#WordPress
33 stories taggedWordPress · page 2 of 3.

Nearly 2,000 Hacked WordPress Sites Turned Into a Criminal Toolkit
A sprawling operation dubbed StopAndProtect is quietly using compromised WordPress sites as a delivery network for malware, stolen files and screenshots.

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected
A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of hundreds of WordPress sites at risk of full takeover.

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts
A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It
A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password
The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

A Week When Small Inputs Caused Big Damage
WordPress code execution, SonicWall zero-days, attacks on AI services, and a fresh SharePoint flaw made for a punishing seven days.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

A WordPress Bug Lets Strangers Run Code on Your Site. No Login Required.
Every WordPress 6.9 and 7.0 site was exposed until a Friday emergency patch. The fix is being force-installed.

Intruder's AI 'vulnerability vending machine' finds a WordPress zero-day on its own
A security firm wired large language models into code-analysis tools and produced a working exploit for an unknown plugin flaw. It says more disclosures are on the way.

Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

Cybercrime Crew Leaves Its Own Server Wide Open, Exposing 1.4 Million Website Target List
A misconfigured server ran unprotected for three weeks, handing researchers a rare look inside a mass WordPress hacking operation now tracked as WP-SHELLSTORM.

ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor
Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline, a clean supply-chain hit on WordPress installs.

Gravity SMTP Flaw Under Active Exploitation, Leaks API Keys and OAuth Tokens
CVE-2026-4020 lets unauthenticated attackers pull secrets from roughly 100,000 WordPress installs running the mail plugin.

Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure
Dutch-led coalition disrupts servers and remediates 14,971 compromised WordPress sites, in the latest tranche of the multinational takedown effort.