Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

WordPress

20 articles

BleepingComputer general WordPress 2d ago

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooComme...

BleepingComputer → Details

GBHackers general WordPress 3d ago

Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads

A critical heap-buffer-overflow vulnerability in libheif could allow authenticated WordPress users to achieve remote code execution by uploading a specially ...

T1190

GBHackers → Details

The Hacker News general WordPress Oct 1

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final ...

The Hacker News → Details

GBHackers general WordPress Oct 1

SC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence

A newly analyzed WordPress malware family, tracked as SC for the “SC_” markers embedded in its injected code, uses a self-healing persistence mesh that can r...

T1190

GBHackers → Details

Exploit Database advisories WordPress Oct 1

[webapps] WordPress 7.0.2 - Path Travesal

WordPress 7.0.

Exploit Database → Details

SANS ISC advisories WordPress Sep 29

Scans for Wordfence Protected Websites, (Tue, Sep 29th)

Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php".

SANS ISC → Details

The Hacker News general WordPress Sep 26

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated atta...

The Hacker News → Details

Security Affairs general WordPress Sep 26

U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog

U.S.

1 IOC

Security Affairs → Details

BleepingComputer general WordPress Sep 25

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accou...

BleepingComputer → Details

CISA Advisories advisories WordPress Sep 25

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-87902 WordPress...

1 IOC

CISA Advisories → Details

CSO Online enterprise WordPress Sep 24

WordPress patches a critical severity security vulnerability

WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution...

T1190 1 IOC

CSO Online → Details

SecurityWeek general WordPress Sep 24

Critical WordPress Vulnerability Exploited Immediately After Disclosure

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerabil...

1 IOC

SecurityWeek → Details

The Hacker News general WordPress Sep 24

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-20...

T1190 1 IOC

The Hacker News → Details

BleepingComputer general WordPress Sep 23

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands ...

1 IOC

BleepingComputer → Details

The Hacker News general WordPress Sep 23

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company s...

The Hacker News → Details

GBHackers general WordPress Sep 23

Critical WordPress Flaw Lets Unauthenticated Attackers Execute Remote Code

WordPress has released version 7.1.

T1190 1 IOC

GBHackers → Details

Help Net Security general WordPress Sep 23

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

WordPress released version 7.1.

1 IOC

Help Net Security → Details

Security Affairs general WordPress Sep 23

CVE-2026-87902: how close is your WordPress to remote code execution?

WordPress 7.1.

T1190 1 IOC

Security Affairs → Details

GBHackers general WordPress Sep 23

Stealthy WordPress Malware Uses Must-Use Plugin and Ethereum EtherHiding for Persistent Backdoor Access

A newly analyzed WordPress malware implant combines must-use plugin persistence, hidden administrator accounts, credential theft, cross-site propagation, and...

T1078

GBHackers → Details

SC Media general WordPress Sep 22

New Exvicy malware-as-a-service framework copies rival's code

Exvicy operates as a ClickFix framework, distributing malware through compromised WordPress websites, according to Sekoia's Threat Detection & Research t...

T1588

SC Media → Details

1 2 3 ... 6 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA