Latest Updates and Insights on WordPress Security


Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks

21 August 2026
Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the vulnerability affects Elementor Pro versions up to and including 4.2.1 and is fixed in version 4.2.2. Elementor Pro is a premium extension for the Elementor page […] The post Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks appeared first on Cyber Security News.

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

19 August 2026
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware

18 August 2026
Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal command-and-control (C2) infrastructure. The campaign blends double-extortion ransomware with covert data theft, quietly harvesting sensitive corporate documents, system screenshots, user credentials, and active communication logs from compromised machines worldwide. Internal logs exposed through the threat actors’ operational […] The post Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware appeared first on Cyber Security News.

Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks

18 August 2026
Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially enabling them to take full control of vulnerable websites. The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1.56.1 and earlier and carries a CVSS severity score of 9.8. Forminator Forms is a widely used […] The post Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks appeared first on Cyber Security News.

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

17 August 2026
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

WordPress Imagick RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File

12 August 2026
WordPress Imagick RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File WordPress has released version 7.0.4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with the Imagick extension and Ghostscript. The WordPress security team is urging site owners to update immediately, either through the Dashboard’s Updates screen or by downloading the release directly from WordPress.org, since sites with automatic […] The post WordPress Imagick RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File appeared first on Cyber Security News.

WordPress 7.0.4 Release

12 August 2026
WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

11 August 2026
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

10 August 2026
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident on August 7, 2026, after discovering that attackers had poisoned a remote promotional API feed used by several popular BdThemes plugins. The affected plugins include Element Pack […] The post New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response appeared first on Cyber Security News.

WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

07 August 2026
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the underlying server. Because the flaw sits in code that has shipped with WordPress since version 4.7, it touched effectively every actively maintained installation of the world’s most popular […] The post WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution appeared first on Cyber Security News.

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

07 August 2026
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,

WordPress 7.0.3 release

06 August 2026
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support […]

WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2

29 July 2026
WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2 A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access. The malicious version, 10.8.7, affects a plugin with roughly 20,000 active installations and is tracked as CVE-2026-18072, with a CVSS score of 9.8. The issue was detected by Wordfence PRISM, the company’s autonomous AI […] The post WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2 appeared first on Cyber Security News.

CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild

22 July 2026
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026. This designation […] The post CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

21 July 2026
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well

GPT-5.6 Sol Ultra Found Wp2shell RCE That Could Be Worth $500,000 for About $25

20 July 2026
GPT-5.6 Sol Ultra Found Wp2shell RCE That Could Be Worth $500,000 for About $25 GPT-5.6 Sol Ultra has reportedly uncovered a critical pre-authentication remote code execution (RCE) vulnerability in WordPress after approximately $25 worth of AI usage. This highlights how advanced models could reshape vulnerability research. Researchers at Searchlight Cyber tasked GPT-5.6 Sol Ultra with auditing a local copy of the WordPress source code using four AI agents over […] The post GPT-5.6 Sol Ultra Found Wp2shell RCE That Could Be Worth $500,000 for About $25 appeared first on Cyber Security News.

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

20 July 2026
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

17 July 2026
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team uncovered the flaw, which stems from a REST API batch-route confusion issue that leads to […] The post New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released appeared first on Cyber Security News.

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

17 July 2026
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the flaw and reported

WordPress 7.0.2 Release

17 July 2026
WordPress 7.0.2 is now available. The 7.0.2 security release addresses one critical and one high severity security issue. Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions. To manually […]