logo

20,000 WordPress Sites Compromised by Backdoor Vulnerability Enabling Malicious Admin Access

ID: 49bcfe95-12c1-526a-be3a-7f9b90bca869

STIX ID: report--49bcfe95-12c1-526a-be3a-7f9b90bca869

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive Summary:** A critical unauthenticated backdoor (CVE-2026-0920, CVSS 9.8) in the LA‑Studio Element Kit for Elementor allowed attackers to create administrative accounts and fully compromise approximately 20,000 WordPress sites; the backdoor was intentionally inserted by a former employee, responsibly disclosed to Wordfence on 2026-01-12, and patched by the vendor in version 1.6.0 on 2026-01-14 — site administrators must update immediately and audit for compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.