Tag

#WordPress

23 stories taggedWordPress.

A close-up, macro, photoreal, news-editorial shot of a tangled cluster of worn ethernet and USB cables plugged into a dusty server strip, bathed in the cool blu
Vulnerabilities

Elementor Pro flaw let attackers plant executable files on WordPress sites

A bug in the paid version of the popular WordPress builder let strangers upload PHP files and run code on the server. A patch is out.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a sleek modern desk with a glowing dark monitor showing abstract code patterns and a subtle subscription-styl
Threat Intelligence

Nearly 2,000 Hacked WordPress Sites Turned Into a Criminal Toolkit

A sprawling operation dubbed StopAndProtect is quietly using compromised WordPress sites as a delivery network for malware, stolen files and screenshots.

3 min read
Photoreal news-editorial overhead shot of a darkened security operations center desk, multiple monitors glowing blue with abstract vulnerability dashboards and
Vulnerabilities

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected

A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of thousands of WordPress sites at risk of full takeover.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room aisle at night, rows of humming rack-mounted servers with soft blue and amber
Vulnerabilities

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts

A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

4 min read
Photoreal editorial shot of a laptop screen glowing in a dim office, showing a generic webmail inbox interface with one email highlighted, faint reflection of c
Vulnerabilities

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It

A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server room with a single rack bathed in blue and red light, a laptop open on a nearby cart sho
Vulnerabilities

Hackers Race to Break Into WordPress Sites Through 'wp2shell' Flaws

Two critical bugs in WordPress core let attackers install backdoors without a password. Automatic updates are out, but roughly one in five sites is still exposed.

4 min read
Full-frame photoreal editorial shot of a darkened server room with a single glowing amber warning light reflected on rows of rack-mounted hardware, faint blue s
Vulnerabilities

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password

The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

3 min read
A close-up, macro, photoreal, news-editorial shot of a tangled cluster of worn ethernet and USB cables plugged into a dusty server strip, bathed in the cool blu
Vulnerabilities

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In

Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with rows of blue-lit rack equipment, one open rack door revealing exposed cabling, warm amber w
Threat Intelligence

A Week When Small Inputs Caused Big Damage

WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw defined a punishing seven days for defenders.

3 min read
A digital lock symbol over a network diagram, representing cybersecurity
Vulnerabilities

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In

A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

3 min read
Macro photograph of tangled fiber optic cables glowing in deep blue and green light against a dark server room background, sharp focus on the glass fiber tips w
Vulnerabilities

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk

A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room aisle at night, rows of humming rack-mounted servers with soft blue and amber
Vulnerabilities

A WordPress Bug Lets Strangers Run Code on Your Site. No Login Required.

Every WordPress 6.9 and 7.0 site was exposed until a Friday emergency patch. The fix is being force-installed.

3 min read
Photoreal editorial shot of a vintage red vending machine in a dim server room, glowing softly, dispensing translucent glass capsules that contain glowing circu
AI Security

Intruder's AI 'vulnerability vending machine' finds a WordPress zero-day on its own

A security firm wired large language models into code-analysis tools and produced a working exploit for an unknown plugin flaw. It says more disclosures are on the way.

4 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Vulnerabilities

Australia sounds the alarm: hackers are hijacking small business websites at scale

The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

4 min read
Full-frame 16:9 photoreal news-editorial shot of a dimly lit server rack in a data centre, one server unit glowing with an unusually bright open port indicator,
Threat Intelligence

Cybercrime Crew Leaves Its Own Server Wide Open, Exposing 1.4 Million Website Target List

A misconfigured server ran unprotected for three weeks, handing researchers a rare look inside a mass WordPress hacking operation now tracked as WP-SHELLSTORM.

3 min read
© 2026 Threat Vectr