Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [.
20 articles
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [.
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload ma...
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premiu...
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update AP...
WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing ...
WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API.
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote cod...
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated ...
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell pa...
The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110.
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPre...
A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection v...
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code an...
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more tha...
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordP...
The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the ...
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [.
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to...