Wordpress

Threat actors target WordPress sites using vulnerable File Manager install

Experts reported threat actors are increasingly targeting a recently addressed vulnerability in the WordPress plugin File Manager. Researchers from WordPress…

5 years ago

Hackers are actively exploiting critical RCE in WordPress sites using File Manager plugin

Hackers actively exploiting a critical remote code execution vulnerability in the File Manager plugin, over 300,000 WordPress sites potentially exposed. Hackers are…

5 years ago

Thousands of WordPress WooCommerce stores potentially exposed to hack

Hackers are attempting to exploit multiple vulnerabilities in the Discount Rules for WooCommerce WordPress plugin, which has 30,000+ installations. Researchers from security…

5 years ago

A critical flaw in wpDiscuz WordPress plugin lets hackers take over hosting account

A critical flaw in the wpDiscuz WordPress plugin could be exploited by remote attackers to execute arbitrary code and take…

6 years ago

KingComposer fixes a reflected XSS impacting 100,000 WordPress sites

An XSS vulnerability in the KingComposer page builder for WordPress impacts 100,000 websites using the WordPress plugin.  Researchers at Wordfence Threat…

6 years ago

Large-scale campaign targets configuration files from WordPress sites

Security experts have observed a large-scale campaign over the weekend aimed at stealing configuration files from WordPress sites. Security researchers…

6 years ago

Over 100K+ WordPress sites using PageLayer plugin exposed to hack

Two security flaws in the PageLayer WordPress plugin can be exploited to potentially wipe the contents or take over WordPress sites. Security…

6 years ago

Stored XSS in WP Product Review Lite plugin allows for automated takeovers

A critical flaw in the WP Product Review Lite plugin installed on over 40,000 WordPress sites could potentially allow their take over.…

6 years ago

Google WordPress Site Kit plugin grants attacker Search Console Access

Experts found a critical bug in Google's official WordPress plugin 'Site Kit' that could allow hackers to gain owner access to…

6 years ago

Popular Page Builder WordPress plugin fixes critical issues. Update it now!

Two issues in the popular Page Builder by SiteOrigin WordPress plugin could be exploited to carry out code execution attacks…

6 years ago

This website uses cookies.