Wordfence·2d agoWordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)#wordpress#wordfence#vulnerability
The Hacker News·8d agoPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents#ai-agents#claude-code#codex 4 min1
GBHackers·8d ago highOver 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability#php-object-injection#plugin-security#rce 4 min4
SecurityWeek·10d ago highUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover#defiant#php-object-injection#plugin-security 2 min2
arXiv cs.CR·11d agoPlug 'n' Pray: Agentic LLM-based Detection of Potential Log File Exposures in Third-Party Content Management System Plugins#cms#llm-agents#log-exposureResearch
The Hacker News·12d agoWordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution#automated-review#jetpack-scan#plugin-security 3 min1
Wordfence·12d agoWordfence Bug Bounty Program Monthly Report – May 2026#bug-bounty#plugin-security#vulnerability-disclosure
Help Net Security·16d agoWordPress adds automated security checks to block risky plugin releases#automated-review#jetpack-scan#plugin-security 2 min
Wordfence·25d ago highWordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms#arbitrary-file-upload#gravity-forms#plugin-security
Wordfence·Aug 27, 2026 highWordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin#authentication-bypass#plugin-security#rce
The Hacker News·Aug 17, 2026 highForminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads#arbitrary-file-upload#authentication-bypass#forminator-forms 3 min