#WordPress
23 stories taggedWordPress.

Elementor Pro flaw let attackers plant executable files on WordPress sites
A bug in the paid version of the popular WordPress builder let strangers upload PHP files and run code on the server. A patch is out.

Nearly 2,000 Hacked WordPress Sites Turned Into a Criminal Toolkit
A sprawling operation dubbed StopAndProtect is quietly using compromised WordPress sites as a delivery network for malware, stolen files and screenshots.

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected
A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of thousands of WordPress sites at risk of full takeover.

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts
A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It
A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

Hackers Race to Break Into WordPress Sites Through 'wp2shell' Flaws
Two critical bugs in WordPress core let attackers install backdoors without a password. Automatic updates are out, but roughly one in five sites is still exposed.

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password
The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In
Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.

A Week When Small Inputs Caused Big Damage
WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw defined a punishing seven days for defenders.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

A WordPress Bug Lets Strangers Run Code on Your Site. No Login Required.
Every WordPress 6.9 and 7.0 site was exposed until a Friday emergency patch. The fix is being force-installed.

Intruder's AI 'vulnerability vending machine' finds a WordPress zero-day on its own
A security firm wired large language models into code-analysis tools and produced a working exploit for an unknown plugin flaw. It says more disclosures are on the way.

Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

Cybercrime Crew Leaves Its Own Server Wide Open, Exposing 1.4 Million Website Target List
A misconfigured server ran unprotected for three weeks, handing researchers a rare look inside a mass WordPress hacking operation now tracked as WP-SHELLSTORM.