ZeroHour
Product

WordPress

5 mentions in 7 days · 28 in 30 days · 32 total · first seen · last

Timeline

Matt Mullenweg tells Automattic staff in Slack he's back in control after ouster

Automattic founder Matt Mullenweg says via Slack he has regained CEO control days after the board ousted him and made CFO Mark Davies interim CEO.

Automattic's board voted earlier this week to place founder Matt Mullenweg on paid leave and named CFO Mark Davies interim CEO, confirmed at the time by a company spokesperson. On Friday, Mullenweg posted in Automattic's Slack that the board was 'back in agreement' and that he was in control; employee sources said Davies' Slack account was deactivated. Mullenweg has publicly suggested Silver Lake, majority owner of WP Engine — which is suing Mullenweg and Automattic — was involved in the ouster. Automattic had not formally confirmed his claim and the situation remains fluid.

Hacker News · securityupdated · 4d agofirst · 4d agoOther 7 sourcesHN 44↑ · 17 comments

Launching managed CRA Article 14 reporting for open source maintainers

EU Cyber Resilience Act Article 14 reporting obligations begin, requiring 24-hour exploit and incident reports; Patchstack launches managed compliance for open-source maintainers.

Starting 11 September 2026, EU Cyber Resilience Act Article 14 requires manufacturers and open-source stewards to report actively exploited vulnerabilities and severe security incidents to ENISA via the EU Single Reporting Platform, with a 24-hour early warning, 72-hour notification, and final reports within 14 days or one month. Patchstack launched a free managed compliance service, acting as Assigned Representative for open-source maintainers and providing a managed VDP. The obligations apply retroactively to all products available on the European market. Patchstack, which has coordinated over 50% of known WordPress ecosystem vulnerabilities, already serves more than 1,000 open-source projects.

Patchstack · 4d agoPolicy & legal

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)

Wordfence's weekly WordPress vulnerability report summarizes plugin and theme vulnerabilities disclosed and added to its database during the week ending September 6, 2026.

Wordfence published its weekly WordPress Vulnerability Report covering disclosures between August 31 and September 6, 2026. The report lists new vulnerabilities added to the Wordfence Intelligence Vulnerability Database and highlights contributors to WordPress Security. Administrators are advised to review the listed plugin and theme vulnerabilities to check whether their sites are affected.

Wordfence · 5d agoAdvisory

WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

WordPress.org now auto-blocks plugin updates flagged by AI review after a backdoor incident, adding a supply-chain gate for millions of sites.

Since June 5, 2026, every WordPress.org plugin and theme release passes a mandatory six-hour cooldown while multiple AI models and Jetpack Scan analyze code changes and produce a consolidated security score; releases above the risk threshold are blocked automatically. The change followed a July 28, 2026 incident where a backdoor was pushed into a plugin with roughly 20,000 active installs, which Wordfence flagged and the Plugins Team pulled 26 minutes later before distribution. Authors are notified of blocking findings and can republish corrected releases or appeal false positives to the Plugins Team.

Cyber Security Newsupdated · 4d agofirst · 5d agoTools 7 sources

Automattic's board forces CEO Matt Mullenweg into leave of absence

Automattic's board voted to place CEO Matt Mullenweg on paid leave against his will, naming CFO Mark Davies interim CEO of WordPress's parent company.

Automattic's board voted to put founder and CEO Matt Mullenweg on paid leave against his will, with CFO Mark Davies appointed interim CEO; Mullenweg remains on the board. The move follows years of turmoil, including a protracted legal battle with WP Engine, a 2024 ultimatum in which 159 employees took severance, and a 16% staff layoff in April 2025. WordPress.org's executive director said the open-source WordPress project and its teams continue as planned and are not impacted. Automattic also owns Tumblr, WooCommerce, and Pocket Casts.

Hacker News · securityupdated · 4d agofirst · 5d agoOther 7 sourcesHN 23↑ · 99 comments

404 Media

404 Media homepage roundup: WordPress CEO Matt Mullenweg put on leave, first Take It Down Act sentence of 15 years, and DHS predictive policing revelations.

