Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

WordPress

20 articles

GBHackers general WordPress Sep 4

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote cod...

T1190 1 IOC

GBHackers → Details

Wordfence Blog vendor WordPress Sep 3

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated ...

T1190

Wordfence Blog → Details

BleepingComputer general WordPress Sep 3

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell pa...

T1190 1 IOC

BleepingComputer → Details

SC Media general WordPress Sep 3

SQL injection vulnerability in WordPress plugin affects millions of sites

The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110.

1 IOC

SC Media → Details

SecurityWeek general WordPress Sep 3

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPre...

T1190 1 IOC

SecurityWeek → Details

GBHackers general WordPress Sep 3

WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover

A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection v...

T1190 1 IOC

GBHackers → Details

BleepingComputer general WordPress Sep 2

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code an...

BleepingComputer → Details

Wordfence Blog vendor WordPress Sep 2

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more tha...

T1190

Wordfence Blog → Details

Wordfence Blog vendor WordPress Sep 1

5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin

On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordP...

Wordfence Blog → Details

GBHackers general WordPress Sep 1

WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited

The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the ...

GBHackers → Details

Security Affairs general WordPress Aug 31

Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers

A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.

1 IOC

Security Affairs → Details

BleepingComputer general WordPress Aug 28

GiveWP WordPress donation plugin flaw lets hackers execute server commands

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [.

BleepingComputer → Details

GBHackers general WordPress Aug 28

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to...

T1556 1 IOC

GBHackers → Details

Wordfence Blog vendor WordPress Aug 27

Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin

On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimat...

T1556

Wordfence Blog → Details

BleepingComputer general WordPress Aug 26

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the ...

BleepingComputer → Details

GBHackers general WordPress Aug 26

Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts

A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts...

1 IOC

GBHackers → Details

Security Affairs general WordPress Aug 25

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database.

T1556 2 IOCs

Security Affairs → Details

Wordfence Blog vendor WordPress Aug 25

400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin

On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400...

Wordfence Blog → Details

SecurityWeek general WordPress Aug 25

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.

T1556 2 IOCs

SecurityWeek → Details

SC Media general WordPress Aug 24

WordPress plugin vulnerabilities allow admin account takeover

The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication.

2 IOCs

SC Media → Details

«Previous page 1 2 3 4 5 6 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA