Security News

WPForms bug allows Stripe refunds on millions of WordPress sites
2024-12-10 20:00

A vulnerability in WPForms, a WordPress plugin used in over 6 million websites, could allow subscriber-level users to issue arbitrary Stripe refunds or cancel subscriptions. [...]

Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote Attacks
2024-11-26 13:23

Two critical security flaws impacting the Spam protection, Anti-Spam, and FireWall plugin WordPress could allow an unauthenticated attacker to install and enable malicious plugins on susceptible...

Urgent: Critical WordPress Plugin Vulnerability Exposes Over 4 Million Sites
2024-11-18 04:52

A critical authentication bypass vulnerability has been disclosed in the Really Simple Security (formerly Really Simple SSL) plugin for WordPress that, if successfully exploited, could grant an...

Security plugin flaw in millions of WordPress sites gives admin access
2024-11-17 15:19

A critical authentication bypass vulnerability has been discovered impacting the WordPress plugin 'Really Simple Security' (formerly 'Really Simple SSL'), including both free and Pro versions. [...]

LiteSpeed Cache WordPress plugin bug lets hackers get admin access
2024-10-31 16:19

The free version of the popular WordPress plugin LiteSpeed Cache has fixed a dangerous privilege elevation flaw on its latest release that could allow unauthenticated site visitors to gain admin...

LiteSpeed Cache Plugin Vulnerability Poses Significant Risk to WordPress Websites
2024-10-31 10:24

A high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could allow an unauthenticated threat actor to elevate their privileges and perform malicious...

WordPress forces user conf organizers to share social media credentials, arousing suspicions
2024-10-28 06:27

One told to take down posts that said nice things about WP Engine Organisers of WordCamps, community-organized events for WordPress users, have been ordered to take down some social media posts...

Over 6,000 WordPress hacked to install plugins pushing infostealers
2024-10-21 17:53

WordPress sites are being hacked to install malicious plugins that display fake software updates and errors to push information-stealing malware. [...]

Jetpack fixes 8-year-old flaw affecting millions of WordPress sites
2024-10-18 22:30

Also, new EU cyber reporting rules are live, exploiters hit the gas pedal, free PDNS for UK schools, and more in brief A critical security update for the near-ubiquitous WordPress plugin Jetpack...

WordPress Plugin Jetpack Patches Major Vulnerability Affecting 27 Million Sites
2024-10-15 04:56

The maintainers of the Jetpack WordPress plugin have released a security update to remediate a critical vulnerability that could allow logged-in users to access forms submitted by others on a...