LIVE · cybersecurity feed
Live wire
ASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE Publication

wordpress news

10 stories
CVE-2026-93836high

Ninja Forms plugin flaw exploited to hack WordPress sites

Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the…

CVE-2026-32475critical

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Reports indicate that a critical arbitrary file upload vulnerability within the Elementor Pro WordPress plugin is currently being actively exploited to compromise websites. The flaw, identified as CVE-2026-32475, allows attackers to upload malicious files to affected sites, potentially leading to full site compromise.

CVE-2026-61979critical

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Two critical authentication bypass vulnerabilities, both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin were actively exploited before public vulnerability databases accurately reflected the affected paid editions. These flaws, identified as CVE-2026-61979 and CVE-2026-15981, allowed unauthenticated attackers to forge SAML authentication responses and gain…

CVE-2026-15748critical

Forminator WordPress Plugin Vulnerable to Remote Code Execution

A critical remote code execution (RCE) vulnerability has been reported in the Forminator WordPress plugin, a tool utilized by over 600,000 websites. The flaw reportedly allows unauthenticated attackers to execute arbitrary code on affected sites. This vulnerability carries a high severity rating, indicating a significant risk to the integrity and security of websites employing the plugin.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical authentication bypass vulnerability, identified as CVE-2026-15826, has been discovered in the User Profile Builder plugin for WordPress, potentially exposing over 40,000 websites to administrative takeover. The flaw, which carries a CVSS rating of 9.8, affects plugin versions up to and including 3.16.4.

CVE-2026-60137high

Two High-Severity WordPress Vulnerabilities Require Immediate Patching

WordPress has released emergency security updates to address two high-severity vulnerabilities, including a critical SQL injection flaw that could lead to remote code execution. Users are urged to patch their installations immediately.

CVE-2026-63030critical

Critical RCE Vulnerability in WordPress Core Affects Millions of Sites

A critical unauthenticated remote code execution vulnerability, identified as CVE-2026-63030, has been discovered in WordPress Core, affecting millions of websites globally. The vulnerability allows an attacker to execute arbitrary code without authentication through the WordPress REST API batch endpoint, potentially leading to a complete compromise of the affected website and its data.

CVE-2026-60137critical

Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws

Cloudflare has confirmed that its Web Application Firewall (WAF) successfully mitigated attacks targeting two critical vulnerabilities in WordPress and its plugins. The vulnerabilities, identified as CVE-2023-50387 and CVE-2024-21724, could lead to remote code execution (RCE) and SQL injection, respectively.

wordpresscritical

WordPress Core Flaw Allows Unauthenticated Code Execution

A critical vulnerability has been reported in the core of WordPress, enabling unauthenticated attackers to achieve arbitrary code execution on affected websites. The flaw, identified by Adam Kues of Searchlight Cyber, was present in WordPress versions 6.9 and 7.0. WordPress has subsequently released patches and initiated forced updates to mitigate the risk across its user base.

defacement

US Army websites defaced with pro-Kurdish sentiments, insults to Trump

At least two U.S. Army websites were defaced with messages expressing pro-Kurdish sentiments and insults directed at President Donald Trump and White House advisor Tom Barrack. The defacements were discovered on error pages of the subdomains oil.army.mil and ai2c.army.mil.