Saturday, April 11, 2026
HomeWordPress

WordPress

Critical Elementor Security Breach Leaves WordPress Sites Open To Admin Takeovers

Attackers exploit a critical privilege escalation flaw in the King Addons for Elementor WordPress plugin, allowing unauthenticated users to create administrator accounts and seize control of sites. This vulnerability, tracked as CVE-2025-8489 with a CVSS score of 9.8, affects over 10,000 installations and has...

PoC Published for W3 Total Cache Flaw Putting 1M+ Websites At Risk Of Remote Code Execution

Security researchers released a proof-of-concept exploit for CVE-2025-9501, a critical unauthenticated remote code execution flaw in the W3 Total Cache WordPress plugin. This vulnerability affects over 1 million sites and allows attackers to run arbitrary PHP code via simple comments.​ Vulnerability Breakdown The flaw affects versions...

1 Million WordPress Sites At Risk Of RCE Attacks Due To W3 Total Cache Command Injection Vulnerability

A critical security flaw in the popular W3 Total Cache WordPress plugin has exposed over one million websites to remote code execution attacks, allowing hackers to run malicious commands without logging in. This vulnerability, tracked as CVE-2025-9501, affects versions before 2.8.13 and was publicly...

WordPress Theme RCE Vulnerability Actively Exploited to take Full Site Control

A critical security vulnerability in the popular "Alone" WordPress theme has been actively exploited by cybercriminals to gain complete control of vulnerable websites. The vulnerability, which affects a theme with over 9,000 sales, allows unauthenticated attackers to upload malicious files and execute remote...

WordPress Post SMTP Plugin Vulnerability Exposes 400K Websites to Account Takeover Attacks

A critical security vulnerability in the popular Post SMTP WordPress plugin has left over 400,000 websites exposed to potential account takeover attacks, allowing even the lowest-privileged users to gain administrator access and achieve full site control. The vulnerability, tracked as CVE-2025-24000, stems from broken...

Attackers Gain Persistent Access to Websites Through Stealthy Backdoor in WordPress Plugins

Security researchers have uncovered a sophisticated WordPress malware campaign that exploits the rarely monitored mu-plugins directory to establish persistent backdoors on compromised websites. The malicious code, discovered in the file wp-content/mu-plugins/wp-index.php, represents a significant evolution in WordPress attack techniques, utilizing database storage and ROT13 obfuscation...