Skip to main content
← All Articles

Tag

#WordPress Security

8 articles

Advertisement

Operation Endgame Disrupts SocGholish: WordPress Site Remediation
HIGH
Malware

Operation Endgame Disrupts SocGholish: WordPress Site Remediation

Operation Endgame targets SocGholish infrastructure, cleaning 14,971 WordPress sites. Understand the impact and crucial remediation steps for web administrators.

Runtime Rebel Intel
5 min read · Jun 19, 2026
CVE-2026-3300: Critical RCE in Everest Forms Pro — Patch Now
CRITICAL
Vulnerabilities

CVE-2026-3300: Critical RCE in Everest Forms Pro — Patch Now

Attackers are exploiting CVE-2026-3300 in Everest Forms Pro up to 1.9.12 to achieve RCE. Learn how to protect your WordPress site from full compromise.

Runtime Rebel Intel
3 min read · Jun 5, 2026
HIGH
Threat Intel

DriveSurge Campaigns: Detecting ClickFix and FakeUpdate Overlays

DriveSurge threat actors have hijacked thousands of sites to deploy ClickFix and FakeUpdate overlays, delivering info-stealers via deceptive browser alerts.

Runtime Rebel Intel
3 min read · Jun 2, 2026
WP Maps Pro Flaw Exploited for Admin Account Creation — Patch Now
CRITICAL
Vulnerabilities

WP Maps Pro Flaw Exploited for Admin Account Creation — Patch Now

Attackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on affected sites.

Runtime Rebel Intel
3 min read · Jun 1, 2026
HIGH
Vulnerabilities

CVE-2024-2123 & CVE-2024-2510: Avada Builder Patch Guidance

Critical flaws in Avada Builder WordPress plugin (CVE-2024-2123, CVE-2024-2510) allow for credential theft and LFI. Immediate update to version 3.11.7 required.

Runtime Rebel Intel
3 min read · May 15, 2026
HIGH
Threat Intel

Google Ads Phishing Campaign Targets GoDaddy ManageWP Users

A persistent phishing campaign leverages malicious Google Ads to steal GoDaddy ManageWP credentials, risking extensive WordPress site compromises.

Runtime Rebel Intel
4 min read · May 7, 2026

Advertisement

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack
HIGH
Supply Chain

Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack

Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.

Runtime Rebel Intel
3 min read · Apr 10, 2026
HIGH
Vulnerabilities

CVE-2023-3800: RCE Vulnerability in Ninja Forms File Uploads Extension

Attackers are exploiting a critical unauthenticated file upload flaw in Ninja Forms File Uploads. Secure your WordPress site and mitigate RCE risks immediately.

Runtime Rebel Intel
3 min read · Apr 8, 2026