Security News

390,000 WordPress accounts stolen from hackers in supply chain attack
2024-12-14 15:17

A threat actor tracked as MUT-1244 has stolen over 390,000 WordPress credentials in a large-scale, year-long campaign targeting other threat actors using a trojanized WordPress credentials checker. [...]

390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits
2024-12-13 20:00

A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled the exfiltration of over 390,000...

WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins
2024-12-12 09:18

Malicious actors are exploiting a critical vulnerability in the Hunk Companion plugin for WordPress to install other vulnerable plugins that could open the door to a variety of attacks. The flaw,...

Hunk Companion WordPress plugin exploited to install vulnerable plugins
2024-12-11 23:28

Hackers are exploiting a critical vulnerability in the "Hunk Companion" plugin to install and activate other plugins with exploitable flaws directly from the WordPress.org repository. [...]

WPForms bug allows Stripe refunds on millions of WordPress sites
2024-12-10 20:00

A vulnerability in WPForms, a WordPress plugin used in over 6 million websites, could allow subscriber-level users to issue arbitrary Stripe refunds or cancel subscriptions. [...]

Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote Attacks
2024-11-26 13:23

Two critical security flaws impacting the Spam protection, Anti-Spam, and FireWall plugin WordPress could allow an unauthenticated attacker to install and enable malicious plugins on susceptible...

Urgent: Critical WordPress Plugin Vulnerability Exposes Over 4 Million Sites
2024-11-18 04:52

A critical authentication bypass vulnerability has been disclosed in the Really Simple Security (formerly Really Simple SSL) plugin for WordPress that, if successfully exploited, could grant an...

Security plugin flaw in millions of WordPress sites gives admin access
2024-11-17 15:19

A critical authentication bypass vulnerability has been discovered impacting the WordPress plugin 'Really Simple Security' (formerly 'Really Simple SSL'), including both free and Pro versions. [...]

LiteSpeed Cache WordPress plugin bug lets hackers get admin access
2024-10-31 16:19

The free version of the popular WordPress plugin LiteSpeed Cache has fixed a dangerous privilege elevation flaw on its latest release that could allow unauthenticated site visitors to gain admin...

LiteSpeed Cache Plugin Vulnerability Poses Significant Risk to WordPress Websites
2024-10-31 10:24

A high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could allow an unauthenticated threat actor to elevate their privileges and perform malicious...