#WordPress
33 stories taggedWordPress.

Elementor Flaw Lets Attackers Hijack WordPress Sites With a Single Admin Click
A cross-site request forgery bug in the popular page-builder plugin can create rogue admin accounts if a logged-in administrator visits a booby-trapped page.

WordPress 7.1.2 Patches a Critical Flaw That Attackers Started Exploiting the Same Day It Shipped
A file-inclusion bug in the world's most popular website builder can hand attackers full control of a server. The patch and the first real attacks arrived within hours of each other.

WordPress 7.1.1 Fixes a Flaw That Could Install a Theme on an Admin's Click
The maintenance release patches 11 security bugs, including a Click2Shell chain that abuses a logged-in administrator's browser session.

WordPress Will Now Scan Every Plugin Update for Malicious Code
The world's biggest website platform is adding automated security checks to plugin updates, after years of criminals sneaking malware into trusted software.

WordPress plugin flaw is being used to plant hidden backdoors on shop sites
A file-upload bug in WooCommerce Wholesale Lead Capture lets attackers drop PHP webshells with no login required. Wordfence has blocked more than 100,000 attempts.

Hacker Backdoored a WordPress Plugin's Own Website, Hitting 1,500 Sites
The maker of Admin Menu Editor Pro says an attacker took over his site and shipped two poisoned updates that installed a hidden admin account on customer sites.

Two Critical Flaws in The Events Calendar Plugin Put 200,000 WordPress Sites at Risk
Anyone can exploit the bugs without logging in, and a successful attack hands full control of a website to the attacker. Patches exist, but roughly half of all installations may not have them yet.

Hackers Fire 440,000 Attacks at Two Popular WordPress Plugins
Flaws in Super Forms and Elementor Pro let attackers upload files and run code on unpatched sites, with mass exploitation already underway.

Attackers Race to Exploit Elementor Pro Flaw, 190,000 Attempts Logged in Four Days
A file-upload bug in the popular WordPress plugin lets criminals plant a PHP backdoor and run commands on the server. Patch shipped August 19; attacks began the same day.

WordPress backup plugin hole leaves 3.25 million sites open to hijack
A flaw in All-in-One WP Migration and Backup lets unauthenticated attackers plant SQL that fires when an admin restores a backup, handing over full control of the site.

Criminals Hid a Hacking Network Inside a Cryptocurrency Blockchain. Thirty-One Companies Got Caught.
A new campaign turns blockchain technology into an untraceable instruction relay, letting attackers redirect infected computers to a new server for less than a penny per update.

Donation plugin flaw hands attackers full control of 100,000 WordPress sites
A maximum-severity bug in GiveWP lets anyone create an account and run commands on the server. The fix landed in version 4.16.7.2 on August 27.

Critical Avada WordPress theme flaw lets attackers hijack sites with no clicks
A six-step bug chain in the popular Avada theme and Fusion Builder plugin, tracked as CVE-2026-18431, hands unauthenticated attackers full control of vulnerable WordPress sites.

Hackers Chain Two miniOrange WordPress Plugin Bugs to Log in as Admin
Paid editions of the popular SAML single sign-on plugin were quietly patched in July but never got a public warning, and now attackers are forging login sessions on sites that never updated.

Elementor Pro flaw let attackers plant executable files on WordPress sites
A bug in the paid version of the popular WordPress builder let strangers upload PHP files and run code on the server. A patch is out.