At a glance Actor / group Unattributed malicious cyber actors Activity Mass exploitation of CMS flaws to...
wordpress
At a glance Malware family ErrTraffic (ClickFix distribution framework / TDS, sold as MaaS) Threat actor Sold...
Around one million WordPress sites just got an urgent reason to patch. A critical Avada Builder...
A critical Gravity SMTP vulnerability is currently facing active exploitation in the wild. Consequently, WordPress site administrators...
A dangerous ShapedPlugin supply chain attack is currently threatening WordPress websites. Security researchers at Wordfence discovered this...
A serious Uncanny Automator breach has exposed customer data and pushed a malicious plugin update to live...
Cybersecurity experts recently identified a massive threat to WordPress websites. Specifically, hackers are actively exploiting a critical...
A security vulnerability has been identified in Temporary Login, a popular WordPress plugin designed to provide secure,...
Researchers expose a critical vulnerability in Perfmatters, a popular performance-optimization WordPress plugin with over 200,000 active installations....
For many nascent web developers and site administrators, the primary source of frustration lies not within the...
A new and stealthy malware campaign is targeting WordPress sites, turning trusted pages into billboards for online...
A sophisticated new phishing campaign is targeting WordPress site owners with fake “domain renewal” notices, tricking victims...
A critical Remote Code Execution (RCE) vulnerability has been discovered in the Sneeit Framework, a core plugin...
A critical security vulnerability carrying a near-maximum severity score has been discovered in “Advanced Custom Fields: Extended,”...
A critical security flaw in a popular WordPress plugin has triggered a massive wave of exploitation attempts,...
A newly disclosed critical vulnerability in the Sneeit Framework β a widely used WordPress plugin powering premium...
A newly disclosed high-severity security flaw in the widely used W3 Total Cache (W3TC) plugin is putting...
Researchers at Wordfence have disclosed a critical vulnerability (CVE-2025-11749, CVSS 9.8) in the popular AI Engine WordPress...
A critical-severity Local File Inclusion (LFI) flaw in the popular WordPress plugin ShopLentor β WooCommerce Builder for...
An extremely severe security vulnerability has been discovered and is being actively exploited in the Jobmonster –...
A critical security vulnerability has been identified and is being actively exploited in the King Addons for...
The Post SMTP plugin, used by over 400,000 WordPress sites to ensure reliable email delivery, has been...