Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution
A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...
Fake CAPTCHA Prompts on Hacked WordPress Sites Fuel Global StopAndProtect Malware Botnet
Researchers have uncovered a sprawling campaign, dubbed StopAndProtect, that has hijacked thousands of poorly maintained WordPress sites to serve as rotating command-and-control infrastructure. Fake CAPTCHA prompts trick visitors...
New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover
A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...
wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In
A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...
CVE-2026-8206 (CVSS 9.8): Kirki WordPress Plugin Flaw Lets Attackers Steal Admin Accounts on 500,000+ Sites
A critical unauthenticated privilege escalation flaw (CVE-2026-8206, CVSS 9.8) in the Kirki WordPress plugin allows attackers to redirect password reset emails and take over administrator accounts. Over 150,000...
WordPress Sites Turned Into Spy Networks: Malware Hides C2 Commands in Steam Profile Comments Using Unicode Steganography
A sophisticated malware campaign has compromised approximately 1,900 WordPress sites using Steam Community profile pages as a covert C2 channel. The malware employs Unicode steganography to hide commands...
Supply Chain Attack Backdoors Smart Slider 3 Pro: 800,000+ WordPress Sites at Risk
Attackers compromised Nextend's update infrastructure to distribute a weaponized version of Smart Slider 3 Pro (v3.5.1.35) for approximately six hours on April 7, 2026. Sites that auto-updated received...
Stealth malware strikes WordPress via MU-Plugins: a technical deep dive
The Sucuri research team has recently uncovered a concerning trend: threat actors are increasingly leveraging the WordPress mu-plugins directory to conceal malicious code. This tactic1 is particularly insidious...