The 404 Media feed aggregates stories including Automattic board members voting WordPress co-founder Matt Mullenweg onto a leave of absence, and James Strahler receiving 15 years under the Take It Down Act for real and AI-generated sexually explicit images plus threats. It also reports a secretive DHS Border Patrol predictive policing unit that analyzes Americans' financial data and has local police pull people over with no suspected crime. Additional items cover Channel 5 sharing subscriber emails with Hunter Biden despite its privacy policy, and a man's death after emotional reliance on ChatGPT.

404 Media · 7d agoOther

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Attackers are actively exploiting critical file-upload flaw CVE-2026-32475 in Elementor Pro, hacking WordPress sites; Defiant has blocked over 190,000 exploit attempts since patching.

Defiant warns that attackers are exploiting CVE-2026-32475 (CVSS 9.8), an unauthenticated arbitrary file upload flaw in the Elementor Pro WordPress plugin's form submission handling, which affects all versions up to 4.2.1 and was patched in version 4.2.2 on August 19. Exploitation began immediately after the fix shipped, with Defiant blocking over 190,000 exploit attempts to date; roughly two-thirds of Elementor's 10 million installations still ran a vulnerable version as of September 4. Successful exploitation writes attacker-controlled PHP files to /wp-content/uploads/elementor/forms/ and can lead to full site compromise; administrators should check that directory for PHP files and review requests to /wp-admin/admin-ajax.php.

SecurityWeek · 10d agoExploit / PoC in the wildCVE-2026-32475

Elementor Pro RCE Flaw Under Active Attack

A critical Elementor Pro Forms module flaw allowing unauthenticated file uploads is under active attack against widely used WordPress sites.

A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload arbitrary files through the plugin's Forms module. The SOCRadar report indicates the flaw is being actively exploited in the wild. No CVE identifier was provided in the available text.

SOCRadar · 11d agoExploit / PoC in the wild

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Wordfence blocked 440,000+ exploit attempts against critical unauthenticated RCE flaws in WordPress plugins Super Forms and Elementor Pro.

Wordfence reports mass exploitation of two unauthenticated arbitrary file upload RCE flaws: CVE-2026-14894 in Super Forms (CVSS 9.8, fixed in 6.3.314) and CVE-2026-32475 in Elementor Pro (CVSS 9.0/9.8, fixed in 4.2.2), with over 250,000 and 190,000 blocked exploit attempts respectively. Attackers upload Base64-encoded PHP web shells such as Mushr00w_upl.php to execute code, create administrator accounts, exfiltrate data, or seize sites. Super Forms exploitation began July 14, 2026 and peaked above 40,000 requests on August 18; Elementor Pro attacks started August 19. Successful Elementor Pro exploitation requires a published page with a Form widget containing a File Upload field.

The Hacker News · 11d agoExploit / PoC in the wildCVE-2026-14894CVE-2026-32475

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

Attackers actively exploit a critical unauthenticated file upload flaw in Elementor Pro (6M+ installs), enabling remote code execution and site takeover.

Wordfence reports that attackers are actively exploiting a critical unauthenticated arbitrary file upload vulnerability in Elementor Pro, which it disclosed on August 19, 2026. The WordPress plugin has more than 6,000,000 active installations. Unauthenticated attackers can upload arbitrary files, including executable PHP files, leading to remote code execution and complete site takeover.

Wordfence · 13d agoExploit / PoC in the wild

5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin

Unauthenticated second-order SQL injection found in All-in-One WP Migration and Backup plugin with 5+ million active installs.

Wordfence received a submission on August 14, 2026 for an unauthenticated second-order SQL injection vulnerability in the All-in-One WP Migration and Backup WordPress plugin. The plugin has more than 5 million active installations. The disclosure text does not include a CVE id, a patch version, or evidence of exploitation.

Wordfence · 14d agoVulnerability

Vulnerability & Patch Roundup — August 2026

Sucuri's monthly roundup compiles August 2026 security patches for the WordPress ecosystem to help site owners prioritize updates against automated exploitation.

Sucuri published its August 2026 Vulnerability & Patch Roundup summarizing essential security updates across the WordPress ecosystem. The post notes that most breaches the company observes begin with automated attacks exploiting previously disclosed vulnerabilities. It urges website operators to apply the listed plugin and theme patches promptly to avoid compromise and costly remediation. No specific CVE identifiers are named in the announcement.

Sucuri Blog · 14d agoAdvisory

Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers

Critical unauthenticated PHP object injection (CVE-2026-82222) in the GiveWP WordPress donation plugin chains to remote code execution; version 4.16.7.2 fixes it.

Patchstack disclosed CVE-2026-82222 (CVSS 10.0), an unauthenticated PHP object injection in GiveWP versions through 4.16.7.1 that chains through TCPDF and Give\TestData gadget classes to arbitrary OS command execution as the web server user. On versions 4.16.5.1 and below, a default installation with one published donation form is enough to exploit, with no user interaction required. Version 4.16.7.2 blocks unsafe serialized data, hardens the gadget chain and cleans already-stored database records; a separate registration bypass issue remains unresolved.

Security Affairs · 15d agoVulnerabilityCVE-2026-82222

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Five critical flaws (CVSS 9.8–10.0) in WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP enable WordPress admin takeover and RCE.

Wordfence and Patchstack disclosed five critical flaws in WordPress plugins and themes: WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. The issues include unauthenticated authentication bypass (CVE-2026-76581), arbitrary file write leading to RCE (CVE-2026-18431), administrator account takeover via password-reset URL exposure (CVE-2026-19632), privilege escalation (CVE-2026-19598), and PHP object injection to RCE (CVE-2026-82222, CVSS 10.0). Patchstack says the GiveWP flaw chains an unsafe unserialize helper, attacker-controlled donation data, and a gadget chain in shipped code.

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP

Patchstack details an unauthenticated PHP object injection chain enabling remote code execution in the GiveWP WordPress donation plugin.

Patchstack disclosed an unauthenticated remote code execution vulnerability in the GiveWP WordPress donation plugin. An attacker with no account can execute arbitrary commands on the server of an affected GiveWP site. The full chain is reachable when a site has one published donation form and one active payment gateway, a configuration the researcher describes as a common default.

Patchstack · 18d agoVulnerability

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)

Wordfence logged 240 disclosed vulnerabilities across 184 WordPress plugins and 17 themes for the week of August 17-23, 2026.

Wordfence's weekly WordPress vulnerability report for August 17-23, 2026 added 240 vulnerabilities to its Intelligence Vulnerability Database, affecting 184 plugins and 17 themes. 105 vulnerability researchers contributed during the period. WordPress administrators are advised to review the list to check whether their sites use affected components.

Wordfence · 19d agoVulnerability

Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales

Wordfence's AI-assisted Argus found a six-step critical RCE chain in the Avada WordPress theme, which has more than one million sales.

Wordfence reports that its Argus research uncovered a complex six-step exploit chain yielding critical remote code execution in the Avada WordPress theme, one of the best-selling themes with over one million sales. The company also notes AI-assisted submissions to its bug bounty program grew from 16% to roughly two-thirds of all reports in recent months. Sites running Avada should apply the patched release.

Wordfence · 21d agoVulnerability

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers are exploiting two unauthenticated WordPress auth bypasses (CVE-2026-61979, CVE-2026-15981, max CVSS 9.8) in miniOrange SAML SSO to gain admin sessions.

Patchstack disclosed two flaws in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin: CVE-2026-15981 (CVSS 9.8) accepts malformed signatures because mo_saml_validate_signature() loosely checks the tri-state result of openssl_verify(), and CVE-2026-61979 (CVSS 8.1) enables privilege escalation via signature algorithm confusion. Both let unauthenticated attackers sign in as any WordPress user, including administrators; fixes shipped in Standard edition versions 17.0.6 and 17.0.5. DigitalOcean observed an attacker using the bypass to obtain an admin session cookie, opportunistic scanning is underway from six IP addresses, and PoC chaining code is public.

