<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #WordPress</title><description>Cybersecurity articles tagged #WordPress on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Chinese-Speaking Operators Target Philippine Nuclear and Naval Assets</title><link>https://runtimerebel.com/blog/chinese-speaking-operators-target-philippine-nuclear-and-naval-assets</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-speaking-operators-target-philippine-nuclear-and-naval-assets</guid><description>Chinese-speaking threat actors targeted the Philippines Nuclear Agency and naval contractors, exploiting known vulnerabilities in ownCloud and WordPress.</description><pubDate>Tue, 01 Sep 2026 02:44:13 GMT</pubDate><category>ownCloud</category><category>WordPress</category><category>WebDAV</category><category>Credential Theft</category><category>Military Intelligence</category></item><item><title>miniOrange SAML SSO Auth Bypass Exploited in WordPress Attacks</title><link>https://runtimerebel.com/blog/miniorange-saml-sso-auth-bypass-exploited-in-wordpress-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/miniorange-saml-sso-auth-bypass-exploited-in-wordpress-attacks</guid><description>Hackers exploit two critical authentication bypasses in miniOrange SAML 2.0 Single Sign On WordPress plugin to gain admin access. Immediate patching is vital.</description><pubDate>Tue, 25 Aug 2026 08:31:42 GMT</pubDate><category>WordPress</category><category>Authentication Bypass</category><category>miniOrange</category><category>SAML</category><category>CVE-2026-61979</category></item><item><title>CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw</title><link>https://runtimerebel.com/blog/cve-2026-32475-elementor-pro-unauthenticated-rce-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-32475-elementor-pro-unauthenticated-rce-flaw</guid><description>A critical flaw, CVE-2026-32475, in Elementor Pro allows unauthenticated attackers to upload PHP files and execute code, affecting versions &lt;= 4.2.1.</description><pubDate>Thu, 20 Aug 2026 08:26:43 GMT</pubDate><category>WordPress</category><category>Remote Code Execution</category><category>CVE-2026-32475</category><category>Elementor Pro</category><category>File Upload Vulnerability</category></item><item><title>BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins</title><link>https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</link><guid isPermaLink="true">https://runtimerebel.com/blog/bdthemes-wordpress-plugin-supply-chain-attack-creates-rogue-admins</guid><description>A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.</description><pubDate>Tue, 11 Aug 2026 08:45:01 GMT</pubDate><category>WordPress</category><category>Supply Chain Attack</category><category>XSS</category><category>Webshell</category><category>BdThemes</category></item><item><title>CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE</title><link>https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</guid><description>A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.</description><pubDate>Fri, 07 Aug 2026 16:42:22 GMT</pubDate><category>WordPress</category><category>XSS</category><category>RCE</category><category>Web Security</category><category>CVE-2026-64638</category></item><item><title>CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</guid><description>CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.</description><pubDate>Sun, 02 Aug 2026 02:55:48 GMT</pubDate><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>CISA KEV</category><category>CVE-2026-60137</category></item><item><title>WordPress Core RCE via CVE-2026-63030 — wp2shell Mitigation Guide</title><link>https://runtimerebel.com/blog/wordpress-core-rce-via-cve-2026-63030-wp2shell-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-core-rce-via-cve-2026-63030-wp2shell-mitigation-guide</guid><description>Attackers are exploiting critical wp2shell vulnerabilities in WordPress Core to deploy persistent webshells. Learn how to detect and secure your servers.</description><pubDate>Tue, 21 Jul 2026 17:23:43 GMT</pubDate><category>CVE-2026-63030</category><category>CVE-2026-60137</category><category>WordPress</category><category>Webshell</category><category>Wp2shell</category></item><item><title>WP2Shell: WordPress RCE via Chained CVE-2026-60137 &amp; CVE-2026-63030</title><link>https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</guid><description>WP2Shell exploits CVE-2026-60137 and CVE-2026-63030 to achieve remote takeover on millions of WordPress sites. Immediate patching is critical.</description><pubDate>Tue, 21 Jul 2026 02:54:17 GMT</pubDate><category>Wp2shell</category><category>WordPress</category><category>RCE</category><category>CVE-2026-60137</category><category>CVE-2026-63030</category><category>Web Security</category></item><item><title>CVE-2026-63030: WordPress Core SQLi Leads to Unauth RCE</title><link>https://runtimerebel.com/blog/cve-2026-63030-wordpress-core-sqli-leads-to-unauth-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63030-wordpress-core-sqli-leads-to-unauth-rce</guid><description>Critical SQL injection vulnerability (CVE-2026-63030) in WordPress Core enables unauthenticated remote code execution. Active exploitation confirmed.</description><pubDate>Mon, 20 Jul 2026 21:15:06 GMT</pubDate><category>CVE-2026-63030</category><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>Wp2shell</category></item><item><title>WordPress RCE and SonicWall Zero-Days: Weekly Threat Intel Update</title><link>https://runtimerebel.com/blog/wordpress-rce-and-sonicwall-zero-days-weekly-threat-intel-update</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-rce-and-sonicwall-zero-days-weekly-threat-intel-update</guid><description>Active exploitation of WordPress RCE and SonicWall zero-day vulnerabilities highlights critical risks for internet-facing systems. Learn how to mitigate.</description><pubDate>Mon, 20 Jul 2026 14:11:23 GMT</pubDate><category>WordPress</category><category>SonicWall</category><category>SharePoint</category><category>RCE</category><category>Zero-Day</category></item><item><title>WP2Shell Vulnerabilities CVE-2026-60137 &amp; CVE-2026-63030 Exploited</title><link>https://runtimerebel.com/blog/wp2shell-vulnerabilities-cve-2026-60137-cve-2026-63030-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp2shell-vulnerabilities-cve-2026-60137-cve-2026-63030-exploited</guid><description>WordPress sites face active exploitation via WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030. Learn the technical details and mitigation steps.</description><pubDate>Mon, 20 Jul 2026 06:49:53 GMT</pubDate><category>Wp2shell</category><category>WordPress</category><category>CVE-2026-60137</category><category>CVE-2026-63030</category><category>RCE</category><category>Active Exploitation</category></item><item><title>WordPress wp2shell RCE: Public Exploits Released for Core Flaws</title><link>https://runtimerebel.com/blog/wordpress-wp2shell-rce-public-exploits-released-for-core-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-wp2shell-rce-public-exploits-released-for-core-flaws</guid><description>Public exploits for wp2shell RCE flaws in WordPress Core are now available. Learn how to detect, mitigate, and patch these critical vulnerabilities immediately.</description><pubDate>Sat, 18 Jul 2026 20:51:39 GMT</pubDate><category>WordPress</category><category>RCE</category><category>Wp2shell</category><category>Exploit Available</category><category>Patching</category></item><item><title>WordPress Core RCE wp2shell: Versions 6.9 and 7.0 Vulnerable</title><link>https://runtimerebel.com/blog/wordpress-core-rce-wp2shell-versions-6-9-and-7-0-vulnerable</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-core-rce-wp2shell-versions-6-9-and-7-0-vulnerable</guid><description>Unauthenticated attackers can achieve RCE on WordPress 6.9 and 7.0 core installations via the wp2shell flaw. Learn how to secure your site today.</description><pubDate>Sat, 18 Jul 2026 02:36:35 GMT</pubDate><category>WordPress</category><category>Wp2shell</category><category>RCE</category><category>Assetnote</category><category>Core Vulnerability</category></item><item><title>ACSC Warns of Global Campaign Targeting Vulnerable CMS Platforms</title><link>https://runtimerebel.com/blog/acsc-warns-of-global-campaign-targeting-vulnerable-cms-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/acsc-warns-of-global-campaign-targeting-vulnerable-cms-platforms</guid><description>The ACSC warns of a global campaign targeting WordPress, Joomla, and Drupal. Learn how to identify web shells and secure your CMS against automated attacks.</description><pubDate>Sat, 11 Jul 2026 16:59:48 GMT</pubDate><category>CMS</category><category>WordPress</category><category>Joomla</category><category>Drupal</category><category>Web Shells</category><category>ACSC</category></item><item><title>WordPress Formidable Forms Abused to Distribute Malicious PDF Files</title><link>https://runtimerebel.com/blog/wordpress-formidable-forms-abused-to-distribute-malicious-pdf-files</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-formidable-forms-abused-to-distribute-malicious-pdf-files</guid><description>Attackers are leveraging the WordPress Formidable Forms plugin to host malicious PDF documents, bypassing security filters to deliver phishing and malware.</description><pubDate>Mon, 29 Jun 2026 05:42:25 GMT</pubDate><category>WordPress</category><category>Formidable Forms</category><category>Phishing</category><category>PDF Analysis</category><category>Threat Intelligence</category></item><item><title>ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored</title><link>https://runtimerebel.com/blog/shapedplugin-supply-chain-attack-wordpress-pro-plugins-backdoored</link><guid isPermaLink="true">https://runtimerebel.com/blog/shapedplugin-supply-chain-attack-wordpress-pro-plugins-backdoored</guid><description>Attackers compromised ShapedPlugin&apos;s distribution pipeline to inject backdoors into Pro WordPress plugins. Learn how to detect and remediate this supply chain threat.</description><pubDate>Tue, 23 Jun 2026 00:57:15 GMT</pubDate><category>ShapedPlugin</category><category>WordPress</category><category>Supply Chain Attack</category><category>Backdoor</category><category>Wordfence</category></item><item><title>Gravity SMTP Flaw Exploited: WordPress Data Harvest &amp; Remediation</title><link>https://runtimerebel.com/blog/gravity-smtp-flaw-exploited-wordpress-data-harvest-remediation</link><guid isPermaLink="true">https://runtimerebel.com/blog/gravity-smtp-flaw-exploited-wordpress-data-harvest-remediation</guid><description>Attackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin to exfiltrate sensitive data, including API keys and server info.</description><pubDate>Mon, 22 Jun 2026 17:38:41 GMT</pubDate><category>Gravity SMTP</category><category>WordPress</category><category>Plugin Vulnerability</category><category>Data Harvesting</category><category>API Keys</category></item><item><title>CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys</title><link>https://runtimerebel.com/blog/cve-2026-4020-gravity-smtp-exploit-exposes-wordpress-api-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-4020-gravity-smtp-exploit-exposes-wordpress-api-keys</guid><description>Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.</description><pubDate>Sat, 20 Jun 2026 12:44:14 GMT</pubDate><category>CVE-2026-4020</category><category>WordPress</category><category>Gravity SMTP</category><category>Information Disclosure</category></item><item><title>CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance</title><link>https://runtimerebel.com/blog/cve-2024-49403-gravity-smtp-information-disclosure-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-49403-gravity-smtp-information-disclosure-patch-guidance</guid><description>Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.</description><pubDate>Sat, 20 Jun 2026 05:36:09 GMT</pubDate><category>CVE-2024-49403</category><category>Gravity SMTP</category><category>WordPress</category><category>Information Disclosure</category></item><item><title>OptinMonster 2.6.5 Update: Managing CDN Supply Chain Attack Risks</title><link>https://runtimerebel.com/blog/optinmonster-2-6-5-update-managing-cdn-supply-chain-attack-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/optinmonster-2-6-5-update-managing-cdn-supply-chain-attack-risks</guid><description>Learn how the OptinMonster CDN supply chain attack compromised over 1 million WordPress sites and how to mitigate the risk of malicious script injection.</description><pubDate>Mon, 15 Jun 2026 17:46:01 GMT</pubDate><category>OptinMonster</category><category>WordPress</category><category>CVE-2021-39341</category><category>Supply Chain Attack</category><category>JavaScript Injection</category></item><item><title>CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover</title><link>https://runtimerebel.com/blog/cve-2024-3300-critical-everest-forms-pro-bypass-leads-to-site-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-3300-critical-everest-forms-pro-bypass-leads-to-site-takeover</guid><description>Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.</description><pubDate>Sat, 06 Jun 2026 16:30:32 GMT</pubDate><category>CVE-2024-3300</category><category>Everest Forms Pro</category><category>WordPress</category><category>Authentication Bypass</category></item><item><title>WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities</title><link>https://runtimerebel.com/blog/wordpress-sites-targeted-via-kirki-and-burst-statistics-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-sites-targeted-via-kirki-and-burst-statistics-vulnerabilities</guid><description>Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.