The past seven days have been an exceptionally busy period for cybersecurity defenders. Between March 16 and...
wordpress security
In a sophisticated new campaign active since late 2025, a mysterious threat actor has been turning the...
The WordPress security team has issued an urgent call to action following the release of WordPress 6.9.2...
A high-severity SQL Injection vulnerability was found in Ally, a popular web accessibility and usability WordPress plugin....
A high-severity vulnerability has been uncovered in Tutor LMS Pro, a popular WordPress plugin used by over...
A massive security hole has been discovered in the User Registration & Membership plugin for WordPress, a...
A highly active cybercriminal group is turning legitimate websites into traps, deploying a potent mix of fake...
A plugin designed to keep spam bots at bay has inadvertently left the back door open for...
A critical security vulnerability has been discovered in WPvivid Backup, a popular WordPress plugin used by over...
A massive wave of “watering hole” attacks has turned thousands of legitimate WordPress websites into traps for...
A critical security vulnerability has been uncovered in the RealHomes CRM plugin, a core component of the...
A critical security incident has rocked the WordPress community after a “backdoor” vulnerability was discovered in the...
A critical security vulnerability has been unearthed in the Academy LMS plugin for WordPress, a popular tool...
A critical security vulnerability has been discovered in Advanced Custom Fields: Extended, a popular WordPress plugin with...
A critical privilege escalation vulnerability, tracked as CVE-2026-23550 (CVSS 10), has been discovered in the Modular DS...
A new phishing campaign is targeting WooCommerce users with fake security vulnerability alerts, attempting to trick them...
A recent investigation by Sucuri revealed a sophisticated credit card skimming attack on a WordPress website. The...