The Hacker News · 21d agoExploit / PoC in the wildCVE-2026-61979CVE-2026-15981

$20 per zero-day is already the WordPress plugin reality

TrendAI and CHT Security used an AI pipeline to find over 300 verified WordPress plugin zero-days at roughly $20 per vulnerability.

A pipeline built in three days by TrendAI and CHT Security, presented at Ekoparty Miami, paired AI-driven static analysis with automated Docker provisioning and Chrome DevTools MCP dynamic verification to surface more than 300 critical zero-days in WordPress plugins within 72 hours. The run consumed about 222 million tokens across 95 tasks, averaging roughly $20 per verified vulnerability, with findings including pre-auth RCE, SQL injection, privilege escalation, SSRF, and an AI-assembled downgrade attack chain. Dynamic verification eliminated over 80% of false positives, but manual review at 30-60 minutes per finding remains the bottleneck, straining ZDI and NIST triage backlogs.

Help Net Security · 22d agoResearch1

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

DigitalOcean researchers reported a critical authentication flaw in miniOrange SAML SSO WordPress plugins, allowing login as WordPress admin across seven editions.

The DigitalOcean security team identified a critical flaw in miniOrange's SAML SSO WordPress plugins that allowed an attacker to authenticate as a WordPress administrator. Patchstack notes the issue spans seven editions of the plugin, all sharing a common slug. The write-up covers root cause analysis by DigitalOcean and vendor follow-up coordinated jointly with Patchstack; no specific CVE id is cited in the text.

Patchstack · 25d agoVulnerability

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

Check Point uncovered StopAndProtect, a cybercrime operation using ~2,000 hacked WordPress sites for ClickFix-driven malware delivery, data theft, surveillance, and ransomware.

Check Point Research identified the StopAndProtect operation in May 2026; it abuses close to 2,000 compromised WordPress sites, many running outdated software, to host malware stages, act as C2, and store stolen data. Infection starts with fake CAPTCHA ClickFix prompts that trick visitors into running a PowerShell command, followed by .NET downloaders deploying ransomware, SMB/USB worm, lockscreen, chat, and credential-stealing components. Rather than always encrypting, operators selectively exfiltrate file lists and specific files; researchers found 700+ stolen-data archives, roughly 31,000 screenshots, and 6,000+ unique victim IP addresses, including WhatsApp activity monitoring.

Security Affairs · 26d agoThreat actor in the wild

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Patchstack disclosed CVE-2026-32475 (CVSS 9.0), an unauthenticated file-upload flaw in Elementor Pro enabling PHP upload and RCE; fixed in version 4.2.2.

Patchstack researcher Tin Pham reported an unrestricted file upload flaw in Elementor Pro's Forms module (CVE-2026-32475, CVSS 9.0), affecting all versions up to and including 4.2.1. Submitting two file parts for one field bypasses the extension blocklist and writes attacker-controlled PHP into a public uploads directory, yielding unauthenticated remote code execution when a published Elementor page uses a Form widget with a File Upload field. A patched version 4.2.2 shipped August 19, 2026, a day after WordPress 7.0.4 fixed CVE-2026-65640 (CVSS 8.8), an RCE via Postscript file upload when Imagick and Ghostscript are in use.

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Check Point details StopAndProtect: ~2,000 compromised WordPress sites deliver ClickFix fake-CAPTCHA malware toolkit combining ransomware, credential theft, screenshots, and WhatsApp surveillance.

Check Point researcher Jaromír Hořejší reports the campaign begins with ClickFix fake-CAPTCHA prompts that trigger a PowerShell command, then two .NET downloader stages that launch six components: SilentEncryptor, NetworkShareScanner, a VBS spreader, LockScreen, SimpleChatProxy, and SilentDataCollector. Hacked WordPress sites host malware stages, serve C2 commands, and receive exfiltrated logs; the actors installed a self-deleting WordPress plugin enabling arbitrary PHP upload anywhere under the WordPress root. From mid-May to late July 2026 the operators exfiltrated more than 700 archives including screenshots every 30 seconds, keylogger output, and WhatsApp contact data, and opsec failures exposed their Visual Basic automation tooling and lists of nearly 2,000 compromised domains.

The Hacker News · 26d agoThreat actor in the wild

Critical Unauthenticated File Upload to RCE in Elementor Pro Plugin

Elementor Pro WordPress plugin has an unauthenticated arbitrary file upload flaw in its Forms module allowing remote code execution.

Patchstack disclosed a critical unauthenticated arbitrary file upload vulnerability in the Elementor Pro WordPress plugin that can lead to remote code execution. The flaw is in the Forms module's File Upload field, where the extension check and the file-move step run in two separate loops with inconsistent handling of empty file entries. The writeup describes exploitation via crafted upload submissions; no CVE id or evidence of in-the-wild exploitation is given in the post.

Patchstack · 27d agoVulnerability

Muhstik Botnet Attacks Tomato Routers to Harvest New IoT Devices

Unit 42 found a Muhstik botnet variant brute-forcing Tomato router web authentication to harvest IoT devices for crypto mining and DDoS attacks.

Palo Alto Networks Unit 42 researchers in December 2019 identified a new Muhstik botnet variant scanning Tomato routers on TCP 8080 and brute-forcing default admin credentials, targeting roughly 4,600 exposed devices found via Shodan. The variant also scans WordPress and Webuzo installations and exploits the Oracle WebLogic deserialization flaw CVE-2019-2725 for unauthenticated remote code execution. Muhstik, active since March 2018, self-propagates like a worm and typically monetizes infections through cryptocurrency mining and DDoS attacks controlled via an IRC C2 channel.

Palo Alto Unit 42 · 27d agoMalware in the wildCVE-2019-2725

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Check Point uncovers the StopAndProtect ransomware operation infecting thousands of WordPress sites via ClickFix social engineering and PowerShell downloaders.

Check Point Research first observed the StopAndProtect ransomware family in mid-May 2026 and linked its infrastructure to thousands of hacked WordPress sites. The infection chain begins with ClickFix social engineering that prompts victims to run a PowerShell command, followed by two stages of additional downloaders. The research maps the shared infrastructure unifying the operation.

Check Point Research · 28d agoRansomware in the wild

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical unauthenticated flaw in the User Profile Builder WordPress plugin exposed roughly 40,000 sites to administrator account takeover.

Infosecurity Magazine reports a critical flaw in the User Profile Builder WordPress plugin that let unauthenticated attackers access administrator accounts. Approximately 40,000 sites were exposed to full admin takeover as a result. The report did not specify a CVE identifier or state whether exploitation was observed in the wild.

Infosecurity Magazine · 29d agoVulnerability

Campaign Evolution: Darkleech to Pseudo

Unit 42 traces the pseudo-Darkleech campaign, which compromises websites to inject scripts redirecting visitors to exploit kits delivering ransomware.

Palo Alto Networks Unit 42 analyzed the evolution of the pseudo-Darkleech campaign, which injects malicious script into compromised Apache, IIS and WordPress sites to redirect visitors to exploit kits such as Angler and Neutrino. The original Darkleech Apache module infected thousands of servers starting in 2012 and delivered Blackhole EK until that kit disappeared after Paunch's 2013 arrest. From 2015 onward, pseudo-Darkleech delivered ransomware families like CryptoWall and TeslaCrypt, and by early 2016 its injected scripts added obfuscated numeric blocks with frequently changing separator characters. Unit 42 tracks these patterns to help defenders identify compromised websites.

Palo Alto Unit 42 · 29d agoThreat actor in the wild

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus exploits Windows AFD.sys zero-day CVE-2026-68820 in Operation Dream Job to deploy Troy backdoor at defense firms.

