Attackers Hijack Popular WordPress Plugins to Deploy BackdoorsInfosecurity Magazine·Jun 15, 17:00 UTC · Jun 15, 2026Malware42
Attackers compromised Awesome Motive CDN files, backdooring WordPress sites running OptinMonster, TrustPulse, and PushEngageSecurity Affairs·Jun 15, 08:52 UTC · Jun 15, 2026Malware42
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPsThe Hacker News·May 6, 08:34 UTC · May 6, 2026Malware30
Critical SQL Injection bug in Ally plugin threatens 400,000+ WordPress sitesSecurity Affairs·Mar 12, 13:25 UTC · Mar 12, 2026VulnerabilityCVE-2026-241360
Critical Flaws in WordPress Plugin Leave 10,000 Sites VulnerableInfosecurity Magazine·Jul 28, 16:05 UTC · Jul 28, 2025VulnerabilityCVE-2025-7340CVE-2025-7341CVE-2025-736060
Hackers Deploy Stealth Backdoor in WordPress MuThe Hacker News·Jul 24, 05:11 UTC · Jul 24, 2025Malware42
OttoKit WordPress Plugin with 100K+ Installs Hit by Exploits Targeting Multiple FlawsThe Hacker News·Jul 18, 04:54 UTC · Jul 18, 2025Exploit / PoC in the wildCVE-2025-27007CVE-2025-310260
Major WordPress Plugin Flaw Exploited in Under 4 HoursInfosecurity Magazine·Apr 14, 16:00 UTC · Apr 14, 2025Vulnerability in the wild60
A flaw in the W3 Total Cache plugin exposes hundreds of thousands of WordPress sites to attacksSecurity Affairs·Jan 19, 19:20 UTC · Jan 19, 2025VulnerabilityCVE-2024-1236535
New EAGERBEE Variant Targets ISPs and Governments with Advanced Backdoor CapabilitiesThe Hacker News·Jan 7, 12:33 UTC · Jan 7, 2025MalwareCVE-2021-2685547
WordPress plugin Jetpack fixes nearly decadeThe Record·Oct 15, 14:11 UTC · Oct 15, 2024Exploit / PoC in the wild60
WordPress LiteSpeed Cache Plugin Security Flaw Exposes Sites to XSS AttacksThe Hacker News·Oct 7, 06:13 UTC · Oct 7, 2024VulnerabilityCVE-2024-47374CVE-2024-44000CVE-2024-43917+2 CVEs60
WordPress LiteSpeed Cache plugin flaw could allow site takeoverSecurity Affairs·Oct 5, 13:49 UTC · Oct 5, 2024VulnerabilityCVE-2024-47374CVE-2024-4400047
Litespeed Cache Plugin Flaw Allows XSS Attack, Update NowInfosecurity Magazine·Oct 3, 17:30 UTC · Oct 3, 2024VulnerabilityCVE-2024-4737435
Critical WPML Plugin Flaw Exposes WordPress Sites to Remote Code ExecutionThe Hacker News·Aug 31, 15:15 UTC · Aug 31, 2024VulnerabilityCVE-2024-638660
Unveiling SpiceRAT: SneakyChef's latest tool targeting EMEA and AsiaCisco Talos·Jun 21, 12:00 UTC · Jun 21, 2024Malware30
Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress SitesThe Hacker News·Apr 27, 04:59 UTC · Apr 27, 2024VulnerabilityCVE-2024-27956CVE-2024-2876CVE-2024-28890+2 CVEs160
A flaw in the Forminator plugin impacts hundreds of thousands of WordPress sitesSecurity Affairs·Apr 22, 06:58 UTC · Apr 22, 2024VulnerabilityCVE-2024-28890CVE-2024-31077CVE-2024-3185760
Malware Campaign Exploits Popup Builder WordPress Plugin to Infect 3,900+ SitesThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2024MalwareCVE-2023-6000CVE-2024-2123CVE-2024-1071+1 CVEs47
