WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated ...
WordPress WP2Shell vulnerabilities expose millions of unpatched sites to full remote takeover - update to 7.0.2 now to stay ...
Hackers are chaining together two newly discovered flaws to achieve remote code execution.
Attackers have found a way to escalate the benign WordPress REST API flaw and use it to gain full access to a victim's server by installing a hidden backdoor. On January 26, the WordPress team ...
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress ...
The flaw affects WordPress Core’s REST Batch API, allowing unauthenticated attackers to execute code on vulnerable sites.
Pakistan’s National CERT has warned of critical WordPress flaws that could let hackers take control of websites and urged ...
WordPress has issued emergency security updates to block a critical vulnerability that allowed unauthenticated attackers to execute code on websites running standard installations without plugins. The ...
The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS. More than 20,000 WordPress sites are vulnerable to malicious code injection, phishing ...