Check Point attributes Operation Dream Job attacks to Lazarus Group exploiting CVE-2026-68820 (CVSS 7.0), a privilege escalation flaw in Windows AFD.sys patched in August 2026 Patch Tuesday. The campaign targets defense and aerospace firms in France, Germany, Brazil, and India via trojanized PDF viewers and DLL side-loading, deploying backdoors Troy, ForestTiger, and the FudModule 3.1 kernel rootkit. Attackers also compromise WordPress, SharePoint, and Roundcube servers as C2, using CVE-2025-49113 and the RelayShell PHP web shell.

The Hacker News · Aug 15, 2026Threat actor in the wildCVE-2026-68820CVE-2025-491131

Wordpress Fixes Critical Plugin

WordPress maintainers patched a critical vulnerability in a widely used plugin, urging site owners to update before potential exploitation.

WordPress has released a fix for a critical vulnerability affecting one of its plugins, per Infosecurity Magazine. Plugins in the WordPress ecosystem often power millions of sites, making timely patching important to limit exposure. The available information does not specify a CVE identifier, affected versions, or whether exploitation has been observed.

Infosecurity Magazine · Aug 15, 2026Vulnerability

When a PNG Isn’t a PNG: WordPress Patches an Author-Level Imagick RCE

WordPress 7.0.4 patches an author-level RCE in how uploaded media is handed to ImageMagick.

WordPress maintenance release 7.0.4 includes a security fix that changes how uploaded media is passed to ImageMagick, closing a path that let a logged-in author turn a crafted image upload into remote code execution. Patchstack's analysis explains the flaw as a file-type handling issue where a PNG may not be treated as a PNG. The text does not mention a CVE ID or observed exploitation, but the flaw affects extremely widely deployed software.

Patchstack · Aug 12, 2026Vulnerability

WordPress 7.0.4 Release

WordPress releases 7.0.4 with a security fix and urges all sites to update immediately.

WordPress.org announced the availability of WordPress 7.0.4, a maintenance release containing a security fix. Because it is a security release, the project recommends updating sites immediately via the dashboard or a download from WordPress.org. The announcement gives no technical details about the flaw being patched.

