News

WordPress websites using unpatched Social Warfare installations (v3.5.1 and v3.5.2) are exposed to attacks abusing a zero-day stored Cross-Site Scripting (XSS) vulnerability fixed in the 3.5.3 ...
A critical vulnerability has been reported in WPML — a multilingual WordPress plugin with more than a million installations globally — that allows remote code execution on affected WordPress ...
A critical security issue found in the Ad Inserter WordPress plugin currently installed on over 200,000 websites allows authenticated attackers to remotely execute PHP code.
The Page Builder by SiteOrigin WordPress plugin was subject to vulnerabilities that exposed websites to code execution attacks.
Hackers exploit zero-day in WordPress plugin to create rogue admin accounts Attacks detected targeting sites running the ThemeREX Addons plugin.