WordPress Patches βClick2Shellβ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
The post WordPress Patches βClick2Shellβ Vulnerability appeared first on SecurityWeek.
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
The post WordPress Patches βClick2Shellβ Vulnerability appeared first on SecurityWeek.
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.
The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.