Wordfence·1d agoWordfence Bug Bounty Program Monthly Report – June 2026#wordfence#wordpress#bug-bounty
Wordfence·2d agoWordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)#wordpress#wordfence#vulnerability
Cyber Security News·4d ago highWordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected#wordpress#malware#etherhiding 3 sources in the wild 6 min
Wordfence·4d ago highPSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core#wordpress#path-traversal#local-file-inclusion
Wordfence·8d ago highWordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server#code-execution#file-disclosure#heic 2 sources
Cyber Security News·8d ago highTutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution#cve-2026-78175#php-object-injection#plugin-vulnerability 4 min
GBHackers·8d ago highOver 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability#php-object-injection#plugin-security#rce 4 min4
Wordfence·9d ago high100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS#php-object-injection#plugin-vulnerability#remote-code-execution1
Wordfence·9d agoWordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)#plugins#vulnerability-disclosure#weekly-report
Infosecurity Magazine·10d ago highPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug#cve-2026-27540#file-upload#rce in the wild 2 min
The Hacker News·11d ago highAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells#arbitrary-file-upload#rce#the-events-calendar in the wild 3 min
BleepingComputer·11d ago highHackers target WordPress sites via third-party WooCommerce plugin#cve#file-upload#plugin in the wild 2 min2
GBHackers·11d ago highHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors#cve-2026-27540#file-upload#rce in the wild 4 min
Cyber Security News·11d ago highHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login#cve-2026-27540#file-upload#webshell in the wild 5 min
GBHackers·11d ago highWordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites#deserialization#events-calendar#php-object-injection 4 min
Cyber Security News·11d ago highCritical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover#php-object-injection#plugin#rce 3 min
Wordfence·12d ago highWordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin#events-calendar#plugin#rce
Wordfence·12d agoWordfence Bug Bounty Program Monthly Report – May 2026#bug-bounty#plugin-security#vulnerability-disclosure
GBHackers·16d agoWordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review#automated-review#backdoor#jetpack-scan 3 min1
Wordfence·16d agoWordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)#plugins#themes#vulnerability-report
Cyber Security News·16d agoWordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites#ai-scanning#jetpack-scan#plugin-updates 4 min1
Help Net Security·16d agoWordPress adds automated security checks to block risky plugin releases#automated-review#jetpack-scan#plugin-security 2 min
The Hacker News·22d ago highOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws#arbitrary-file-upload#elementor-pro#exploitation in the wild 4 min1