GiveWP flaw opens server to unauthenticated takeover
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
18 results for “wordpress”
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
A 9.8-rated flaw chain in the Avada WordPress theme lets unauthenticated attackers run PHP code.
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
CVE-2026-15826 in User Profile Builder exposes 40,000+ WordPress sites to admin takeover.
Attackers planted rogue admins and webshells on WordPress sites via a poisoned data feed, not file changes.
A critical authorization bypass in the AI Copilot plugin allows unauthenticated attackers to create administrator accounts and seize full control of websites.
A critical authorization bypass vulnerability in the TrueBooker plugin allows unauthenticated attackers to reset passwords for any user, including administrators.
A critical vulnerability in the Single Sign On For TNG WordPress plugin allows unauthenticated attackers to reset any user password and take over sites.
WordPress Core is under active attack via an interpretation conflict vulnerability that allows for SQL injection and remote code execution.
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
A critical vulnerability in a WordPress plugin allows unauthenticated users to gain full administrator access to affected websites.
A pair of newly identified vulnerabilities dubbed WP2Shell are being actively exploited in the wild, triggering forced site updates.
A dual-vulnerability chain allows unauthenticated code execution on WordPress core installations, prompting emergency updates.
A critical privilege escalation flaw in the Bricksforge plugin allows unauthenticated attackers to create new administrator accounts.
A critical privilege escalation flaw in the Aimogen Pro WordPress plugin could permit unauthenticated administrative access.
A critical vulnerability in the Bricksforge WordPress plugin allows unauthenticated attackers to create unauthorized administrator accounts.
Researchers are moving beyond theoretical AI capabilities, building automated pipelines to find live vulnerabilities in software.
As an automated, potentially AI-assisted campaign scans for flawed plugins, small businesses face a severe rise in stealthy webshell attacks.