WordPress
WordPress security: plugin and theme vulnerabilities, supply-chain compromises and website takeovers. Check the affected extensions and versions before applying fixes.
Latest report:
Matching reports 16
Elementor CSRF Flaw Can Turn One Administrator Click Into Full WordPress Control
Elementor 4.3.0-4.3.1 CSRF flaw lets attackers hijack admin sessions with one click to create rogue admins. Update to 4.3.2 immediately.
Attackers Turn WordPress Template Flaw Into Remote Code Execution Within Hours
Critical WordPress flaw CVE-2026-87902 is exploited within hours via pearcmd.php for RCE. Learn affected themes, attack chain, and fix in 7.1.2.
One Exploit Operator, Three Technology Stacks and Thousands of Exposed Government Records
Chinese-linked actor exploited WordPress, Zyxel and UniFi flaws to breach government networks, stealing 18,566 records and compromising 996 devices.
Click2Shell Turns a WordPress Admin Visit Into a Forced Theme Installation
WordPress patched Click2Shell flaw letting attackers trick admins into installing themes, chainable to RCE. Update to 7.1.1 now.
Critical Events Calendar Flaws Put More Than 200,000 WordPress Sites at Risk
Two critical 9.8 RCE flaws in The Events Calendar plugin expose 200,000+ WordPress sites. Update to version 6.17.4.1 to fix both vulnerabilities.
Attackers Exploit WooCommerce Plugin Flaw to Install PHP Web Shells
Attackers exploit CVE-2026-27540 in a WooCommerce plugin to upload PHP web shells. Learn the indicators, impact, and recommended defenses.
WordPress Under Attack: More Than 440,000 Attempts Target Super Forms and Elementor Pro
Over 440,000 attacks exploit critical unauthenticated file upload flaws in Super Forms and Elementor Pro, enabling remote code execution. Update now.
WordPress: RCE Vulnerability in All-in-One WP Migration Exposes Approximately 3.2 Million Sites
CVE-2026-19949 in All-in-One WP Migration up to 7.109 enables RCE via second-order SQL injection, exposing 3.2M sites. Update to 7.110 immediately.
CVE-2026-82222: The Critical Vulnerability in GiveWP That Exposes WordPress to Command Execution
CVE-2026-82222: Critical GiveWP plugin flaw enables remote command execution on WordPress sites. Update to version 4.16.7.2 to fix.
Six Chained Vulnerabilities in WordPress Avada Theme Allow Full Site Takeover
Six chained vulnerabilities in WordPress Avada theme allow unauthenticated attackers to take over sites. Update to version 7.16.1 immediately.
WordPress Attacks: Two Vulnerabilities in miniOrange SAML SSO Plugin Allow Administrator Access
Discover how two critical vulnerabilities in the miniOrange SAML SSO plugin allow unauthorized WordPress admin access. Update your site now.
Elementor Pro, Critical Vulnerability in Forms: File Upload Could Lead to Code Execution
Critical flaw in Elementor Pro (CVE-2026-32475) lets attackers upload PHP files to execute code remotely. Affects versions before 4.2.2. Update immediately.
How this coverage is selected
Articles are selected by explicit entity names or reviewed aliases in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.