</description><pubDate>Wed, 03 Jun 2026 13:48:48 GMT</pubDate><category>CVE-2024-11884</category><category>CVE-2024-11046</category><category>WordPress</category><category>Kirki</category><category>Burst Statistics</category><category>XSS</category><category>Privilege Escalation</category></item><item><title>CVE-2026-8732: WP Maps Pro Admin Creation Vulnerability Exploited</title><link>https://runtimerebel.com/blog/cve-2026-8732-wp-maps-pro-admin-creation-vulnerability-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-8732-wp-maps-pro-admin-creation-vulnerability-exploited</guid><description>Critical vulnerability [CVE-2026-8732] in WP Maps Pro allows unauthenticated attackers to create admin accounts, leading to WordPress site takeovers. Patch immediately.</description><pubDate>Mon, 01 Jun 2026 21:15:33 GMT</pubDate><category>CVE-2026-8732</category><category>WP Maps Pro</category><category>WordPress</category><category>Plugin Vulnerability</category><category>Site Takeover</category><category>Authentication Bypass</category></item><item><title>WordPress Sites Targeted by Malware Using Steam Profile Dead-Drops</title><link>https://runtimerebel.com/blog/wordpress-sites-targeted-by-malware-using-steam-profile-dead-drops</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-sites-targeted-by-malware-using-steam-profile-dead-drops</guid><description>Over 2,000 WordPress sites compromised in a campaign hiding C2 resolution data within Steam Community profiles. Technical breakdown of the evasion tactics.</description><pubDate>Mon, 01 Jun 2026 18:06:43 GMT</pubDate><category>WordPress</category><category>Steam Community</category><category>C2 Evasion</category><category>Steganography</category><category>Malware Analysis</category></item><item><title>CVE-2024-10642: WP Maps Pro Exploited to Create WordPress Admin Accounts</title><link>https://runtimerebel.com/blog/cve-2024-10642-wp-maps-pro-exploited-to-create-wordpress-admin-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-10642-wp-maps-pro-exploited-to-create-wordpress-admin-accounts</guid><description>Attackers are exploiting a critical privilege escalation flaw in the WP Maps Pro WordPress plugin to create rogue admin accounts without authentication.</description><pubDate>Sun, 31 May 2026 16:31:35 GMT</pubDate><category>CVE-2024-10642</category><category>WordPress</category><category>WP Maps Pro</category><category>Privilege Escalation</category><category>Active Exploitation</category></item><item><title>Funnel Builder Plugin Exploited for WooCommerce Checkout Skimming</title><link>https://runtimerebel.com/blog/funnel-builder-plugin-exploited-for-woocommerce-checkout-skimming</link><guid isPermaLink="true">https://runtimerebel.com/blog/funnel-builder-plugin-exploited-for-woocommerce-checkout-skimming</guid><description>Attackers are exploiting a vulnerability in the Funnel Builder WordPress plugin to inject skimming scripts and steal payment data from WooCommerce sites.</description><pubDate>Sat, 16 May 2026 20:20:35 GMT</pubDate><category>WordPress</category><category>WooCommerce</category><category>Funnel Builder</category><category>Magecart</category><category>Skimming</category></item><item><title>Funnel Builder WordPress Plugin Exploited for Credit Card Skimming</title><link>https://runtimerebel.com/blog/funnel-builder-wordpress-plugin-exploited-for-credit-card-skimming</link><guid isPermaLink="true">https://runtimerebel.com/blog/funnel-builder-wordpress-plugin-exploited-for-credit-card-skimming</guid><description>Critical vulnerability in Funnel Builder WordPress plugin actively exploited to inject credit card skimming JavaScript into WooCommerce checkout pages.</description><pubDate>Fri, 15 May 2026 20:31:22 GMT</pubDate><category>WordPress</category><category>Funnel Builder</category><category>WooCommerce</category><category>E Commerce</category><category>Credit Card Skimming</category><category>JavaScript Injection</category><category>Web Skimming</category></item><item><title>CVE-2024-7109: Burst Statistics WordPress Plugin Auth Bypass Exploited</title><link>https://runtimerebel.com/blog/cve-2024-7109-burst-statistics-wordpress-plugin-auth-bypass-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-7109-burst-statistics-wordpress-plugin-auth-bypass-exploited</guid><description>Hackers are actively exploiting CVE-2024-7109, a critical authentication bypass in Burst Statistics WordPress plugin, to gain admin access. Patch immediately.</description><pubDate>Fri, 15 May 2026 00:52:51 GMT</pubDate><category>Burst Statistics</category><category>WordPress</category><category>Authentication Bypass</category><category>Plugin Vulnerability</category><category>Web Security</category><category>CVE-2024-7109</category></item><item><title>WordPress Quick Page/Post Redirect Backdoor: Arbitrary Code Injection</title><link>https://runtimerebel.com/blog/wordpress-quick-page-post-redirect-backdoor-arbitrary-code-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-quick-page-post-redirect-backdoor-arbitrary-code-injection</guid><description>A dormant backdoor in the Quick Page/Post Redirect WordPress plugin allowed arbitrary code injection for five years on over 70,000 sites. Learn mitigation.