WordPress

Critical Elementor Security Breach Leaves WordPress Sites Open To Admin Takeovers

Attackers exploit a critical privilege escalation flaw in the King Addons for Elementor WordPress plugin, allowing unauthenticated users to create…

5 months ago

PoC Published for W3 Total Cache Flaw Putting 1M+ Websites At Risk Of Remote Code Execution

Security researchers released a proof-of-concept exploit for CVE-2025-9501, a critical unauthenticated remote code execution flaw in the W3 Total Cache…

5 months ago

1 Million WordPress Sites At Risk Of RCE Attacks Due To W3 Total Cache Command Injection Vulnerability

A critical security flaw in the popular W3 Total Cache WordPress plugin has exposed over one million websites to remote…

5 months ago

WordPress Theme RCE Vulnerability Actively Exploited to take Full Site Control

A critical security vulnerability in the popular "Alone" WordPress theme has been actively exploited by cybercriminals to gain complete control…

9 months ago

WordPress Post SMTP Plugin Vulnerability Exposes 400K Websites to Account Takeover Attacks

A critical security vulnerability in the popular Post SMTP WordPress plugin has left over 400,000 websites exposed to potential account…

9 months ago

Attackers Gain Persistent Access to Websites Through Stealthy Backdoor in WordPress Plugins

Security researchers have uncovered a sophisticated WordPress malware campaign that exploits the rarely monitored mu-plugins directory to establish persistent backdoors…

9 months ago

Malicious Actors Exploit WordPress Sites to Redirect Users to Harmful Destinations

Last month, cybersecurity experts uncovered a sophisticated malware campaign targeting WordPress websites that stealthily redirects visitors to malicious domains. The…

10 months ago

200,000 Websites at Risk of Takeover Due to Severe WordPress Plugin Vulnerability

A critical security vulnerability has been discovered in the popular SureForms WordPress plugin, putting over 200,000 active installations at risk…

10 months ago

Cyberattack Alert – NetSupport RAT Spreads Through Compromised WordPress Site Using ClickFix Exploit

Cybersecurity researchers at Cybereason's Global Security Operations Center (GSOC) have identified a sophisticated campaign in which threat actors exploit compromised…

10 months ago

WordPress Admins Alert: Beware of Fake SEO Plugins That Hijack Your Website

A sophisticated malware campaign targeting WordPress websites through fake plugins that cleverly disguise themselves using the victim's own domain name.…

10 months ago