Security News

Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers
2025-05-01 15:47

Cybersecurity researchers have shed light on a new campaign targeting WordPress sites that disguises the malware as a security plugin. The plugin, which goes by the name "WP-antymalwary-bot.php,"...

WordPress plugin disguised as a security tool injects backdoor
2025-04-30 21:05

A new malware campaign targeting WordPress sites employs a malicious plugin disguised as a security tool to trick users into installing and trusting it. [...]

WordPress ad-fraud plugins generated 1.4 billion ad requests per day
2025-04-21 13:00

A large-scale ad fraud operation called 'Scallywag' is monetizing pirating and URL shortening sites through specially crafted WordPress plugins that generate billions of daily fraudulent requests. [...]

OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation
2025-04-11 04:58

A newly disclosed high-severity security flaw impacting OttoKit (formerly SureTriggers) has come under active exploitation within a few hours of public disclosure. The vulnerability, tracked as...

Hackers exploit WordPress plugin auth bypass hours after disclosure
2025-04-10 19:11

Hackers started exploiting a high-severity flaw that allows bypassing authentication in the OttoKit (formerly SureTriggers) plugin for WordPress just hours after public disclosure. [...]

Hackers abuse WordPress MU-Plugins to hide malicious code
2025-03-31 17:06

Hackers are utilizing the WordPress mu-plugins ("Must-Use Plugins") directory to stealthily run malicious code on every page while evading detection. [...]

Hackers Exploit WordPress mu-Plugins to Inject Spam and Hijack Site Images
2025-03-31 12:04

Threat actors are using the "mu-plugins" directory in WordPress sites to conceal malicious code with the goal of maintaining persistent remote access and redirecting site visitors to bogus sites....

The 4 WordPress flaws hackers targeted the most in Q1 2025
2025-03-27 16:29

A new report sheds light on the most targeted WordPress plugin vulnerabilities hackers used in the first quarter of 2025 to compromise sites. [...]

WordPress security plugin WP Ghost vulnerable to remote code execution bug
2025-03-20 14:58

Popular WordPress security plugin WP Ghost is vulnerable to a critical severity flaw that could allow unauthenticated attackers to remotely execute code and hijack servers. [...]

Malware campaign 'DollyWay' breached 20,000 WordPress sites
2025-03-19 23:12

A malware operation dubbed 'DollyWay' has been underway since 2016, compromising over 20,000 WordPress sites globally to redirect users to malicious sites. [...]