CVE-2026-32475critical
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.
CVE-2026-76581critical
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in
CVE-2026-61979critical
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two critical authentication bypass vulnerabilities (CVSS 9.8) in the miniOrange SAML 2.0 Single Sign On WordPress plugin have been actively exploited. These flaws allow unauthenticated attackers to forge SAML responses and gain administrative access. The vulnerabilities were particularly insidious because they affected paid editions of the plugin, which were not listed in public vulnerability databases and did not trigger automatic updates, leaving administrators unaware of their exposure.
ransomware
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder tha
malware
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software
CVE-2026-15748critical
Forminator WordPress Plugin Vulnerable to Remote Code Execution
A critical vulnerability in the Forminator WordPress plugin, used by over 600,000 sites, allows unauthenticated attackers to execute arbitrary code. This is achieved by exploiting a flaw that permits the upload of malicious PHP files. The vulnerability has a high severity rating.
CVE-2026-15826critical
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.