Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

WordPress

20 articles

SC Media general WordPress NEW 1h ago

New Exvicy malware-as-a-service framework copies rival's code

Exvicy operates as a ClickFix framework, distributing malware through compromised WordPress websites, according to Sekoia's Threat Detection & Research t...

T1588

SC Media → Details

Wordfence Blog vendor WordPress NEW 1h ago

PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core

WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affecte...

T1190

Wordfence Blog → Details

The Hacker News general WordPress NEW 5h ago

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On...

The Hacker News → Details

SecurityWeek general WordPress 13h ago

WordPress Patches ‘Click2Shell’ Vulnerability

The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerabili...

T1190

SecurityWeek → Details

GBHackers general WordPress 17h ago

Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data

A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business tar...

2 IOCs

GBHackers → Details

The Hacker News general WordPress 17h ago

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened tha...

1 IOC

The Hacker News → Details

BleepingComputer general WordPress 1d ago

WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell'...

BleepingComputer → Details

GBHackers general WordPress 1d ago

Click2Shell WordPress Flaw Lets Hackers Execute PHP Code and Take Over Websites

A recently disclosed WordPress vulnerability, known as Click2Shell, could let attackers execute remote PHP code on vulnerable sites after convincing a logged...

GBHackers → Details

The Hacker News general WordPress 4d ago

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in...

1 IOC

The Hacker News → Details

Help Net Security general WordPress 4d ago

Most WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security inciden...

Help Net Security → Details

Wordfence Blog vendor WordPress 5d ago

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could a...

T1190

Wordfence Blog → Details

Infosecurity Magazine general WordPress 6d ago

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells

T1190

Infosecurity Magazine → Details

The Hacker News general WordPress 6d ago

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active insta...

T1190

The Hacker News → Details

BleepingComputer general WordPress Sep 15

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the ma...

BleepingComputer → Details

BleepingComputer general WordPress Sep 15

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [.

BleepingComputer → Details

GBHackers general WordPress Sep 15

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload ma...

2 IOCs

GBHackers → Details

Wordfence Blog vendor WordPress Sep 14

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premiu...

T1190

Wordfence Blog → Details

The Hacker News general WordPress Sep 14

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update AP...

1 IOC

The Hacker News → Details

GBHackers general WordPress Sep 11

WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review

WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing ...

1 IOC

GBHackers → Details

Help Net Security general WordPress Sep 10

WordPress adds automated security checks to block risky plugin releases

WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API.

1 IOC

Help Net Security → Details

1 2 3 ... 5 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA