Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

WordPress

20 articles

SC Media general WordPress NEW 5h ago

WordPress plugin vulnerabilities allow admin account takeover

The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication.

2 IOCs

SC Media → Details

BleepingComputer general WordPress 8h ago

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can ...

T1556

BleepingComputer → Details

GBHackers general WordPress 20h ago

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete control o...

1 IOC

GBHackers → Details

Wordfence Blog vendor WordPress 3d ago

100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin

On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 a...

T1548

Wordfence Blog → Details

BleepingComputer general WordPress 4d ago

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [.

T1190

BleepingComputer → Details

Wordfence Blog vendor WordPress 4d ago

Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin

On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimate...

T1190

Wordfence Blog → Details

The Hacker News general WordPress 4d ago

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remo...

T1190 1 IOC

The Hacker News → Details

The Hacker News general WordPress 5d ago

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malw...

The Hacker News → Details

GBHackers general WordPress 5d ago

Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix

A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harves...

GBHackers → Details

Check Point Research research WordPress 6d ago

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. ...

Check Point Research → Details

SecurityWeek general WordPress 6d ago

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potent...

1 IOC

SecurityWeek → Details

The Hacker News general WordPress Aug 17

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to a...

1 IOC

The Hacker News → Details

Wordfence Blog vendor WordPress Aug 17

600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin

On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more tha...

Wordfence Blog → Details

Infosecurity Magazine general WordPress Aug 17

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts

Infosecurity Magazine → Details

Exploit Database advisories WordPress Aug 17

[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

WooCommerce 1.5.

Exploit Database → Details

Wordfence Blog vendor WordPress Aug 14

40,000 WordPress Sites affected by Authentication Bypass Vulnerability in User Profile Builder WordPress Plugin

On July 14th, 2026, we received a submission for an Authentication Bypass vulnerability in User Profile Builder, a WordPress plugin with more than 40,000 act...

T1556

Wordfence Blog → Details

SecurityWeek general WordPress Aug 13

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.

T1190

SecurityWeek → Details

GBHackers general WordPress Aug 13

WordPress RCE Vulnerability Lets Authenticated Authors Execute Remote Code

WordPress has released version 7.0.

T1190 1 IOC

GBHackers → Details

The Hacker News general WordPress Aug 11

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS)...

T1195 1 IOC

The Hacker News → Details

BleepingComputer general WordPress Aug 10

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delive...

BleepingComputer → Details

1 2 3 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA