WordPress LiteSpeed Cache plugin flaw could allow site takeoverSecurity Affairs·Oct 5, 13:49 UTC · Oct 5, 2024VulnerabilityCVE-2024-47374CVE-2024-4400047
Critical WPML Plugin Flaw Exposes WordPress Sites to Remote Code ExecutionThe Hacker News·Aug 31, 15:15 UTC · Aug 31, 2024VulnerabilityCVE-2024-638660
GiveWP WordPress Plugin Vulnerability Puts 100,000+ Websites at RiskThe Hacker News·Aug 21, 04:35 UTC · Aug 21, 2024VulnerabilityCVE-2024-5932CVE-2024-6500CVE-2024-7094+4 CVEs60
WordPress Plugins at Risk From Polyfill Library CompromiseInfosecurity Magazine·Jul 3, 17:15 UTC · Jul 3, 2024Vulnerability42
WordPress Plugin Exploited to Steal Credit Card Data from EThe Hacker News·May 29, 04:41 UTC · May 29, 2024Malware30
Fake Online Stores Scam Over 850,000 ShoppersInfosecurity Magazine·May 9, 09:30 UTC · May 9, 2024Phishing & fraud30
Sneaky Credit Card Skimmer Disguised as Harmless Facebook TrackerThe Hacker News·Apr 12, 09:26 UTC · Apr 12, 2024Malware42
Backup Migration WordPress Plugin Flaw Impacts 90,000 SitesInfosecurity Magazine·Dec 12, 10:00 UTC · Dec 12, 2023Exploit / PoCCVE-2023-655360
Many popular websites still cling to password creation policies from 1985Help Net Security·Dec 12, 00:00 UTC · Dec 12, 2023Data breach45
Vulnerability Exposed in WordPress Plugin User Submitted PostsInfosecurity Magazine·Oct 12, 17:00 UTC · Oct 12, 2023VulnerabilityCVE-2023-4560335
New Magecart campaign hides malicious code in 404 error pageSecurity Affairs·Oct 12, 07:23 UTC · Oct 12, 2023Threat actor45
New Magecart Campaign Alters 404 Error Pages to Steal Shoppers' Credit CardsThe Hacker News·Oct 10, 12:40 UTC · Oct 10, 2023Threat actor45
Magecart Hackers Hide in 404 Error PagesInfosecurity Magazine·Oct 10, 09:30 UTC · Oct 10, 2023Vulnerability42
Flaw Exposes WP Migration Plugin to HacksInfosecurity Magazine·Aug 30, 17:30 UTC · Aug 30, 2023Vulnerability42
Cybersecurity Study Reveals Web App Vulnerability CrisisInfosecurity Magazine·Aug 18, 17:00 UTC · Aug 18, 2023Vulnerability55
Scammers Exploit Hacked Websites For PhishingInfosecurity Magazine·Aug 16, 16:30 UTC · Aug 16, 2023Phishing & fraud30
Multiple Flaws Found in the Avada WordPress Theme and PluginInfosecurity Magazine·Aug 11, 17:30 UTC · Aug 11, 2023VulnerabilityCVE-2023-39309CVE-2023-39306CVE-2023-39307+2 CVEs47
High Severity Vulnerabilities Discovered in Ninja Forms PluginInfosecurity Magazine·Jul 27, 17:00 UTC · Jul 27, 2023VulnerabilityCVE-2023-37979CVE-2023-38393CVE-2023-3838647
Zero-Day Attacks Exploited Critical Vulnerability in Citrix ADC and GatewayThe Hacker News·Jul 22, 03:57 UTC · Jul 22, 2023Exploit / PoC in the wildCVE-2023-3519CVE-2023-3466CVE-2023-3467+3 CVEs60
Improve Your Security WordPress Spam Protection With CleanTalk AntiThe Hacker News·Jul 8, 06:14 UTC · Jul 8, 2023Industry30
Magecart campaign abuses legitimate sites to host web skimmers and act as C2Security Affairs·Jun 5, 08:03 UTC · Jun 5, 2023Threat actor45
Threat actors have abused a legitimate feature of the Google Tag Manager service to secretly add and deploy malicious JavaScript code to more than 300 eThe Record·Jan 20, 00:00 UTC · Jan 20, 2023Threat actor45
Mailchimp Suffers Another Security Breach Compromising Some Customers' InformationThe Hacker News·Jan 19, 05:38 UTC · Jan 19, 2023Data breach45
WordPress Security Alert: New Linux Malware Exploiting Over Two Dozen CMS FlawsThe Hacker News·Jan 17, 12:32 UTC · Jan 17, 2023MalwareCVE-2016-10972CVE-2019-17232CVE-2019-1723347
New Linux malware targets WordPress sites by exploiting 30 bugsSecurity Affairs·Dec 30, 21:36 UTC · Dec 30, 2022MalwareCVE-2016-10972CVE-2019-17232CVE-2019-1723347
What Developers Need to Fight the Battle Against Common VulnerabilitiesThe Hacker News·Dec 1, 11:17 UTC · Dec 1, 2022Vulnerability55
Secure your CMS-based websites against pervasive attacksHelp Net Security·Aug 23, 07:16 UTC · Aug 23, 2022Vulnerability30
Magecart Hacks Food Ordering Systems to Steal Payment Data from Over 300 RestaurantsThe Hacker News·Jul 25, 09:13 UTC · Jul 25, 2022Threat actor45
Newly Discovered Magecart Infrastructure Reveals the Scale of Ongoing CampaignThe Hacker News·Jun 22, 10:08 UTC · Jun 22, 2022Threat actor45
CMS-based sites under attack: The latest threats and trendsHelp Net Security·May 3, 00:00 UTC · May 3, 2022Vulnerability42
For Magecart groups and other credit-card skimmers, old and new opportunities aboundCyberScoop·Mar 21, 10:00 UTC · Mar 21, 2022Ransomware57
Crooks injects e-skimmers in random WordPress plugins of eSecurity Affairs·Dec 9, 14:46 UTC · Dec 9, 2021Vulnerability42
Small businesses urged to protect their customers from card skimmingHelp Net Security·Nov 23, 00:00 UTC · Nov 23, 2021Vulnerability30
TIM’s Red Team Research (RTR) discovered 2 new zero-day vulnerabilities in WordPress Plugin Limit Login Attempts ReloadedSecurity Affairs·Feb 3, 22:05 UTC · Feb 3, 2021Exploit / PoCCVE-2020-35590CVE-2020-3558960
Threat actors target WordPress sites using vulnerable File Manager installsSecurity Affairs·Sep 11, 21:01 UTC · Sep 11, 2020Threat actor60
e-Commerce Site Hackers Now Hiding Credit Card Stealer Inside Image MetadataThe Hacker News·Jun 30, 07:57 UTC · Jun 30, 2020Malware30
Over 800K WordPress sites are at risk due to a flaw in Ninja Forms pluginSecurity Affairs·May 1, 08:38 UTC · May 1, 2020Exploit / PoC in the wild60
100k+ WordPress sites exposed to hack due to a bug in RealSecurity Affairs·Apr 28, 09:03 UTC · Apr 28, 2020Exploit / PoC in the wild60
100K+ WordPress sites using the Contact Form 7 Datepicker plugin are exposed to hackSecurity Affairs·Apr 3, 08:50 UTC · Apr 3, 2020Exploit / PoC in the wild60