Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

WordPress

20 articles

Security Affairs CVE WordPress 1d ago

Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access

Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked.

1 IOC

Security Affairs →

SecurityWeek Vulnerability Disclosure WordPress 1d ago

Everest Forms Vulnerability Exploited to Hack WordPress Sites

The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploite...

SecurityWeek →

Security Affairs Campaigns WordPress 2d ago

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 100

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Malw...

Security Affairs →

BleepingComputer CVE WordPress 3d ago

Critical Everest Forms Pro flaw exploited to take over WordPress sites

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPres...

1 IOC

BleepingComputer →

The Hacker News CVE WordPress 4d ago

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arb...

T1190 1 IOC

The Hacker News →

Exploit Database Vulnerability Disclosure WordPress 4d ago

[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

WordPress Contest Gallery 28.1.

Exploit Database →

Infosecurity Magazine Vulnerability Disclosure WordPress 5d ago

Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites

Critical Everest Forms Pro RCE flaw exploited to create rogue WordPress admin accounts

T1190

Infosecurity Magazine →

SC Media Vulnerability Disclosure WordPress 5d ago

WordPress Kirki plugin vulnerability allows account takeover

The vulnerability, present in Kirki versions 6.0.

SC Media →

Wordfence Blog Vulnerability Disclosure WordPress 6d ago

Attackers Actively Exploiting Critical Vulnerability in Everest Forms Pro Plugin

On March 30th, 2026, we publicly disclosed a critical Remote Code Execution vulnerability in Everest Forms Pro, a WordPress plugin with an estimated 4,000 ac...

T1190

Wordfence Blog →

GBHackers CVE WordPress 6d ago

WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites

A critical security flaw in the Kirki – Freeform Page Builder, Website Builder & Customizer WordPress plugin is exposing sites to account takeover and privil...

T1548 1 IOC

GBHackers →

BleepingComputer CVE WordPress Jun 2

Critical Kirki flaw exploited to hijack WordPress admin accounts

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, includi...

T1548 1 IOC

BleepingComputer →

HackRead TTPs WordPress Jun 2

New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions

GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected.

T1071

HackRead →

Security Affairs TTPs WordPress Jun 2

GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure

Malware on approximately 2,000 WordPress sites hid C2 instructions in Steam profile comments using invisible Unicode. GoDaddy researchers spotted a command-a...

T1583

Security Affairs →

SC Media Campaigns WordPress Jun 1

Malware hides in Steam comments to infect WordPress sites

The malware campaign, discovered in July 2025, has affected approximately 1,980 WordPress sites.

SC Media →

SecurityWeek CVE WordPress Jun 1

WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites

The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vu...

1 IOC

SecurityWeek →

BleepingComputer TTPs WordPress Jun 1

WordPress malware campaign hides payloads in Steam profiles

Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data. [.

BleepingComputer →

Wordfence Blog Vulnerability Disclosure WordPress Jun 1

Unauthenticated Privilege Escalation Vulnerability Patched in Kirki WordPress Plugin

On May 4th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in the Kirki WordPress plugin. Although the plugin has m...

T1548

Wordfence Blog →

Exploit Database General WordPress Jun 1

[webapps] WordPress OrderConvo 14 - Path Traversal

WordPress OrderConvo 14 - Path Traversal

Exploit Database →

BleepingComputer General WordPress May 31

WP Maps Pro bug exploited to create admin accounts on WordPress sites

Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without a...

BleepingComputer →

Exploit Database Vulnerability Disclosure WordPress May 29

[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

Quick Playground for WordPress 1.3.

T1190

Exploit Database →

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA