Wordpress

Hiding WordPress malware in the mu-plugins directory to avoid detectionHiding WordPress malware in the mu-plugins directory to avoid detection

Hiding WordPress malware in the mu-plugins directory to avoid detection

Sucuri researchers spotted threat actors deploying WordPress malware in the mu-plugins directory to evade security checks. In February, Sucuri warned…

2 months ago
Credit Card Skimmer campaign targets WordPress via database injectionCredit Card Skimmer campaign targets WordPress via database injection

Credit Card Skimmer campaign targets WordPress via database injection

Stealthy credit card skimmer targets WordPress e-commerce sites, injecting malicious JavaScript into CMS database tables to evade detection. Sucuri researchers…

4 months ago
Critical Really Simple Security plugin flaw impacts 4M+ WordPress sitesCritical Really Simple Security plugin flaw impacts 4M+ WordPress sites

Critical Really Simple Security plugin flaw impacts 4M+ WordPress sites

A Really Simple Security plugin flaw affects 4M+ sites, allowing attackers full admin access. It’s one of the most critical…

6 months ago
WordPress LiteSpeed Cache plugin flaw could allow site takeoverWordPress LiteSpeed Cache plugin flaw could allow site takeover

WordPress LiteSpeed Cache plugin flaw could allow site takeover

A high-severity flaw in the WordPress LiteSpeed Cache plugin could allow attackers to execute arbitrary JavaScript code under certain conditions.…

7 months ago
A flaw in WordPress LiteSpeed Cache Plugin allows account takeoverA flaw in WordPress LiteSpeed Cache Plugin allows account takeover

A flaw in WordPress LiteSpeed Cache Plugin allows account takeover

A critical flaw in the LiteSpeed Cache plugin for WordPress could allow unauthenticated users to take control of arbitrary accounts.…

8 months ago
Critical flaw in WPML WordPress plugin impacts 1M websites<gwmw style="display: none; background-color: transparent;"></gwmw><gwmw style="display: none; background-color: transparent;"></gwmw>Critical flaw in WPML WordPress plugin impacts 1M websites<gwmw style="display: none; background-color: transparent;"></gwmw><gwmw style="display: none; background-color: transparent;"></gwmw>

Critical flaw in WPML WordPress plugin impacts 1M websites<gwmw style="display: none; background-color: transparent;"></gwmw><gwmw style="display: none; background-color: transparent;"></gwmw>

A critical flaw in the WPML WordPress plugin, which is installed on 1 million websites, could allow potential compromise of…

9 months ago
LiteSpeed Cache WordPress plugin actively exploited in the wildLiteSpeed Cache WordPress plugin actively exploited in the wild

LiteSpeed Cache WordPress plugin actively exploited in the wild

Threat actors are exploiting a high-severity vulnerability in the LiteSpeed Cache plugin for WordPress to take over web sites. WPScan…

1 year ago
Experts warn of an ongoing malware campaign targeting WP-Automatic pluginExperts warn of an ongoing malware campaign targeting WP-Automatic plugin

Experts warn of an ongoing malware campaign targeting WP-Automatic plugin

A critical vulnerability in the WordPress Automatic plugin is being exploited to inject backdoors and web shells into websites WordPress…

1 year ago
XSS flaw in WordPress WP-Members Plugin can lead to script injectionXSS flaw in WordPress WP-Members Plugin can lead to script injection

XSS flaw in WordPress WP-Members Plugin can lead to script injection

A cross-site scripting vulnerability (XXS) in the WordPress WP-Members Membership plugin can lead to malicious script injection. Researchers from Defiant’s…

1 year ago
Large-scale Sign1 malware campaign already infected 39,000+ WordPress sitesLarge-scale Sign1 malware campaign already infected 39,000+ WordPress sites

Large-scale Sign1 malware campaign already infected 39,000+ WordPress sites

A large-scale malware campaign, tracked as Sign1, has already compromised 39,000 WordPress sites in the last six months. Sucurity researchers…

1 year ago