wordpress news
10 stories
Ninja Forms plugin flaw exploited to hack WordPress sites
Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the…

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Reports indicate that a critical arbitrary file upload vulnerability within the Elementor Pro WordPress plugin is currently being actively exploited to compromise websites. The flaw, identified as CVE-2026-32475, allows attackers to upload malicious files to affected sites, potentially leading to full site compromise.

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two critical authentication bypass vulnerabilities, both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin were actively exploited before public vulnerability databases accurately reflected the affected paid editions. These flaws, identified as CVE-2026-61979 and CVE-2026-15981, allowed unauthenticated attackers to forge SAML authentication responses and gain…

Forminator WordPress Plugin Vulnerable to Remote Code Execution
A critical remote code execution (RCE) vulnerability has been reported in the Forminator WordPress plugin, a tool utilized by over 600,000 websites. The flaw reportedly allows unauthenticated attackers to execute arbitrary code on affected sites. This vulnerability carries a high severity rating, indicating a significant risk to the integrity and security of websites employing the plugin.

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
A critical authentication bypass vulnerability, identified as CVE-2026-15826, has been discovered in the User Profile Builder plugin for WordPress, potentially exposing over 40,000 websites to administrative takeover. The flaw, which carries a CVSS rating of 9.8, affects plugin versions up to and including 3.16.4.

Two High-Severity WordPress Vulnerabilities Require Immediate Patching
WordPress has released emergency security updates to address two high-severity vulnerabilities, including a critical SQL injection flaw that could lead to remote code execution. Users are urged to patch their installations immediately.

Critical RCE Vulnerability in WordPress Core Affects Millions of Sites
A critical unauthenticated remote code execution vulnerability, identified as CVE-2026-63030, has been discovered in WordPress Core, affecting millions of websites globally. The vulnerability allows an attacker to execute arbitrary code without authentication through the WordPress REST API batch endpoint, potentially leading to a complete compromise of the affected website and its data.

Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws
Cloudflare has confirmed that its Web Application Firewall (WAF) successfully mitigated attacks targeting two critical vulnerabilities in WordPress and its plugins. The vulnerabilities, identified as CVE-2023-50387 and CVE-2024-21724, could lead to remote code execution (RCE) and SQL injection, respectively.

WordPress Core Flaw Allows Unauthenticated Code Execution
A critical vulnerability has been reported in the core of WordPress, enabling unauthenticated attackers to achieve arbitrary code execution on affected websites. The flaw, identified by Adam Kues of Searchlight Cyber, was present in WordPress versions 6.9 and 7.0. WordPress has subsequently released patches and initiated forced updates to mitigate the risk across its user base.

US Army websites defaced with pro-Kurdish sentiments, insults to Trump
At least two U.S. Army websites were defaced with messages expressing pro-Kurdish sentiments and insults directed at President Donald Trump and White House advisor Tom Barrack. The defacements were discovered on error pages of the subdomains oil.army.mil and ai2c.army.mil.