WordPress
WordPress security: plugin and theme vulnerabilities, supply-chain compromises and website takeovers. Check the affected extensions and versions before applying fixes.
Latest report:
Matching reports 16
StopAndProtect: The Ransomware Campaign Turning Nearly 2,000 WordPress Sites into Criminal Infrastructure
Check Point reveals StopAndProtect campaign compromises nearly 2,000 WordPress sites into a botnet for data theft and ransomware distribution.
Two Critical WordPress Plugin Vulnerabilities Could Lead to Full Site Takeover
Two critical vulnerabilities have been reported in widely used WordPress plugins. The first affects Forminator Forms , installed on more than 600,000
BdThemes Compromised: WordPress Supply-Chain Attack Creates Rogue Administrator Accounts
BdThemes plugins compromised in supply-chain attack, creating rogue admin accounts in WordPress. Check for malicious files and unauthorized accounts.
XSS2Shell: A Pre-Authentication Chain Can Turn WordPress into a Gateway to the Server
Learn how XSS2Shell exploits WordPress login page via pre-auth XSS and DOM clobbering for potential server compromise and remote code execution.
How this coverage is selected
Articles are selected by explicit entity names or reviewed aliases in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.



