Security News

OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation
2025-04-11 04:58

A newly disclosed high-severity security flaw impacting OttoKit (formerly SureTriggers) has come under active exploitation within a few hours of public disclosure. The vulnerability, tracked as...

Hackers exploit WordPress plugin auth bypass hours after disclosure
2025-04-10 19:11

Hackers started exploiting a high-severity flaw that allows bypassing authentication in the OttoKit (formerly SureTriggers) plugin for WordPress just hours after public disclosure. [...]

Hackers abuse WordPress MU-Plugins to hide malicious code
2025-03-31 17:06

Hackers are utilizing the WordPress mu-plugins ("Must-Use Plugins") directory to stealthily run malicious code on every page while evading detection. [...]

Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site Images
2025-03-31 12:04

Threat actors are using the "mu-plugins" directory in WordPress sites to conceal malicious code with the goal of maintaining persistent remote access and redirecting site visitors to bogus sites....

The 4 WordPress flaws hackers targeted the most in Q1 2025
2025-03-27 16:29

A new report sheds light on the most targeted WordPress plugin vulnerabilities hackers used in the first quarter of 2025 to compromise sites. [...]

WordPress security plugin WP Ghost vulnerable to remote code execution bug
2025-03-20 14:58

Popular WordPress security plugin WP Ghost is vulnerable to a critical severity flaw that could allow unauthenticated attackers to remotely execute code and hijack servers. [...]

Malware campaign 'DollyWay' breached 20,000 WordPress sites
2025-03-19 23:12

A malware operation dubbed 'DollyWay' has been underway since 2016, compromising over 20,000 WordPress sites globally to redirect users to malicious sites. [...]

Thousands of WordPress Websites Infected with Malware
2025-03-10 11:01

The malware includes four separate backdoors: Creating four backdoors facilitates the attackers having multiple points of re-entry should one be detected and removed. A unique case we haven’t seen...

Over 1,000 WordPress Sites Infected with JavaScript Backdoors Enabling Persistent Attacker Access
2025-03-06 09:57

Over 1,000 websites powered by WordPress have been infected with a third-party JavaScript code that injects four separate backdoors. "Creating four backdoors facilitates the attackers having...

Critical zero-days impact premium WordPress real estate plugins
2025-01-22 22:59

The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow unauthenticated users to gain administrative privileges. [...]