Latest Updates and Insights on WordPress Security


BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

11 August 2026
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

10 August 2026
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident on August 7, 2026, after discovering that attackers had poisoned a remote promotional API feed used by several popular BdThemes plugins. The affected plugins include Element Pack […] The post New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response appeared first on Cyber Security News.

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

07 August 2026
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server. Because the flaw sits in code that has shipped with WordPress since version 4.7, it touched effectively every actively maintained installation of the world’s most popular […] The post WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution appeared first on Cyber Security News.

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

07 August 2026
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

WordPress 7.0.3 release

06 August 2026
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]

WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2

29 July 2026
WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2 A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access. The malicious version, 10.8.7, affects a plugin with roughly 20,000 active installations and is tracked as CVE-2026-18072, with a CVSS score of 9.8. The issue was detected by Wordfence PRISM, the company’s autonomous AI […] The post WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2 appeared first on Cyber Security News.

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

22 July 2026
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026. This designation […] The post CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

21 July 2026
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well

GPT-5.6 Sol Ultra Found Wp2shell RCE That Could Be Worth $500,000 for About $25

20 July 2026
GPT-5.6 Sol Ultra Found Wp2shell RCE That Could Be Worth $500,000 for About $25 GPT-5.6 Sol Ultra has reportedly uncovered a critical pre-authentication remote code execution (RCE) vulnerability in WordPress after approximately $25 worth of AI usage. This highlights how advanced models could reshape vulnerability research. Researchers at Searchlight Cyber tasked GPT-5.6 Sol Ultra with auditing a local copy of the WordPress source code using four AI agents over […] The post GPT-5.6 Sol Ultra Found Wp2shell RCE That Could Be Worth $500,000 for About $25 appeared first on Cyber Security News.

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

20 July 2026
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

17 July 2026
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team uncovered the flaw, which stems from a REST API batch-route confusion issue that leads to […] The post New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released appeared first on Cyber Security News.

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

17 July 2026
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the flaw and reported

WordPress 7.0.2 Release

17 July 2026
WordPress 7.0.2 is now available. The 7.0.2 security release addresses one critical and one high severity security issue. Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions. To manually […]

Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website

13 July 2026
Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites to complete takeover by unauthenticated remote attackers. The flaw, tracked as CVE-2026-57807, carries a near-maximum CVSS score of 9.8 and was disclosed by Patchstack on July 9, 2026. […] The post Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website appeared first on Cyber Security News.

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

10 July 2026
A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside. The operation, now tracked as

70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks

08 July 2026
70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks A recent study has revealed that more than 70% of publicly accessible WordPress websites are running outdated versions of PHP, significantly increasing their exposure to cyberattacks. The findings highlight a growing security gap in the global web ecosystem, where millions of sites rely on aging backend technologies despite the availability of regular security updates. WordPress, […] The post 70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks appeared first on Cyber Security News.

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

22 June 2026
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

20 June 2026
Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens

Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

19 June 2026
Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1, was discovered by security researcher “daroo” and reported through the Wordfence Bug […] The post Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks appeared first on Cyber Security News.

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

19 June 2026
Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercriminals of access to infected computer systems," Maikel Rollman of the Netherlands National High Tech Crime Unit said. "This prevents