons for Elementor plugin for WordPress has been exploited to take over websites. Ionut ArghireDecember 3, 2025
Vulnerabilities Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover The critical vulnerability allows attackers to read arbitrary emails, including password reset messages. Ionut ArghireNovember 5, 2025
Vulnerabilities Year-Old WordPress Plugin Flaws Exploited to Hack Websites Roughly 9 million exploit attempts were observed this month as mass exploitation of the critical vulnerabilities recommenced. Ionut ArghireOctober 27, 2025
Vulnerabilities Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations The Post SMTP email delivery WordPress plugin is affected by a critical vulnerability and half of websites using it remain unpatched. Eduard KovacsJuly 28, 2025