Security News

Critical zero-days impact premium WordPress real estate plugins
2025-01-22 22:59

The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow unauthenticated users to gain administrative privileges. [...]

W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks
2025-01-16 20:36

A severe flaw in the W3 Total Cache plugin installed on more than one million WordPress sites could give attackers access to various information, including metadata on cloud-based apps. [...]

WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites
2025-01-14 20:54

A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data. [...]

WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables
2025-01-13 06:40

Cybersecurity researchers are warning of a new stealthy credit card skimmer campaign that targets WordPress e-commerce checkout pages by inserting malicious JavaScript code into a database table...

Unpatched critical flaws impact Fancy Product Designer WordPress plugin
2025-01-08 21:34

Premium WordPress plugin Fancy Product Designer from Radykal is vulnerable to two critical severity flaws that remain unfixed in the current latest version. [...]

Premium WPLMS WordPress plugins address seven critical flaws
2024-12-23 16:59

Two WordPress plugins required by the premium WordPress WPLMS theme, which has over 28,000 sales, are vulnerable to more than a dozen critical-severity vulnerabilities. [...]

390,000 WordPress accounts stolen from hackers in supply chain attack
2024-12-14 15:17

A threat actor tracked as MUT-1244 has stolen over 390,000 WordPress credentials in a large-scale, year-long campaign targeting other threat actors using a trojanized WordPress credentials checker. [...]

390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC Exploits
2024-12-13 20:00

A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled the exfiltration of over 390,000...

WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable Plugins
2024-12-12 09:18

Malicious actors are exploiting a critical vulnerability in the Hunk Companion plugin for WordPress to install other vulnerable plugins that could open the door to a variety of attacks. The flaw,...

Hunk Companion WordPress plugin exploited to install vulnerable plugins
2024-12-11 23:28

Hackers are exploiting a critical vulnerability in the "Hunk Companion" plugin to install and activate other plugins with exploitable flaws directly from the WordPress.org repository. [...]