A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object ...
A critical authentication bypass vulnerability in the WPMU DEV Dashboard plugin could allow unauthenticated attackers to ...
WordPress plugin TranslatePress stored admin password-reset links in a database table any visitor could read without logging ...
Chinese-speaking hackers exploited ownCloud and WordPress flaws to steal sensitive data from Philippine nuclear and naval ...
CVE-2026-19632 exposes WordPress admin password-reset links through TranslatePress, allowing unauthenticated attackers to take over affected WordPress websites.
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to ...
TranslatePress WordPress plugin flaw lets unauthenticated attackers hijack admin accounts and compromise websites.
Two miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability ...
WordPress sites face active attacks exploiting two miniOrange SAML flaws that can be chained to bypass authentication and ...
Nearly 2,000 hacked WordPress sites became infrastructure for the StopAndProtect malware operation, stealing crypto wallet ...