Saturday, May 2, 2026
HomeWordPress

WordPress

Malicious Actors Exploit WordPress Sites to Redirect Users to Harmful Destinations

Last month, cybersecurity experts uncovered a sophisticated malware campaign targeting WordPress websites that stealthily redirects visitors to malicious domains. The threat actors embedded their malicious payload deep within core files, enabling search engine poisoning and unauthorized content injection without raising immediate alarms. A detailed...

200,000 Websites at Risk of Takeover Due to Severe WordPress Plugin Vulnerability

A critical security vulnerability has been discovered in the popular SureForms WordPress plugin, putting over 200,000 active installations at risk of complete website takeover. The flaw, designated CVE-2025-6691 with a high CVSS rating of 8.8, allows unauthenticated attackers to delete arbitrary files from affected...

Cyberattack Alert – NetSupport RAT Spreads Through Compromised WordPress Site Using ClickFix Exploit

Cybersecurity researchers at Cybereason's Global Security Operations Center (GSOC) have identified a sophisticated campaign in which threat actors exploit compromised WordPress websites to distribute malicious versions of the legitimate NetSupport Manager Remote Access Tool (RAT). The attack, detected in May 2025, employs a multi-stage...

WordPress Admins Alert: Beware of Fake SEO Plugins That Hijack Your Website

A sophisticated malware campaign targeting WordPress websites through fake plugins that cleverly disguise themselves using the victim's own domain name. This deceptive tactic allows the malicious software to evade detection while injecting SEO spam content designed to manipulate search engine rankings, particularly targeting Cialis-related...

WordPress Plugin Vulnerability Puts Over 600,000 Sites at Risk of Remote Takeover

A severe security vulnerability discovered in the popular Forminator WordPress plugin has left over 600,000 websites vulnerable to complete takeover by unauthenticated attackers. The vulnerability, designated CVE-2025-6463 with a critical CVSS rating of 8.8, allows malicious actors to delete arbitrary files from affected servers,...

Fake WordPress Caching Plugin Steals Admin Credentials, Experts Warn Site Owners

Cybersecurity analysts have issued a stark warning to WordPress site owners after uncovering a sophisticated fake caching plugin, dubbed wp-runtime-cache, that silently exfiltrates admin credentials. The malicious plugin, discovered during a routine malware scan, exploits WordPress’s plugin architecture and cleverly masks its presence, making detection...