WordPress.org · Security · Aug 12, 2026Advisory

Related CVEs

  • Unauthenticated PHP File Upload (RCE) in Elementor Pro WordPress Plugin
    Elementor Pro, the paid add-on to the widely used Elementor page builder for WordPress, is affected by an unrestricted upload of files with dangerous types (CWE-434) that can be triggered by unauthenticated attackers. An attacker sends a crafted upload request to the plugin's vulnerable endpoint and can upload a dangerous file — notably a PHP file — which the web server then executes, yielding remote code execution on the hosting account. The critical 9.0 CVSS score with scope change (S:C) and high impact across confidentiality, integrity and availability reflects that code execution lets an attacker take over the site, plant backdoors, modify content and potentially affect the underlying host. All Elementor Pro releases up to and including 4.2.1 are affected, meaning every site that has not yet updated to a fixed version is in scope. The flaw is not yet listed in CISA KEV and no public proof-of-concept is cataloged, and EPSS assigns a 2.4% 30-day exploitation probability (83rd percentile), but news reports already document hundreds of thousands of exploit attempts against Elementor Pro and Super Forms RCE flaws, so it should be treated as exploited in the wild.
    · Elementor Pro (WordPress plugin) All versions from n/a through 4.2.1 (i.e., every release up to and including 4.2.1)mass
  • Unauthenticated PHP Object Injection Leading to RCE in GiveWP WordPress Plugin
    CVE-2026-82222 is a deserialization of untrusted data flaw (CWE-502) in the GiveWP donation plugin for WordPress, developed by Liquid Web / StellarWP, affecting all versions through 4.16.7.1. The vulnerable code path is reachable over the network without authentication (CVSS vector AV:N/AC:L/PR:N), allowing an attacker to supply a crafted serialized object that the plugin unserializes, resulting in PHP object injection. By exploiting gadget chains in the plugin or WordPress core, the attacker can achieve remote code execution and run commands on the WordPress server, with the scope-changed CVSS rating and high confidentiality, integrity, and availability impacts indicating full site or server compromise is possible. Any WordPress site running GiveWP version 4.16.7.1 or older is affected, and because donation plugins are typically deployed on donor-facing public pages, the vulnerable endpoints are often directly exposed to the internet. A public proof-of-concept exists, but current exploitation risk is assessed as low: EPSS is 0.4% (35th percentile) and the flaw is not yet in CISA's Known Exploited Vulnerabilities catalog.
    · Liquid Web / StellarWP GiveWP (WordPress plugin) all versions from n/a through 4.16.7.1 PoC large
  • Unauthenticated Injection in Oracle WebLogic Web Services Enables RCE
    CVE-2019-2725 is an easily exploitable injection flaw (CWE-74) in the Web Services subcomponent of Oracle WebLogic Server within Oracle Fusion Middleware, publicly documented as affecting WebLogic 10.3.6.0, 12.1.3.0, 12.2.1.1 and 12.2.1.3. It is triggered when an unauthenticated remote attacker sends attacker-controlled XML over HTTP to the WebLogic Web Services async response endpoint (the /_async/AsyncResponseService servlet), which processes the input unsafely. Successful attacks give the attacker takeover of the affected WebLogic server (remote code execution); in the 2019 exploitation wave this was used to install cryptocurrency miners and deploy ransomware. Any organization running affected Oracle WebLogic Server versions is exposed, with the greatest risk where the async/Web Services endpoints are reachable, especially on internet-facing servers. Exploitation is confirmed in the wild: CISA added the CVE to its KEV catalog on 2022-01-10 with ransomware use known and requires applying vendor updates, the EPSS probability of exploitation is 100% (100th percentile), and no public PoC is catalogued.
    · Oracle WebLogic Server (Oracle Fusion Middleware, Web Services subcomponent) KEV ransomware PoC large
  • Authenticated PHP Object Deserialization RCE in Roundcube Webmail
    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 contains a PHP object deserialization flaw (CWE-502) that allows remote code execution by authenticated users. The bug is in program/actions/settings/upload.php, where the _from URL parameter is not validated before deserialization, so any logged-in user can trigger it with a crafted URL to the settings upload action, with no user interaction required. Successful exploitation gives the attacker code execution on the web server with high confidentiality, integrity, and availability impact (CVSS 3.1 8.8). All deployments running affected versions are exposed, including Roundcube packages shipped with Debian Linux. The flaw reportedly existed for roughly a decade before disclosure, carries a 98.9% EPSS score (top percentile), and was added to CISA's KEV catalog on 2026-02-20, confirming exploitation in the wild.
    · Roundcube Webmail all versions before 1.5.10, and 1.6.x before 1.6.11 · Debian Linux (Roundcube Webmail package) Debian releases shipping affected Roundcube versions; fixes delivered via Debian security updates KEV PoC ×2mass
  • Unauthenticated Sensitive Information Exposure in TranslatePress WordPress Plugin
