Security News

WordPress security plugin WP Ghost vulnerable to remote code execution bug
2025-03-20 14:58

Popular WordPress security plugin WP Ghost is vulnerable to a critical severity flaw that could allow unauthenticated attackers to remotely execute code and hijack servers. [...]

Malware campaign 'DollyWay' breached 20,000 WordPress sites
2025-03-19 23:12

A malware operation dubbed 'DollyWay' has been underway since 2016, compromising over 20,000 WordPress sites globally to redirect users to malicious sites. [...]

Thousands of WordPress Websites Infected with Malware
2025-03-10 11:01

The malware includes four separate backdoors: Creating four backdoors facilitates the attackers having multiple points of re-entry should one be detected and removed. A unique case we haven’t seen...

Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker Access
2025-03-06 09:57

Over 1,000 websites powered by WordPress have been infected with a third-party JavaScript code that injects four separate backdoors. "Creating four backdoors facilitates the attackers having...

Critical zero-days impact premium WordPress real estate plugins
2025-01-22 22:59

The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow unauthenticated users to gain administrative privileges. [...]

W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks
2025-01-16 20:36

A severe flaw in the W3 Total Cache plugin installed on more than one million WordPress sites could give attackers access to various information, including metadata on cloud-based apps. [...]

WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites
2025-01-14 20:54

A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data. [...]

WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables
2025-01-13 06:40

Cybersecurity researchers are warning of a new stealthy credit card skimmer campaign that targets WordPress e-commerce checkout pages by inserting malicious JavaScript code into a database table...

Unpatched critical flaws impact Fancy Product Designer WordPress plugin
2025-01-08 21:34

Premium WordPress plugin Fancy Product Designer from Radykal is vulnerable to two critical severity flaws that remain unfixed in the current latest version. [...]

Premium WPLMS WordPress plugins address seven critical flaws
2024-12-23 16:59

Two WordPress plugins required by the premium WordPress WPLMS theme, which has over 28,000 sales, are vulnerable to more than a dozen critical-severity vulnerabilities. [...]