Critical WordPress Post SMTP plugin flaw exposes 200K+ sites to full takeoverSecurity Affairs·Jul 28, 13:14 UTC · Jul 28, 2025VulnerabilityCVE-2025-2400060
OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple FlawsThe Hacker News·Jul 18, 04:54 UTC · Jul 18, 2025Exploit / PoC in the wildCVE-2025-27007CVE-2025-310260
Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist PluginThe Hacker News·May 29, 08:52 UTC · May 29, 2025VulnerabilityCVE-2025-4757760
RCE Vulnerability Found in RomethemeKit For Elementor PluginInfosecurity Magazine·May 19, 16:00 UTC · May 19, 2025VulnerabilityCVE-2025-3091160
⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and MoreThe Hacker News·May 7, 10:33 UTC · May 7, 2025MalwareCVE-2025-29927CVE-2025-23120CVE-2024-56346+13 CVEs60
WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site BackdoorsThe Hacker News·Apr 28, 08:06 UTC · Apr 28, 2025Vulnerability55
Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site ImagesThe Hacker News·Apr 1, 05:37 UTC · Apr 1, 2025Data breachCVE-2024-27956CVE-2024-8353CVE-2024-434560
Critical Vulnerabilities Found in WordPress Plugins WPLMS and VibeBPInfosecurity Magazine·Dec 23, 17:15 UTC · Dec 23, 2024VulnerabilityCVE-2024-56046CVE-2024-56043CVE-2024-5604260
Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPressThe Hacker News·Sep 6, 06:35 UTC · Sep 6, 2024VulnerabilityCVE-2024-44000CVE-2024-2800060
Critical WPML Plugin Flaw Exposes WordPress Sites to Remote Code ExecutionThe Hacker News·Aug 31, 15:15 UTC · Aug 31, 2024VulnerabilityCVE-2024-638660
Critical Flaw in WordPress LiteSpeed Cache Plugin Allows Hackers Admin AccessThe Hacker News·Aug 23, 04:12 UTC · Aug 23, 2024Vulnerability in the wildCVE-2024-28000CVE-2023-4000060
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress SitesThe Hacker News·May 8, 14:05 UTC · May 8, 2024Vulnerability in the wildCVE-2023-4000060
LiteSpeed Cache WordPress plugin actively exploited in the wildSecurity Affairs·May 8, 11:48 UTC · May 8, 2024Exploit / PoC in the wildCVE-2023-4000060
Experts warn of malware campaign targeting WPSecurity Affairs·Apr 26, 13:40 UTC · Apr 26, 2024MalwareCVE-2024-27956160
Critical Security Flaw in Social Login Plugin for WordPress Exposes Users' AccountsThe Hacker News·Jun 29, 07:24 UTC · Jun 29, 2023VulnerabilityCVE-2023-2982CVE-2023-3105CVE-2023-3296060
Critical Security Vulnerability Discovered in WooCommerce Stripe Gateway PluginThe Hacker News·Jun 15, 00:00 UTC · Jun 15, 2023VulnerabilityCVE-2023-3400060
Urgent WordPress Update Fixes Critical Flaw in Jetpack Plugin on Million of SitesThe Hacker News·Jun 1, 04:02 UTC · Jun 1, 2023Exploit / PoC in the wildCVE-2023-2878260
Critical RCE Flaw Reported in WordPress Elementor Website Builder PluginThe Hacker News·Apr 18, 05:47 UTC · Apr 18, 2022Vulnerability55
Critical Bug Found in WordPress Plugin for Elementor with Over a Million InstallationsThe Hacker News·Feb 2, 05:24 UTC · Feb 2, 2022Vulnerability55