logo

WordPress Plugin Vulnerabilities

Critical, high‑severity security flaws in widely used WordPress plugins (SQLi, RCE, auth bypass, privilege escalation) are being actively exploited to create admin accounts, deploy backdoors, and take over sites, prompting vendor patches and urgent update and audit recommendations.

List of posts related to this topic

Post TitleDate PublishedDescribes IncidentFeed
Critical WordPress Plugin Flaw Allows Unauthorized Access to Websites2026-05-14TrueGBHackers
Not Subscribed
40,000+ Sites Exposed: Critical 9.8 CVSS Flaw Grants Total WordPress Account Takeover2026-05-02Truesecurityonline.info
Not Subscribed
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access2026-04-13TruecybersecurityNews.com
Not Subscribed
Critical WordPress Plugin Bug Allows Authentication Bypass, Admin Takeover2026-04-13TrueCyber Press
Not Subscribed
WordPress Membership Plugin Flaw Lets Attackers Create Admin Accounts2026-03-06TrueGBHackers
Not Subscribed
WordPress membership plugin bug exploited to create admin accounts2026-03-05TrueBleeping Computer
Not Subscribed
WordPress Security Alert: Critical Privilege Escalation Flaw in Popular Membership Plugin2026-03-04Truesecurityonline.info
Not Subscribed
WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks2026-02-12TruecybersecurityNews.com
Not Subscribed
WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks2026-02-12TrueGBHackers
Not Subscribed
ACF plugin bug gives hackers admin on 50,000 WordPress sites2026-01-20TrueBleeping Computer
Not Subscribed
Critical WordPress Plugin Vulnerability Exposes 100,000+ Websites to Privilege Escalation Attacks2026-01-20TrueGBHackers
Not Subscribed
Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code2025-12-04TruecybersecurityNews.com
Not Subscribed
Severe WordPress Plugin Flaw Puts Over 600,000 Sites at Risk of Remote Takeover2025-07-02TrueCyber Press
Not Subscribed
20,000 WordPress Sites at Risk of File Upload & Deletion Exploits2025-04-02TrueGBHackers
Not Subscribed
Critical WordPress Plug-in Flaw Exposes 4M Sites to Takeover2024-11-18TrueDark Reading
Not Subscribed
Hackers are exploiting critical bug in LiteSpeed Cache plugin2024-08-22TrueBleeping Computer
Not Subscribed
Litespeed Cache bug exposes millions of WordPress sites to takeover attacks2024-08-21TrueBleeping Computer
Not Subscribed
Hackers Exploiting LiteSpeed Cache Bug to Gain Full Control of WordPress Sites2024-05-08TrueThe Hacker News
Not Subscribed
Hackers exploit LiteSpeed Cache flaw to create WordPress admins2024-05-07TrueBleeping Computer
Not Subscribed
Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites2024-04-26TrueThe Hacker News
Not Subscribed
WP Automatic WordPress plugin hit by millions of SQL injection attacks2024-04-25TrueBleeping Computer
Not Subscribed
WordPress Plugin Alert - Critical SQLi Vulnerability Threatens 200K+ Websites2024-02-27TrueThe Hacker News
Not Subscribed

1–22 of 22