Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Wordpress
#Wordpress

Click2Shell Chain Turns One Malicious Link Into WordPress Server Takeover

19 September 2026  |  dark6  |  Vulnerability

WordPress has fixed a theme-preview weakness that can silently install an attacker-selected theme when an administrator opens a crafted link. Paired with unsafe pre-activation code in a theme,...

>> read more

Two Critical Flaws in a Popular WordPress Calendar Plugin Put 600,000+ Sites at Risk of Full Takeover

16 September 2026  |  dark6  |  Vulnerability

Two unauthenticated, maximum-severity vulnerabilities in the widely used 'The Events Calendar' WordPress plugin could let attackers seize full control of more than 600,000 websites without ever logging in....

>> read more

Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution

22 August 2026  |  dark6  |  Vulnerability

A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...

>> read more

Fake CAPTCHA Prompts on Hacked WordPress Sites Fuel Global StopAndProtect Malware Botnet

19 August 2026  |  dark6  |  Malware

Researchers have uncovered a sprawling campaign, dubbed StopAndProtect, that has hijacked thousands of poorly maintained WordPress sites to serve as rotating command-and-control infrastructure. Fake CAPTCHA prompts trick visitors...

>> read more

New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...

>> read more

wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In

20 July 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...

>> read more

CVE-2026-8206 (CVSS 9.8): Kirki WordPress Plugin Flaw Lets Attackers Steal Admin Accounts on 500,000+ Sites

4 June 2026  |  dark6  |  Vulnerability

A critical unauthenticated privilege escalation flaw (CVE-2026-8206, CVSS 9.8) in the Kirki WordPress plugin allows attackers to redirect password reset emails and take over administrator accounts. Over 150,000...

>> read more

WordPress Sites Turned Into Spy Networks: Malware Hides C2 Commands in Steam Profile Comments Using Unicode Steganography

3 June 2026  |  dark6  |  Malware

A sophisticated malware campaign has compromised approximately 1,900 WordPress sites using Steam Community profile pages as a covert C2 channel. The malware employs Unicode steganography to hide commands...

>> read more