WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable PluginsThe Hacker News·Dec 12, 10:02 UTC · Dec 12, 2024Exploit / PoCCVE-2024-11972CVE-2024-50498CVE-2024-1120560
Palo Alto Networks’ Koi acquisition is all about keeping AI agents in checkCyberScoop·Feb 17, 16:55 UTC · Feb 17, 2026Exploit / PoC in the wild60
Hackers Actively Exploiting WidelyThe Hacker News·Apr 23, 19:23 UTC · Apr 23, 2019Exploit / PoC in the wildCVE-2019-997860
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress SitesThe Hacker News·May 8, 14:05 UTC · May 8, 2024Vulnerability in the wildCVE-2023-4000060
WordPress Social Warfare plugin zeroSecurity Affairs·Mar 24, 11:01 UTC · Mar 24, 2019Exploit / PoC in the wild60
New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to CyberattacksThe Hacker News·May 15, 00:00 UTC · May 15, 2023Vulnerability in the wildCVE-2023-30777CVE-2023-30177CVE-2023-31144+1 CVEs60
Essential Addons for Elementor XSS Vulnerability DiscoveredInfosecurity Magazine·Feb 24, 17:00 UTC · Feb 24, 2025VulnerabilityCVE-2025-2475260
Flaws in Social Warfare plugin actively exploited in the wildSecurity Affairs·Apr 25, 18:35 UTC · Apr 25, 2019Exploit / PoC in the wildCVE-2019-997860
Attackers exploit Funnel Builder bug to inject e-skimmers into eSecurity Affairs·May 17, 12:25 UTC · May 17, 2026Vulnerability in the wild60
Researchers Uncover Active Exploitation of WordPress Plugin VulnerabilitiesThe Hacker News·May 30, 13:49 UTC · May 30, 2024Vulnerability in the wildCVE-2023-6961CVE-2023-40000CVE-2024-219460
Drupal Releases Core CMS Updates to Patch Several VulnerabilitiesThe Hacker News·Apr 17, 21:51 UTC · Apr 17, 2019Vulnerability in the wildCVE-2019-10909CVE-2019-10910CVE-2019-109160
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt StrikeThe Hacker News·May 26, 05:19 UTC · May 26, 2026Exploit / PoCCVE-2026-542660
Over 800K WordPress sites are at risk due to a flaw in Ninja Forms pluginSecurity Affairs·May 1, 08:38 UTC · May 1, 2020Exploit / PoC in the wild60
Critical Security Flaw Found in Popular LayerSlider WordPress PluginThe Hacker News·Apr 4, 04:21 UTC · Apr 4, 2024VulnerabilityCVE-2024-2879CVE-2024-1852CVE-2024-1751+1 CVEs60
New Case Study: The Evil Twin Checkout PageThe Hacker News·Oct 8, 10:58 UTC · Oct 8, 2024Data breach60
LiteSpeed cPanel Plugin CVE-2026The Hacker News·May 27, 09:52 UTC · May 27, 2026Ransomware in the wildCVE-2026-48172CVE-2026-4194060
Funnel Builder Flaw Exploited to Enable WooCommerce Checkout SkimmingThe Hacker News·Jun 1, 11:32 UTC · Jun 1, 2026Exploit / PoC in the wild60
600+ installs of WordPress Cookie Consent Plugin vulnerable. Fix it now!Security Affairs·Feb 13, 11:01 UTC · Feb 13, 2020VulnerabilityCVE-2020-841760
Crooks are attempting to take over tens of thousands of WordPress sitesSecurity Affairs·Feb 29, 16:15 UTC · Feb 29, 2020Exploit / PoC in the wild60
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Critical flaws in NextGen Gallery WordPress plugin still impact over 500K installsSecurity Affairs·Feb 9, 15:18 UTC · Feb 9, 2021VulnerabilityCVE-2020-3594260
Zero-day in popular Yuzo Related Posts WordPress Plugin exploited in the wildSecurity Affairs·Apr 12, 09:35 UTC · Apr 12, 2019Exploit / PoC in the wild60
Researcher releases PoC code for critical Atlassian Crowd RCE flawHelp Net Security·Aug 3, 11:37 UTC · Aug 3, 2020Exploit / PoCCVE-2019-1158060
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
APT-C-60 Group Exploit WPS Office Flaw to Deploy SpyGlace BackdoorThe Hacker News·Aug 29, 04:31 UTC · Aug 29, 2024MalwareCVE-2024-7262CVE-2024-726360
Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and GatewayThe Hacker News·Jul 22, 03:57 UTC · Jul 22, 2023Exploit / PoC in the wildCVE-2023-3519CVE-2023-3466CVE-2023-3467+3 CVEs60
Threat actors target WordPress sites using vulnerable File Manager installsSecurity Affairs·Sep 11, 21:01 UTC · Sep 11, 2020Threat actor60
Magecart group compromises customer ratings tool, affecting 'hundreds' of online storesCyberScoop·Oct 9, 13:36 UTC · Oct 9, 2018Data breach in the wild60
Using a WordPress flaw to leverage zerologon vulnerability and attack companies’ Domain ControllersSecurity Affairs·Oct 7, 06:03 UTC · Oct 7, 2020Vulnerability in the wildCVE-2020-25213CVE-2020-147260
CVE-2026-8732: The WP Maps Pro Flaw That Lets Anyone Create a WordPress Admin Without a PasswordSecurity Affairs·Jun 1, 11:36 UTC · Jun 1, 2026Vulnerability in the wildCVE-2026-873260
WordPress LiteSpeed Cache Plugin Security Flaw Exposes Sites to XSS AttacksThe Hacker News·Oct 7, 06:13 UTC · Oct 7, 2024VulnerabilityCVE-2024-47374CVE-2024-44000CVE-2024-43917+2 CVEs60
SAP June 2025 Security Patch Day fixed critical NetWeaver bugSecurity Affairs·Jun 10, 17:31 UTC · Jun 10, 2025VulnerabilityCVE-2025-42989CVE-2025-42982CVE-2025-42983+3 CVEs60
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AICyberScoop·May 8, 13:14 UTC · May 8, 2026Exploit / PoC in the wild60
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript ZeroPalo Alto Unit 42·Jul 3, 01:11 UTC · Jul 3, 2020Exploit / PoCCVE-2016-6957CVE-2016-695860
Microsoft Security Updates January 2016Kaspersky Securelist·Jan 12, 19:08 UTC · Jan 12, 2016Vulnerability in the wildCVE-2016-003460
Flawed WordPress theme may allow admin account takeover on 22,000+ sites (CVE-2025-4322)Help Net Security·May 21, 00:00 UTC · May 21, 2025VulnerabilityCVE-2025-432260
Broadcom Patches VMware Aria FlawsThe Hacker News·Jan 31, 05:49 UTC · Jan 31, 2025Vulnerability in the wildCVE-2025-22218CVE-2025-22219CVE-2025-22220+5 CVEs60
Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site ImagesThe Hacker News·Apr 1, 05:37 UTC · Apr 1, 2025Data breachCVE-2024-27956CVE-2024-8353CVE-2024-434560
Barracuda Warns of Zero-Day Exploited to Breach Email Security Gateway AppliancesThe Hacker News·May 27, 07:08 UTC · May 27, 2023Exploit / PoC in the wildCVE-2023-286860
A flaw in the Forminator plugin impacts hundreds of thousands of WordPress sitesSecurity Affairs·Apr 22, 06:58 UTC · Apr 22, 2024VulnerabilityCVE-2024-28890CVE-2024-31077CVE-2024-3185760