WordPress.org to require two-factor authentication for plugin developersCyberScoop·Sep 11, 19:12 UTC · Sep 11, 2024Threat actor57
WordPress Mandates Two-Factor Authentication for Plugin and Theme DevelopersThe Hacker News·Sep 12, 04:57 UTC · Sep 12, 2024Vulnerability42
Compromised plugins found on WordPress.orgHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2024Vulnerability42
Backdoor slipped into multiple WordPress plugins in ongoing supplyArs Technica · Security·Jun 24, 21:00 UTC · Jun 24, 2024Malware42
ShapedPlugin Supply Chain Attack Backdoors Pro Plugin UpdatesSecurity Affairs·Jun 23, 08:23 UTC · Jun 23, 2026Malware42
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress AdminsThe Hacker News·Aug 11, 05:48 UTC · Aug 11, 2026VulnerabilityCVE-2026-18072CVE-2026-6463847
WordPress announces bug bounty programHelp Net Security·Nov 21, 07:55 UTC · Nov 21, 2023Vulnerability42
Tens of AccessPress WordPress themes compromised as part of a supply chain attackSecurity Affairs·Jan 24, 20:33 UTC · Jan 24, 2022VulnerabilityCVE-2021-2486747
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain AttackThe Hacker News·Jul 7, 11:22 UTC · Jul 7, 2026MalwareCVE-2026-10735CVE-2026-4977747
Fake SEO plugin backdoors WordPress installationsHelp Net Security·Aug 6, 13:01 UTC · Aug 6, 2019Malware42
Backdoored Display Widgets Plugin potentially affects 200,000 WordPress installs abusing them to spam contentSecurity Affairs·Oct 3, 13:55 UTC · Oct 3, 2017Malware42
Forcepoint spotted the modular Felismus RAT, it appears the work of skilled professionals.Security Affairs·Apr 2, 13:34 UTC · Apr 2, 2017Malware42