XSS flaw in LiteSpeed Cache plugin exposes millions of WordPress sites at riskSecurity Affairs·Feb 27, 15:29 UTC · Feb 27, 2024VulnerabilityCVE-2023-4000047
Flaw in AI Plugin Exposes 50,000 WordPress Sites to Remote AttackInfosecurity Magazine·Jan 9, 16:45 UTC · Jan 9, 2024VulnerabilityCVE-2023-5140960
Researchers Uncover Malware Posing as WordPress Caching PluginThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2023Malware42
Critical flaw found in the WooCommerce Stripe Gateway PluginSecurity Affairs·Jun 14, 13:32 UTC · Jun 14, 2023VulnerabilityCVE-2023-3400060
Hackers are actively exploiting a flaw in Elementor Pro WordPress pluginSecurity Affairs·Mar 31, 20:36 UTC · Mar 31, 2023Exploit / PoC in the wild60
Experts warn of attacks exploiting WordPress gift card pluginSecurity Affairs·Dec 25, 19:42 UTC · Dec 25, 2022VulnerabilityCVE-2022-4535960
Over 280,000 WordPress Sites Attacked Using WPGateway Plugin ZeroThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2022Exploit / PoC in the wildCVE-2022-318060
Hackers Planted Secret Backdoor in Dozens of WordPress Plugins and ThemesThe Hacker News·Jan 22, 07:39 UTC · Jan 22, 2022MalwareCVE-2021-24867CVE-2022-021847
A flaw in The Plus Addons for Elementor WordPress plugin allows sites takeoverSecurity Affairs·Mar 10, 09:20 UTC · Mar 10, 2021Exploit / PoC in the wild60
Critical flaws in NextGen Gallery WordPress plugin still impact over 500K installsSecurity Affairs·Feb 9, 15:18 UTC · Feb 9, 2021VulnerabilityCVE-2020-3594260
Vulnerability Spotlight: Multiple vulnerabilities in Genivia gSOAPCisco Talos·Jan 5, 17:22 UTC · Jan 5, 2021Vulnerability in the wildCVE-2020-13574CVE-2020-13575CVE-2020-13576+2 CVEs60
WordPress Easy WP SMTP zero-day potentially exposes hundreds of thousands of sites to hackSecurity Affairs·Dec 12, 12:09 UTC · Dec 12, 2020Exploit / PoC60
Flaws in WordPress Ultimate Member plugin expose 25K sites to hackSecurity Affairs·Nov 10, 18:50 UTC · Nov 10, 2020Vulnerability55
Vulnerabilities Affect 100,000 Sites Using WordPress PluginInfosecurity Magazine·Nov 10, 17:32 UTC · Nov 10, 2020Vulnerability55
Critical Bug in WordPress Theme Plugin Opens 200,000 Sites to HackersThe Hacker News·Feb 17, 22:09 UTC · Feb 17, 2020Vulnerability55
Modular Plurox backdoor can spread over local networkSecurity Affairs·Jun 19, 07:02 UTC · Jun 19, 2019Malware42
Serious flaw found and patched in WordPress, but it might lurk in pluginsCyberScoop·Feb 19, 20:38 UTC · Feb 19, 2019Vulnerability in the wild60
WordPress plugin patches flaw that gave hackers potential access to 40,000 websitesCyberScoop·Feb 12, 14:32 UTC · Feb 12, 2019Vulnerability in the wild60
Flaw in WordPress plugin allowed unauthorized admin access, backdoorsCyberScoop·Nov 12, 16:01 UTC · Nov 12, 2018Malware in the wild60
Vulnerability Spotlight: Multiple Issues in Foxit PDF ReaderCisco Talos·Oct 1, 16:59 UTC · Oct 1, 2018VulnerabilityCVE-2018-3956CVE-2018-3957CVE-2018-3958+12 CVEs35