Threats Tagged 'wordpress'
View all threats tagged with 'wordpress'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'wordpress'
Click on any threat for detailed analysis and mitigation recommendations
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...] Join the discussion | Bleeping Computer | 09/25/2026, 18:13:33 UTC Added: 09/25/2026, 19:02:49 UTC |
A critical vulnerability has been discovered in the popular WordPress content management system that allows attackers to execute arbitrary code on the web server. The vulnerability has been assigned the number CVE-2026-87902. The good news is that on September 22, WordPress released an update that patches it. The bad news is that the first attempts to exploit CVE-2026-87902 were detected just a few hours after the patch was released. Therefore, all companies whose corporate websites or blogs run on this platform are advised to update immediately. WordPress versions affected by CVE-2026-87902 According to data published by WordPress on GitHub, all versions of the CMS from 4.7.0 through 7.1.1 are vulnerable. The company has released updates for all supported branches of the system; a complete table listing the patched version numbers can be found on the company’s GitHub page . The latest version of WordPress should be updated to version 7.1.2 (or newer). What’s the nature of the CVE-2026-87902 vulnerability, and why is it so dangerous? Under normal circumstances, WordPress loads PHP template files only from a specific folder within the active theme. However, due to the CVE-2026-87902 vulnerability, an attacker can craft a request to WordPress in such a way that an arbitrary PHP file is included — without requiring any authorization. Yes, the file must already be uploaded to the targeted server in some way, but that’s not really a problem for an attacker. It sounds like a path traversal vulnerability, but in most publications, CVE-2026-87902 is classified as an RCE (Remote Code Execution) vulnerability because, under certain WordPress and PHP server configurations, the attack can lead to the execution of arbitrary code. How to stay safe The only way to secure a corporate WordPress site is to install the latest version. The researcher who discovered the vulnerability also offers several tips for hardening CMS security, but emphasizes that these are meant to complement the patch, not replace it. The Hacker News lists several PHP filenames and IP addresses used in the attack via CVE-2026-87902. These can serve as indicators that a WordPress instance has been compromised. Given that only a few hours pass between the publication of information about a vulnerability’s existence and the start of attacks exploiting it, it’s crucial for companies to have a properly configured, centralized vulnerability management system. To achieve this, they should have a specialized solution capable of identifying and resolving vulnerabilities, prioritizing them based on actual risks, and automating remediation processes. Join the discussion | Bleeping Computer | 09/25/2026, 15:23:46 UTC Added: 09/23/2026, 18:47:50 UTC |
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...] Join the discussion | Bleeping Computer | 09/22/2026, 20:35:24 UTC Added: 09/22/2026, 21:02:47 UTC |
WordPress patched a vulnerability called Click2Shell that allowed attackers to automatically install and preview inactive themes via specially crafted URLs. This flaw could lead to remote code execution (RCE) by abusing how theme slugs are interpreted differently by the themes API and JavaScript in an administrator's browser. Attackers could force installation of attacker-selected themes fetched from the official WordPress.org catalog without administrator consent. Some inactive third-party themes could be exploited for PHP code execution during the Customizer preview, enabling attackers to execute code under the WordPress server account without needing an attacker WordPress account. The vulnerability was fixed in WordPress version 7.1.1 and backported to versions as early as 4.7. Join the discussion | SecurityWeek | 09/22/2026, 10:22:27 UTC Added: 09/22/2026, 10:32:45 UTC |
Click2Shell is a cross-site request forgery (CSRF) vulnerability in WordPress Core up to version 7.1.0 that allows unauthenticated attackers to execute arbitrary PHP code on the server by forcing the installation of a theme from the official WordPress.org catalog. The attack requires a logged-in administrator to visit a crafted URL, which triggers the execution of PHP code via an inactive theme during a Customizer preview. This vulnerability was fixed in WordPress version 7.1.1 by escaping the theme slug and restricting jQuery selectors. The flaw enables remote code execution that could lead to file manipulation, data access, and creation of rogue admin accounts. Join the discussion | Bleeping Computer | 09/21/2026, 18:23:11 UTC Added: 09/21/2026, 18:31:40 UTC |
This security news roundup highlights multiple cybersecurity developments including a critical SAP vulnerability (CVE-2026-44756) allowing unauthenticated memory corruption, a WordPress plugin file-upload flaw enabling mass webshell uploads, and a zero-click Plugin4Shell vulnerability affecting AI coding assistants that permits silent malicious plugin updates. Additionally, it covers the sentencing of a ransomware developer, new malware linked to bug bounty hunting, and other notable cybercrime and defense updates. Join the discussion | SecurityWeek | 09/18/2026, 14:25:00 UTC Added: 09/18/2026, 14:31:43 UTC |
Two critical unauthenticated remote code execution (RCE) vulnerabilities affect The Events Calendar WordPress plugin versions before 6.17.3.1 and 6.17.4.1. These flaws allow attackers to execute arbitrary code and potentially take over affected WordPress sites. The first vulnerability (CVE-2026-78159) involves unauthenticated code injection via insufficient validation, patched in version 6.17.3.1. The second (CVE-2026-78006) is an unauthenticated PHP object injection exploitable if event comments are enabled, fixed in version 6.17.4.1. Approximately 240,000 sites using vulnerable versions may be exposed, though exploitation requires comments to be enabled. Both vulnerabilities lead to full site compromise if exploited. Join the discussion | SecurityWeek | 09/16/2026, 11:32:53 UTC Added: 09/16/2026, 11:46:36 UTC |
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...] Join the discussion | Bleeping Computer | 09/15/2026, 20:34:15 UTC Added: 09/15/2026, 20:46:38 UTC |
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...] Join the discussion | Bleeping Computer | 09/15/2026, 14:45:10 UTC Added: 09/15/2026, 15:16:37 UTC |
0 CVE-2026-32475 is a critical vulnerability in the Elementor Pro WordPress plugin that allows unrestricted upload of files with dangerous types through the form submission handling function. This arbitrary file upload flaw can lead to complete compromise of confidentiality, integrity, and availability of affected sites. The vulnerability has a high CVSS score of 9.8, indicating severe impact if exploited. Join the discussion | CVE Database V5 | 09/05/2026, 13:00:28 UTC Added: 08/19/2026, 17:43:13 UTC |
Showing 1 to 10 of 69 results