Critical Forminator WordPress Flaw Allows Unauthenticated RCE via Malicious PHP Uploads
A critical vulnerability has been disclosed in the Forminator Forms WordPress plugin, which has over 600,000 active installations. Tracked as CVE-2026-15748 and…
A critical vulnerability has been disclosed in the Forminator Forms WordPress plugin, which has over 600,000 active installations. Tracked as CVE-2026-15748 and…
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
A high-severity path traversal vulnerability in the open-source developer platform Windmill, tracked as CVE-2026-29059 (CVSS 7.5), is under active exploitation. The flaw…
A cybercrime crew left its server exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM.…
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way…
Threat actors are actively exploiting a recently patched medium-severity information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on…
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors tampered with the official release channels…
Wordfence is a prominent WordPress security company that provides firewall, malware scanning, and threat intelligence services. It disclosed and analyzed critical vulnerabilities…