Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

WordPress

20 articles

BleepingComputer general WordPress Sep 15

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [.

BleepingComputer → Details

GBHackers general WordPress Sep 15

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload ma...

2 IOCs

GBHackers → Details

Wordfence Blog vendor WordPress Sep 14

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premiu...

T1190

Wordfence Blog → Details

The Hacker News general WordPress Sep 14

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update AP...

1 IOC

The Hacker News → Details

GBHackers general WordPress Sep 11

WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review

WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing ...

1 IOC

GBHackers → Details

Help Net Security general WordPress Sep 10

WordPress adds automated security checks to block risky plugin releases

WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API.

1 IOC

Help Net Security → Details

SecurityWeek general WordPress Sep 5

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.

1 IOC

SecurityWeek → Details

GBHackers general WordPress Sep 4

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote cod...

T1190 1 IOC

GBHackers → Details

Wordfence Blog vendor WordPress Sep 3

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated ...

T1190

Wordfence Blog → Details

BleepingComputer general WordPress Sep 3

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell pa...

T1190 1 IOC

BleepingComputer → Details

SC Media general WordPress Sep 3

SQL injection vulnerability in WordPress plugin affects millions of sites

The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110.

1 IOC

SC Media → Details

SecurityWeek general WordPress Sep 3

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPre...

T1190 1 IOC

SecurityWeek → Details

GBHackers general WordPress Sep 3

WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover

A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection v...

T1190 1 IOC

GBHackers → Details

BleepingComputer general WordPress Sep 2

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code an...

BleepingComputer → Details

Wordfence Blog vendor WordPress Sep 2

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more tha...

T1190

Wordfence Blog → Details

Wordfence Blog vendor WordPress Sep 1

5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin

On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordP...

Wordfence Blog → Details

GBHackers general WordPress Sep 1

WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited

The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the ...

GBHackers → Details

Security Affairs general WordPress Aug 31

Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers

A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.

1 IOC

Security Affairs → Details

BleepingComputer general WordPress Aug 28

GiveWP WordPress donation plugin flaw lets hackers execute server commands

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [.

BleepingComputer → Details

GBHackers general WordPress Aug 28

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to...

T1556 1 IOC

GBHackers → Details

«Previous page 1 2 3 4 5 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA