-
More than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin v…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API. This new control is designed to prevent vulner…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tra…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the world’s most widely used content management system. This initiative, known as the Core Se…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted payloads, fake reCAPTCHA prompts and fileless execution to deploy the Amatera information steale…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vul…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete control of affected websites by escalating privileges to the administrator level. This vulnerability, tr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researc…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


