Follow the story

WordPress

WordPress security: plugin and theme vulnerabilities, supply-chain compromises and website takeovers. Check the affected extensions and versions before applying fixes.

Latest report:

16articles
9Reports in the past 30 days
25CVEs covered

Matching reports 16

  1. Vulnerabilities

    Elementor CSRF Flaw Can Turn One Administrator Click Into Full WordPress Control

    Elementor 4.3.0-4.3.1 CSRF flaw lets attackers hijack admin sessions with one click to create rogue admins. Update to 4.3.2 immediately.

  2. Vulnerabilities

    Attackers Turn WordPress Template Flaw Into Remote Code Execution Within Hours

    Critical WordPress flaw CVE-2026-87902 is exploited within hours via pearcmd.php for RCE. Learn affected themes, attack chain, and fix in 7.1.2.

  3. APT

    One Exploit Operator, Three Technology Stacks and Thousands of Exposed Government Records

    Chinese-linked actor exploited WordPress, Zyxel and UniFi flaws to breach government networks, stealing 18,566 records and compromising 996 devices.

  4. Vulnerabilities

    Click2Shell Turns a WordPress Admin Visit Into a Forced Theme Installation

    WordPress patched Click2Shell flaw letting attackers trick admins into installing themes, chainable to RCE. Update to 7.1.1 now.

  5. Vulnerabilities

    Critical Events Calendar Flaws Put More Than 200,000 WordPress Sites at Risk

    Two critical 9.8 RCE flaws in The Events Calendar plugin expose 200,000+ WordPress sites. Update to version 6.17.4.1 to fix both vulnerabilities.

  6. Vulnerabilities

    Attackers Exploit WooCommerce Plugin Flaw to Install PHP Web Shells

    Attackers exploit CVE-2026-27540 in a WooCommerce plugin to upload PHP web shells. Learn the indicators, impact, and recommended defenses.

  7. Vulnerabilities

    WordPress Under Attack: More Than 440,000 Attempts Target Super Forms and Elementor Pro

    Over 440,000 attacks exploit critical unauthenticated file upload flaws in Super Forms and Elementor Pro, enabling remote code execution. Update now.

  8. Vulnerabilities

    WordPress: RCE Vulnerability in All-in-One WP Migration Exposes Approximately 3.2 Million Sites

    CVE-2026-19949 in All-in-One WP Migration up to 7.109 enables RCE via second-order SQL injection, exposing 3.2M sites. Update to 7.110 immediately.

  9. Vulnerabilities

    CVE-2026-82222: The Critical Vulnerability in GiveWP That Exposes WordPress to Command Execution

    CVE-2026-82222: Critical GiveWP plugin flaw enables remote command execution on WordPress sites. Update to version 4.16.7.2 to fix.

  10. Vulnerabilities

    Six Chained Vulnerabilities in WordPress Avada Theme Allow Full Site Takeover

    Six chained vulnerabilities in WordPress Avada theme allow unauthenticated attackers to take over sites. Update to version 7.16.1 immediately.

  11. Vulnerabilities

    WordPress Attacks: Two Vulnerabilities in miniOrange SAML SSO Plugin Allow Administrator Access

    Discover how two critical vulnerabilities in the miniOrange SAML SSO plugin allow unauthorized WordPress admin access. Update your site now.

  12. Vulnerabilities

    Elementor Pro, Critical Vulnerability in Forms: File Upload Could Lead to Code Execution

    Critical flaw in Elementor Pro (CVE-2026-32475) lets attackers upload PHP files to execute code remotely. Affects versions before 4.2.2. Update immediately.

How this coverage is selected

Articles are selected by explicit entity names or reviewed aliases in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.