Tag

#Wordfence

7 stories taggedWordfence.

An e-commerce website backend showing a file upload dialog box, with PHP webshell code visible in the editor beneath, and an alert badge showing blocked attack
Vulnerabilities

WordPress plugin flaw is being used to plant hidden backdoors on shop sites

A file-upload bug in WooCommerce Wholesale Lead Capture lets attackers drop PHP webshells with no login required. Wordfence has blocked more than 100,000 attempts.

4 min read
A web developer's laptop screen showing WordPress dashboard with security alerts and warnings flooding the notification panel, files being scanned by antivirus
Vulnerabilities

Hackers Fire 440,000 Attacks at Two Popular WordPress Plugins

Flaws in Super Forms and Elementor Pro let attackers upload files and run code on unpatched sites, with mass exploitation already underway.

4 min read
A hacker's workspace with multiple monitors showing file upload interfaces and server command lines, a PHP code snippet visible on one screen, malicious activit
Vulnerabilities

Attackers Race to Exploit Elementor Pro Flaw, 190,000 Attempts Logged in Four Days

A file-upload bug in the popular WordPress plugin lets criminals plant a PHP backdoor and run commands on the server. Patch shipped August 19; attacks began the same day.

4 min read
A WordPress admin dashboard with a backup restoration dialog box highlighted, surrounded by warning indicators and database server racks in the background
Vulnerabilities

WordPress backup plugin hole leaves 3.25 million sites open to hijack

A flaw in All-in-One WP Migration and Backup lets unauthenticated attackers plant SQL that fires when an admin restores a backup, handing over full control of the site.

4 min read
A WordPress dashboard displaying the Avada theme interface, with a security vulnerability warning overlay showing code injection and unauthorized access pathway
Vulnerabilities

Critical Avada WordPress theme flaw lets attackers hijack sites with no clicks

A six-step bug chain in the popular Avada theme and Fusion Builder plugin, tracked as CVE-2026-18431, hands unauthenticated attackers full control of vulnerable WordPress sites.

3 min read
A WordPress admin dashboard displaying installed plugins including Element Pack, a hidden admin account notification visible in a suspicious log entry, maliciou
Vulnerabilities

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts

A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

3 min read
Threat Intelligence

ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor

Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline, a clean supply-chain hit on WordPress installs.

2 min read
© 2026 Threat Vectr