Wordpress

Remove WordPress miniOrange plugins, a critical flaw can allow site takeoverRemove WordPress miniOrange plugins, a critical flaw can allow site takeover

Remove WordPress miniOrange plugins, a critical flaw can allow site takeover

A critical vulnerability in WordPress miniOrange's Malware Scanner and Web Application Firewall plugins can allow site takeover. On March 1st,…

1 year ago
XSS flaw in LiteSpeed Cache plugin exposes millions of WordPress sites at riskXSS flaw in LiteSpeed Cache plugin exposes millions of WordPress sites at risk

XSS flaw in LiteSpeed Cache plugin exposes millions of WordPress sites at risk

Researchers warn of an XSS vulnerability, tracked as CVE-2023-40000, in the LiteSpeed Cache plugin for WordPress Patchstack researchers warn of…

1 year ago
WordPress 6.4.2 fixed a Remote Code Execution (RCE) flawWordPress 6.4.2 fixed a Remote Code Execution (RCE) flaw

WordPress 6.4.2 fixed a Remote Code Execution (RCE) flaw

WordPress 6.4.2 addressed a security vulnerability that could be chained with another flaw to achieve remote code execution. WordPress released…

1 year ago
More than 17,000 WordPress websites infected with the Balada Injector in SeptemberMore than 17,000 WordPress websites infected with the Balada Injector in September

More than 17,000 WordPress websites infected with the Balada Injector in September

In September more than 17,000 WordPress websites have been compromised by the Balada Injector malware. Sucuri researchers reported that more than…

2 years ago
Balada Injector still at large – new domains discoveredBalada Injector still at large – new domains discovered

Balada Injector still at large – new domains discovered

The Balada Injector is still at large and still evading security software by utilizing new domain names and using new…

2 years ago
Three flaws in Ninja Forms plugin for WordPress impact 900K sitesThree flaws in Ninja Forms plugin for WordPress impact 900K sites

Three flaws in Ninja Forms plugin for WordPress impact 900K sites

Experts warn of vulnerabilities impacting the Ninja Forms plugin for WordPress that could be exploited for escalating privileges and data…

2 years ago
Hacking campaign targets sites using WordPress WooCommerce Payments PluginHacking campaign targets sites using WordPress WooCommerce Payments Plugin

Hacking campaign targets sites using WordPress WooCommerce Payments Plugin

Threat actors are actively exploiting a critical flaw, tracked as CVE-2023-28121, in the WooCommerce Payments WordPress plugin. Threat actors are actively…

2 years ago
Indexing Over 15 Million WordPress Websites with PWNPressIndexing Over 15 Million WordPress Websites with PWNPress

Indexing Over 15 Million WordPress Websites with PWNPress

Sicuranex's PWNPress platform indexed over 15 million WordPress websites, it collects data related to vulnerabilities and misconfigurations Leveraging the extensive…

2 years ago
WordPress sites using the Ultimate Member plugin are under attackWordPress sites using the Ultimate Member plugin are under attack

WordPress sites using the Ultimate Member plugin are under attack

Threat actors are exploiting a critical WordPress zero-day in the Ultimate Member plugin to create secret admin accounts. Hackers are…

2 years ago
miniOrange’s WordPress Social Login and Register plugin was affected by a critical auth bypass bugminiOrange’s WordPress Social Login and Register plugin was affected by a critical auth bypass bug

miniOrange’s WordPress Social Login and Register plugin was affected by a critical auth bypass bug

A critical authentication bypass flaw in miniOrange’s WordPress Social Login and Register plugin, can allow gaining access to any account on a…

2 years ago