SQL Injection Flaw Affects 40,000 WordPress SitesInfosecurity Magazine·Feb 3, 16:15 UTC · Feb 3, 2026Vulnerability in the wildCVE-2025-6798760
Actively exploited critical flaw in Modular DS WordPress plugin enables admin takeoverSecurity Affairs·Jan 16, 08:26 UTC · Jan 16, 2026Vulnerability in the wildCVE-2026-2355060
Attackers are exploiting recently disclosed OttoKit WordPress plugin flawSecurity Affairs·Apr 12, 10:44 UTC · Apr 12, 2025Vulnerability in the wildCVE-2025-310260
New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to CyberattacksThe Hacker News·May 15, 00:00 UTC · May 15, 2023Vulnerability in the wildCVE-2023-30777CVE-2023-30177CVE-2023-31144+1 CVEs60
OptinMonster supply chain attack hits 1.2 million sitesSansec (Magento / e-commerce security)·Jun 15, 18:34 UTC · Jun 15, 2026Vulnerability in the wild57
OttoKit WordPress Plugin Admin Creation Vulnerability Under Active ExploitationThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2025Vulnerability in the wildCVE-2025-310260
Critical Flaw in WordPress LiteSpeed Cache Plugin Allows Hackers Admin AccessThe Hacker News·Aug 23, 04:12 UTC · Aug 23, 2024Vulnerability in the wildCVE-2024-28000CVE-2023-4000060
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress SitesThe Hacker News·May 8, 14:05 UTC · May 8, 2024Vulnerability in the wildCVE-2023-4000060