</description><pubDate>Thu, 30 Apr 2026 00:51:16 GMT</pubDate><category>WordPress</category><category>Quick Page Post Redirect</category><category>Backdoor</category><category>Code Injection</category><category>Supply Chain</category><category>Plugin Vulnerability</category></item><item><title>CVE-2024-52317: Critical File Upload Bug in Breeze Cache — Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-52317-critical-file-upload-bug-in-breeze-cache-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-52317-critical-file-upload-bug-in-breeze-cache-patch-now</guid><description>Attackers are actively exploiting a critical unauthenticated file upload vulnerability (CVE-2024-52317) in the Breeze Cache WordPress plugin.</description><pubDate>Fri, 24 Apr 2026 00:46:36 GMT</pubDate><category>CVE-2024-52317</category><category>WordPress</category><category>Breeze Cache</category><category>RCE</category></item><item><title>Critical RCE Threats: Confluence OGNL &amp; Exchange Server Patching</title><link>https://runtimerebel.com/blog/critical-rce-threats-confluence-ognl-exchange-server-patching</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rce-threats-confluence-ognl-exchange-server-patching</guid><description>Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.</description><pubDate>Thu, 23 Apr 2026 05:06:17 GMT</pubDate><category>Atlassian Confluence</category><category>OGNL Injection</category><category>RCE</category><category>Microsoft Exchange Server</category><category>Patch Tuesday</category><category>WordPress</category><category>WP Reset</category><category>SQL Injection</category><category>Vulnerability</category></item><item><title>Ninja Forms RCE via Arbitrary File Upload: Mitigation Guide</title><link>https://runtimerebel.com/blog/ninja-forms-rce-via-arbitrary-file-upload-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ninja-forms-rce-via-arbitrary-file-upload-mitigation-guide</guid><description>Hackers are actively exploiting a critical Ninja Forms vulnerability to upload arbitrary files and achieve RCE. Learn how to secure your WordPress site now.</description><pubDate>Wed, 08 Apr 2026 12:28:42 GMT</pubDate><category>WordPress</category><category>Ninja Forms</category><category>Remote Code Execution</category><category>Active Exploitation</category><category>File Upload</category></item><item><title>Smart Slider 3 Vulnerability: Patch CVE-2024-11116 File Read Flaw</title><link>https://runtimerebel.com/blog/smart-slider-3-vulnerability-patch-cve-2024-11116-file-read-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/smart-slider-3-vulnerability-patch-cve-2024-11116-file-read-flaw</guid><description>A file read vulnerability in Smart Slider 3 affects over 800,000 WordPress sites. Authenticated users can access sensitive server files via CVE-2024-11116.</description><pubDate>Sun, 29 Mar 2026 16:13:24 GMT</pubDate><category>CVE-2024-11116</category><category>WordPress</category><category>Smart Slider 3</category><category>LFI</category><category>Local File Inclusion</category></item><item><title>Elementor Ally Plugin SQLi: Unauthenticated Data Theft Risk</title><link>https://runtimerebel.com/blog/elementor-ally-plugin-sqli-unauthenticated-data-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/elementor-ally-plugin-sqli-unauthenticated-data-theft-risk</guid><description>An unauthenticated SQL injection vulnerability in the Elementor Ally WordPress plugin affects over 400,000 sites, risking sensitive data exposure.</description><pubDate>Wed, 11 Mar 2026 20:13:50 GMT</pubDate><category>SQL Injection</category><category>WordPress</category><category>Elementor Ally</category><category>Web Accessibility</category><category>Data Theft</category></item><item><title>WordPress User Registration &amp; Membership Plugin: Admin Account Exploit</title><link>https://runtimerebel.com/blog/wordpress-user-registration-membership-plugin-admin-account-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-user-registration-membership-plugin-admin-account-exploit</guid><description>Critical vulnerability in WordPress User Registration &amp; Membership plugin actively exploited to create unauthorized admin accounts.</description><pubDate>Thu, 05 Mar 2026 20:16:17 GMT</pubDate><category>WordPress</category><category>User Registration Membership</category><category>Plugin Vulnerability</category><category>Admin Account Creation</category><category>Website Security</category><category>Privilege Escalation</category></item></channel></rss>