WordPress security
Core and plugin vulnerabilities, backdoors, and account-takeover flaws across WordPress, the web's most-deployed CMS, plus the patches that actually matter.
WP Fastest Cache flaw lets attackers poison cached pages served to every WordPress visitor
WP Fastest Cache flaw CVE-2026-74916 lets attackers poison cached WordPress pages and hit every visitor with malicious script. Update to 1.5.1 and purge cache.
Five WordPress plugin and theme flaws let attackers take the site or the whole server
Wordfence and Patchstack disclosed five unauthenticated WordPress flaws rated 9.8 to 10.0. GiveWP and Avada run code on the host. Patch all five now.
LiteSpeed Cache flaw lets a planted comment run scripts in your visitors' browsers (CVE-2026-18978)
CVE-2026-18978 is a stored cross-site scripting flaw in the LiteSpeed Cache WordPress plugin.
Elementor Pro flaw (CVE-2026-32475) lets an unauthenticated attacker upload PHP and run code. Patch to 4.2.2.
Elementor Pro before 4.2.2 has a critical file upload flaw (CVE-2026-32475, CVSS 9.0) letting an unauthenticated attacker plant a PHP webshell. Patch now.
A flaw in the Mailgun for WordPress plugin lets a stranger take over the admin account (CVE-2026-78003)
A critical Mailgun for WordPress plugin flaw (CVE-2026-78003) lets unauthenticated attackers reroute password-reset emails and seize admin accounts. Fix: 2.2.1.
A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.
Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.
Forminator WordPress plugin flaw lets attackers run code with no login (CVE-2026-15748)
CVE-2026-15748 is a CVSS 9.8 unauthenticated file-upload RCE in the Forminator WordPress plugin. Affects versions up to 1.56.1. Update to 1.56.2 now.
Bookly WordPress plugin flaw lets an anonymous visitor run scripts in the admin's browser (CVE-2026-13424)
CVE-2026-13424 is an unauthenticated stored cross-site scripting flaw in the Bookly WordPress booking plugin.
BdThemes WordPress plugins were hijacked to plant hidden admin accounts and a webshell
A supply-chain attack poisoned a data feed in BdThemes WordPress plugins to create hidden admin accounts and drop a webshell.
WordPress login-page XSS can chain to code execution, patch 7.0.3
WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth login-page XSS that runs attacker code from one failed login and can chain to server code execution. Patch now.
A link an admin clicks can create a rogue WordPress admin via the AI Engine plugin (CVE-2026-15988)
CVE-2026-15988 lets an attacker create a new WordPress administrator on sites running AI Engine 3.6.5 or earlier if a logged-in admin clicks one link.
A public exploit lets a stranger log in as WordPress admin through miniOrange's single sign-on plugin
A public exploit for CVE-2026-15981 lets unauthenticated attackers log in as any WordPress admin via the miniOrange SAML SSO plugin. Update to 5.4.5 now.
WPForms Pro flaw lets a stranger upload a file and run code on your WordPress site. Patch now.
A flaw in WPForms Pro (CVE-2026-10818) lets unauthenticated attackers upload executable files to WordPress sites on versions up to 1.10.1.1 and run code.
wp2shell went from patch to public exploit in a day. Patching is no longer enough.
Public proof-of-concept exploits for the wp2shell WordPress Core RCE (CVE-2026-63030) are live and the mechanism is disclosed.
A stranger with no login can take over WordPress sites on 6.9 and 7.0. Patch now.
WordPress Core 6.9 and 7.0 carry wp2shell (CVE-2026-63030), an unauthenticated remote code execution flaw. Update to 6.9.5 or 7.0.2 right away, then hunt.
Mass CMS campaign turns unpatched plugins into webshells
Australia's cyber agency warns of a global campaign mass-exploiting 16 known CMS and plugin flaws to drop webshells on WordPress, Joomla and Craft sites.
A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.
An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.
Super Forms flaw lets anyone take over a WordPress site, and a working exploit is now public
A critical flaw (CVSS 9.8) in the Super Forms WordPress plugin lets unauthenticated attackers run code on the server.
The free plugin was clean. The paid update is what backdoored these WordPress sites.
Backdoored ShapedPlugin Pro updates stole admin logins and 2FA seeds from WordPress sites between April and June 2026. A password reset alone will not clear it.
On 200,000 WordPress sites, a low-level user can quietly steal the admin's login
A contributor-level user can make Ultimate Member leak every user's password reset link, admins included. Affects versions through 2.11.4; fixed in 2.12.0.
Gravity SMTP's 'medium' bug leaks live email API keys to anyone. Patching alone will not save you.
Gravity SMTP's CVE-2026-4020 hands live Amazon SES, Google, and OAuth keys to unauthenticated visitors on 100,000 WordPress sites.
Police scrubbed SocGholish from 15,000 WordPress sites. The way in is still wide open.
Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector.
Branda fixed this WordPress account takeover in January. It is back, and a public exploit is circulating.
CVE-2026-11551 is a CVSS 9.8 unauthenticated account takeover in the Branda WordPress plugin (versions up to 3.4.29). A public exploit is out.
A WordPress form plugin lets a stranger delete your site, the moment an admin looks
CVE-2026-9843 lets an unauthenticated visitor plant a form entry that deletes WordPress files when an admin opens it.
Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.
OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.