    TranslatePress – Translate Multilingual sites with AI Translation for WordPress, in all versions up to and including 3.3.1, leaks sensitive data through its unauthenticated 'trp_get_translations_regular' AJAX action (CWE-640). When automatic string saving is enabled (the plugin's default) and an administrator's profile locale is set to a published secondary language, the raw password-reset URL — containing the plaintext reset key and login parameters — is persisted in the secondary-language translation dictionary table. An unauthenticated attacker can then retrieve these stored strings via the AJAX endpoint and use the leaked reset key to take over the administrator account. Any WordPress site running the affected versions under those configuration conditions is exposed. No public proof-of-concept or confirmed exploitation is known; the flaw is not in CISA KEV and EPSS estimates a 0.8% probability of exploitation within 30 days.
    · TranslatePress – Translate Multilingual sites with AI Translation (WordPress plugin) All versions up to and including 3.3.1large
  • Unauthenticated Privilege Escalation in WordPress Pods Plugin Enables Site Takeover
    The Pods – Custom Content Types and Fields plugin for WordPress (all versions through 3.3.9) routes every access check on its pods_admin AJAX router — the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which in the JSON meta-box-loader compatibility path only writes a PHP error-log entry and returns false instead of terminating the request. As a result, an unauthenticated request sent through this AJAX path passes all of the plugin's guards without being stopped and can invoke privileged administrator actions. An attacker can escalate to Administrator or overwrite the password of any user account, including the site owner's, achieving complete site takeover or performing other administrator-level actions. Any WordPress site running an affected version of the plugin is exposed. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, though the 9.8 CVSS score and elevated EPSS (2.8%, 86th percentile) make it a high-priority patching target.
    · Pods Foundation Pods – Custom Content Types and Fields (WordPress plugin) All versions up to and including 3.3.9mass
  • Unauthenticated Arbitrary File Write to RCE in Avada WordPress Theme
    CVE-2026-18431 is a critical (CVSS 9.8) arbitrary file write vulnerability in the Avada WordPress theme (all versions through 7.16) that is exploitable when the bundled Fusion Builder plugin (all versions through 3.16) is also installed and active. A chain of missing authorization (CWE-862) and input validation weaknesses across the two components allows unauthenticated attackers to write attacker-controlled files to the server. Because the attacker can create and execute arbitrary PHP files, successful exploitation leads to remote code execution and complete site compromise. Exploitation requires both components to be active and certain administrator-authored content to be present, narrowing the practical attack surface. No public proof of concept, in-the-wild exploitation, or KEV listing is currently known, and EPSS estimates only a 0.6% chance of exploitation within 30 days.
    · ThemeFusion Avada theme for WordPress all versions up to and including 7.16 · ThemeFusion Fusion Builder plugin for WordPress all versions up to and including 3.16 (when installed and active)mass
  • The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the sub
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed…
    · WordPress
  • Author-Level RCE in WordPress Core via Malicious Postscript File Upload
    WordPress core is vulnerable to remote code execution when a user with Author-level privileges or higher (holding the upload_files capability) uploads a malicious Postscript file that the server processes using the Imagick image library with Ghostscript. Exploitation requires two server prerequisites: Imagick must be in use and Ghostscript must be installed, and the attacker needs an account with upload rights, so unauthenticated attacks are not possible. A successful attacker gains code execution on the web server with high impact on confidentiality, integrity, and availability (CVSS 8.8). All versions of WordPress are affected; a fix shipped in WordPress 7.0.4 and was backported as a courtesy to all branches back to 4.7. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS assigns a 1.9% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is documented.
    · WordPress (core) All versions prior to the fix; fixed in 7.0.4, with the fix backported to all branches back to 4.7mass
  • Unauthenticated privilege escalation in miniOrange SAML SSO WordPress plugin
    CVE-2026-61979 is an unauthenticated privilege-escalation flaw (CWE-266, incorrect assignment of privileges) in the miniOrange 'SAML SP Single Sign On' plugin for WordPress, affecting every version up to and including 5.4.3. Because it is reachable over the network with no privileges required and no user interaction (the CVSS 3.1 vector rates attack complexity as high), a remote attacker can abuse the plugin's SAML single sign-on handling to gain WordPress administrator-level privileges without valid credentials. With administrator access, an attacker can modify content, install plugins or themes, create rogue admin accounts, and use the site as a foothold. Any WordPress site running the affected versions is exposed, and reporting indicates the plugin's paid editions were also vulnerable to related flaws in the same campaign. No public proof-of-concept is known for this specific flaw and it is not in CISA KEV (EPSS ~0.3% over 30 days), but two separate CVSS 9.8 authentication-bypass flaws in the same plugin were exploited in the wild before they were even catalogued, and attackers are actively targeting miniOrange SAML flaws that grant WordPress admin access.
    · miniOrange SAML SP Single Sign On (WordPress plugin) <= 5.4.3 · miniOrange SAML SP Single Sign On - paid/premium editions (reported alongside the actively exploited related flaws)large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.