Advertisement
Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets
Chinese-speaking threat actors targeted the Philippines Nuclear Agency and naval contractors, exploiting known vulnerabilities in ownCloud and WordPress.
miniOrange SAML SSO Auth Bypass Exploited in WordPress Attacks
Hackers exploit two critical authentication bypasses in miniOrange SAML 2.0 Single Sign On WordPress plugin to gain admin access. Immediate patching is vital.
CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw
A critical flaw, CVE-2026-32475, in Elementor Pro allows unauthenticated attackers to upload PHP files and execute code, affecting versions <= 4.2.1.
BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins
A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.
CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE
A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.
CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now
CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.
Advertisement
WordPress Core RCE via CVE-2026-63030 — wp2shell Mitigation Guide
Attackers are exploiting critical wp2shell vulnerabilities in WordPress Core to deploy persistent webshells. Learn how to detect and secure your servers.
WP2Shell: WordPress RCE via Chained CVE-2026-60137 & CVE-2026-63030
WP2Shell exploits CVE-2026-60137 and CVE-2026-63030 to achieve remote takeover on millions of WordPress sites. Immediate patching is critical.
CVE-2026-63030: WordPress Core SQLi Leads to Unauth RCE
Critical SQL injection vulnerability (CVE-2026-63030) in WordPress Core enables unauthenticated remote code execution. Active exploitation confirmed.
WordPress RCE and SonicWall Zero-Days: Weekly Threat Intel Update
Active exploitation of WordPress RCE and SonicWall zero-day vulnerabilities highlights critical risks for internet-facing systems. Learn how to mitigate.
WP2Shell Vulnerabilities CVE-2026-60137 & CVE-2026-63030 Exploited
WordPress sites face active exploitation via WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030. Learn the technical details and mitigation steps.
WordPress wp2shell RCE: Public Exploits Released for Core Flaws
Public exploits for wp2shell RCE flaws in WordPress Core are now available. Learn how to detect, mitigate, and patch these critical vulnerabilities immediately.
WordPress Core RCE wp2shell: Versions 6.9 and 7.0 Vulnerable
Unauthenticated attackers can achieve RCE on WordPress 6.9 and 7.0 core installations via the wp2shell flaw. Learn how to secure your site today.
ACSC Warns of Global Campaign Targeting Vulnerable CMS Platforms
The ACSC warns of a global campaign targeting WordPress, Joomla, and Drupal. Learn how to identify web shells and secure your CMS against automated attacks.
WordPress Formidable Forms Abused to Distribute Malicious PDF Files
Attackers are leveraging the WordPress Formidable Forms plugin to host malicious PDF documents, bypassing security filters to deliver phishing and malware.
ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored
Attackers compromised ShapedPlugin's distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.
Gravity SMTP Flaw Exploited: WordPress Data Harvest & Remediation
Attackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin to exfiltrate sensitive data, including API keys and server info.
CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys
Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.
CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance
Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.
OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks
Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.
CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover
Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.
WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities
Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.
CVE-2026-8732: WP Maps Pro Admin Creation Vulnerability Exploited
Critical vulnerability [CVE-2026-8732] in WP Maps Pro allows unauthenticated attackers to create admin accounts, leading to WordPress site takeovers. Patch immediately.
WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops
Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.