WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated ...
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress ...
WordPress WP2Shell vulnerabilities expose millions of unpatched sites to full remote takeover - update to 7.0.2 now to stay protected.
Attackers have found a way to escalate the benign WordPress REST API flaw and use it to gain full access to a victim's server by installing a hidden backdoor. On January 26, the WordPress team ...
Hackers are chaining together two newly discovered flaws to achieve remote code execution.
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain ...
The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS. More than 20,000 WordPress sites are vulnerable to malicious code injection, phishing ...
Pakistan’s National CERT has warned of critical WordPress flaws that could let hackers take control of websites and urged ...