Security news

Latest security news

12 of 1,256 storiesWordPressClear all

Today · Wed, 16 Sept 2026

  1. PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

    Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells

    Infosecurity MagazineWordPress
  2. Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

    The Hacker NewsWordPress

Yesterday · Tue, 15 Sept 2026

  1. Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

    Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account.

    BleepingComputerWordPress
  2. Hackers target WordPress sites via third-party WooCommerce plugin

    Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.

    BleepingComputerWordPress

Mon, 14 Sept 2026

  1. WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

    WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin

    The Hacker NewsWordPress

Thu, 10 Sept 2026

  1. WordPress adds automated security checks to block risky plugin releases

    WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release. Until now there was no consistent review step between a release being committed and that release reaching millions of sites,” David Perez, Co-Lead, WordPress Official Plugin Repository Team, explained. … More →

    Help Net SecurityWordPress

Fri, 4 Sept 2026

  1. Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

    Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

    The Hacker NewsWordPress

Tue, 18 Aug 2026

  1. Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

    Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and

    Check Point ResearchWordPress

Mon, 17 Aug 2026

  1. WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

    Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts

    Infosecurity MagazineWordPress

Fri, 14 Aug 2026

  1. Metasploit Wrap Up: Lot of summer shells and fit http profiles

    This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.* New module content (13) Ray Dashboard Logs API Path Traversal Author: Richard Howe Type: Auxiliary Pull request: #21681 contributed by rmhowe425 Path: `gather/ray_dashboard_logs_api_path_traversal` Description: This adds an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of

    Rapid7 BlogWindows, SonicWall, Linux

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets