WordPress
21 stories on WordPress, newest first, from 21 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting.
- Elementor Plugin Bug Lets Attackers Hijack WordPress Sites With a Single Click
- CISA Warns of Actively Exploited WordPress Vulnerability
- Critical WordPress Flaw Under Active Attack Within Hours of Patch Release
- WordPress Patches Critical Flaw Allowing Unauthenticated Code Execution on Some Sites
- WordPress Fixes 'Comment2Shell' Flaw That Let Anonymous Comments Hijack Admin Sessions
- WordPress Patches 'Click2Shell' Flaw That Could Let Attackers Hijack Admin Sessions
- Unpatched WooCommerce Plugin Flaw Still Letting Attackers Plant Webshells on WordPress Sites
- Critical WooCommerce Plugin Flaw Lets Hackers Plant Backdoors on WordPress Sites
- WordPress Adds Automated Security Scans to Catch Malicious Plugin Updates Before They Go Live
- 440,000+ Attacks Target Critical WordPress Plugin Flaws — Is Your Site at Risk?
- Critical Flaw in Popular WordPress Migration Plugin Puts 3 Million Sites at Risk
- Critical WordPress Plugin and Theme Bugs Put Sites at Risk of Takeover
- Critical Login Bypass Flaws Found in Popular WordPress SSO Plugin
- Hackers Actively Exploiting WordPress SAML Login Plugin Flaws
- Critical Elementor Pro Flaw Lets Hackers Take Over WordPress Sites Without Logging In
- Nearly 2,000 Hacked WordPress Sites Turned Into Malware Distribution Network
- WordPress Form Plugin Flaw Puts 300,000 Sites at Risk of Takeover
- WordPress Patch Fixes Serious Remote Code Execution Flaw
- WordPress Plugin Vendor BdThemes Hit by Supply Chain Attack, Creating Rogue Admin Accounts
- Critical WordPress Flaw Could Let Hackers Take Over Your Website — Update Now
- WordPress's Two-Bug Combo: What the wp2shell RCE Teaches Us About Code Review