Follow the story

WordPress

WordPress security: plugin and theme vulnerabilities, supply-chain compromises and website takeovers. Check the affected extensions and versions before applying fixes.

Latest report:

16articles
9Reports in the past 30 days
25CVEs covered

Matching reports 16

  1. Vulnerabilities

    StopAndProtect: The Ransomware Campaign Turning Nearly 2,000 WordPress Sites into Criminal Infrastructure

    Check Point reveals StopAndProtect campaign compromises nearly 2,000 WordPress sites into a botnet for data theft and ransomware distribution.

  2. Vulnerabilities

    Two Critical WordPress Plugin Vulnerabilities Could Lead to Full Site Takeover

    Two critical vulnerabilities have been reported in widely used WordPress plugins. The first affects Forminator Forms , installed on more than 600,000

  3. Vulnerabilities

    BdThemes Compromised: WordPress Supply-Chain Attack Creates Rogue Administrator Accounts

    BdThemes plugins compromised in supply-chain attack, creating rogue admin accounts in WordPress. Check for malicious files and unauthorized accounts.

  4. Vulnerabilities

    XSS2Shell: A Pre-Authentication Chain Can Turn WordPress into a Gateway to the Server

    Learn how XSS2Shell exploits WordPress login page via pre-auth XSS and DOM clobbering for potential server compromise and remote code execution.

How this coverage is selected

Articles are selected by explicit entity names or reviewed aliases in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.