#Wordfence
7 stories taggedWordfence.

WordPress plugin flaw is being used to plant hidden backdoors on shop sites
A file-upload bug in WooCommerce Wholesale Lead Capture lets attackers drop PHP webshells with no login required. Wordfence has blocked more than 100,000 attempts.

Hackers Fire 440,000 Attacks at Two Popular WordPress Plugins
Flaws in Super Forms and Elementor Pro let attackers upload files and run code on unpatched sites, with mass exploitation already underway.

Attackers Race to Exploit Elementor Pro Flaw, 190,000 Attempts Logged in Four Days
A file-upload bug in the popular WordPress plugin lets criminals plant a PHP backdoor and run commands on the server. Patch shipped August 19; attacks began the same day.

WordPress backup plugin hole leaves 3.25 million sites open to hijack
A flaw in All-in-One WP Migration and Backup lets unauthenticated attackers plant SQL that fires when an admin restores a backup, handing over full control of the site.

Critical Avada WordPress theme flaw lets attackers hijack sites with no clicks
A six-step bug chain in the popular Avada theme and Fusion Builder plugin, tracked as CVE-2026-18431, hands unauthenticated attackers full control of vulnerable WordPress sites.

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts
A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor
Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline, a clean supply-chain hit on WordPress installs.