Skip to main content
← All Articles

Tag

#WordPress

35 articles

Advertisement

HIGH
Threat Intel

Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets

Chinese-speaking threat actors targeted the Philippines Nuclear Agency and naval contractors, exploiting known vulnerabilities in ownCloud and WordPress.

Runtime Rebel Intel
3 min read · Sep 1, 2026
HIGH
Vulnerabilities

miniOrange SAML SSO Auth Bypass Exploited in WordPress Attacks

Hackers exploit two critical authentication bypasses in miniOrange SAML 2.0 Single Sign On WordPress plugin to gain admin access. Immediate patching is vital.

Runtime Rebel Intel
4 min read · Aug 25, 2026
CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw
CRITICAL
Vulnerabilities

CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw

A critical flaw, CVE-2026-32475, in Elementor Pro allows unauthenticated attackers to upload PHP files and execute code, affecting versions <= 4.2.1.

Runtime Rebel Intel
4 min read · Aug 20, 2026
MEDIUM
Supply Chain

BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins

A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.

Runtime Rebel Intel
5 min read · Aug 11, 2026
CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE
HIGH
Vulnerabilities

CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE

A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.

Runtime Rebel Intel
5 min read · Aug 7, 2026
CRITICAL
Vulnerabilities

CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now

CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.

Runtime Rebel Intel
4 min read · Aug 2, 2026

Advertisement

CRITICAL
Vulnerabilities

WordPress Core RCE via CVE-2026-63030 — wp2shell Mitigation Guide

Attackers are exploiting critical wp2shell vulnerabilities in WordPress Core to deploy persistent webshells. Learn how to detect and secure your servers.

Runtime Rebel Intel
3 min read · Jul 21, 2026
WP2Shell: WordPress RCE via Chained CVE-2026-60137 & CVE-2026-63030
CRITICAL
Vulnerabilities

WP2Shell: WordPress RCE via Chained CVE-2026-60137 & CVE-2026-63030

WP2Shell exploits CVE-2026-60137 and CVE-2026-63030 to achieve remote takeover on millions of WordPress sites. Immediate patching is critical.

Runtime Rebel Intel
5 min read · Jul 21, 2026
CRITICAL
Vulnerabilities

CVE-2026-63030: WordPress Core SQLi Leads to Unauth RCE

Critical SQL injection vulnerability (CVE-2026-63030) in WordPress Core enables unauthenticated remote code execution. Active exploitation confirmed.

Runtime Rebel Intel
4 min read · Jul 20, 2026
WordPress RCE and SonicWall Zero-Days: Weekly Threat Intel Update
CRITICAL
Threat Intel

WordPress RCE and SonicWall Zero-Days: Weekly Threat Intel Update

Active exploitation of WordPress RCE and SonicWall zero-day vulnerabilities highlights critical risks for internet-facing systems. Learn how to mitigate.

Runtime Rebel Intel
3 min read · Jul 20, 2026
HIGH
Vulnerabilities

WP2Shell Vulnerabilities CVE-2026-60137 & CVE-2026-63030 Exploited

WordPress sites face active exploitation via WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030. Learn the technical details and mitigation steps.

Runtime Rebel Intel
3 min read · Jul 20, 2026
HIGH
Vulnerabilities

WordPress wp2shell RCE: Public Exploits Released for Core Flaws

Public exploits for wp2shell RCE flaws in WordPress Core are now available. Learn how to detect, mitigate, and patch these critical vulnerabilities immediately.

Runtime Rebel Intel
3 min read · Jul 18, 2026
WordPress Core RCE wp2shell: Versions 6.9 and 7.0 Vulnerable
HIGH
Vulnerabilities

WordPress Core RCE wp2shell: Versions 6.9 and 7.0 Vulnerable

Unauthenticated attackers can achieve RCE on WordPress 6.9 and 7.0 core installations via the wp2shell flaw. Learn how to secure your site today.

Runtime Rebel Intel
4 min read · Jul 18, 2026
HIGH
Threat Intel

ACSC Warns of Global Campaign Targeting Vulnerable CMS Platforms

The ACSC warns of a global campaign targeting WordPress, Joomla, and Drupal. Learn how to identify web shells and secure your CMS against automated attacks.

Runtime Rebel Intel
4 min read · Jul 11, 2026
MEDIUM
Threat Intel

WordPress Formidable Forms Abused to Distribute Malicious PDF Files

Attackers are leveraging the WordPress Formidable Forms plugin to host malicious PDF documents, bypassing security filters to deliver phishing and malware.

Runtime Rebel Intel
4 min read · Jun 29, 2026
ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored
HIGH
Supply Chain

ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored

Attackers compromised ShapedPlugin's distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Jun 23, 2026
HIGH
Vulnerabilities

Gravity SMTP Flaw Exploited: WordPress Data Harvest & Remediation

Attackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin to exfiltrate sensitive data, including API keys and server info.

Runtime Rebel Intel
5 min read · Jun 22, 2026
CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys
MEDIUM
Vulnerabilities

CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys

Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.

Runtime Rebel Intel
3 min read · Jun 20, 2026
HIGH
Vulnerabilities

CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance

Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.

Runtime Rebel Intel
3 min read · Jun 20, 2026
HIGH
Supply Chain

OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks

Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.

Runtime Rebel Intel
4 min read · Jun 15, 2026
CRITICAL
Vulnerabilities

CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover

Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.

Runtime Rebel Intel
4 min read · Jun 6, 2026
HIGH
Vulnerabilities

WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities

Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.

Runtime Rebel Intel
3 min read · Jun 3, 2026
CRITICAL
Vulnerabilities

CVE-2026-8732: WP Maps Pro Admin Creation Vulnerability Exploited

Critical vulnerability [CVE-2026-8732] in WP Maps Pro allows unauthenticated attackers to create admin accounts, leading to WordPress site takeovers. Patch immediately.

Runtime Rebel Intel
4 min read · Jun 1, 2026
MEDIUM
Threat Intel

WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops

Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.

Runtime Rebel Intel
4 min read · Jun 1, 2026