Patchstack·21h ago highCross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites#elementor#wordpress#csrf 3 sources 9 min
Cyber Security News·23h ago criticalHackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code#wordpress#cve-2026-87902#local-file-inclusion 16 sources in the wild 3 min5
Wordfence·1d agoWordfence Bug Bounty Program Monthly Report – June 2026#wordfence#wordpress#bug-bounty
BleepingComputer·1d ago highWordPress Click2Shell flaw lets hackers execute PHP on the server#wordpress#click2shell#csrf 6 sources 3 min
CISA Advisories·1d ago highCISA Adds One Known Exploited Vulnerability to Catalog#bod-26-04#cisa#cve-2026-87902CVE-2026-87902 in the wild
Wordfence·2d agoWordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)#wordpress#wordfence#vulnerability
The Hacker News·2d ago highNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control#cpanel#whm#wp-toolkit 6 sources 3 min
Infosecurity Magazine·3d agoNew Exvicy ClickFix Framework Built on Rival ErrTraffic's Code#exvicy#clickfix#errtraffic 2 sources in the wild 2 min
Cyber Security News·4d ago highWordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected#wordpress#malware#etherhiding 3 sources in the wild 6 min1
Wordfence·4d ago highPSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core#wordpress#path-traversal#local-file-inclusion
BleepingComputer·4d ago highChinese hackers exploit WordPress, Zyxel flaws to steal govt data#red-heron#wordpress#zyxel in the wild 3 min1
Hacker News · security·4d ago highWordPress: Unauthenticated path traversal leading to conditional RCE#wordpress#path-traversal#rceVulnerability
GBHackers·4d ago criticalHackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data#breach#chinese-threat-actor#cve-2026-60137 2 sources in the wild 5 min2
Cyber Security News·6d ago criticalWeekly Cybersecurity Newsletter Bulletin – Cisco and Android 0-Day, BragJack Attack, Claude Opus 5 Used to Hack OpenAI, and 20+ Stories#cisco#ise#zero-day in the wild 14 min2
GreyNoise·6d ago highOpen Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation#apt#china#cve-2026-63030 in the wild 15 min
Cyber Security News·8d ago highClick2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link#click2shell#csrf#exploit-chain 4 min1
Security Affairs·8d ago criticalBrevo Supply-Chain Attack Infected Over 100,000 Websites#brevo#clickfix#cloudflare in the wild 4 min2
Patchstack·8d ago highClick2Shell: The RCE WordPress 7.1.1 Just Patched#click2shell#csrf#jquery 4 min1
Wordfence·8d ago highWordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server#code-execution#file-disclosure#heic 2 sources
TechCrunch · AI·8d agoAutomattic’s 33-Hour Coup, and can AI labs police themselves?#ai-safety#anthropic#automattic 3 min
The Hacker News·8d ago highNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution#click2shell#csrf#patch 3 min2
SecurityWeek·8d agoIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw#ai-agents#info-stealer#ransomware in the wild 5 min2
Cyber Security News·8d ago highTutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution#cve-2026-78175#php-object-injection#plugin-vulnerability 4 min
GBHackers·8d ago highOver 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability#php-object-injection#plugin-security#rce 4 min4