Most WordPress Pros Still Have No Plan for Recovering From a Hack

Only 27.9% of WordPress pros have a breach recovery plan, a Melapress survey finds. Most learn of hacks when someone notices the site acting strangely.

A CSRF Flaw in Elementor Lets a Single Click Create a Rogue Admin Account

A critical flaw in Elementor, active on 10 million+ sites, lets one clicked link create a rogue admin account. Update to 4.3.2 now.

Issue 20: A Second Critical WordPress Patch, Under Attack Within a Day

WordPress 7.1.2 patches a critical, unauthenticated flaw already under active attack. A Tutor LMS bug and blockchain-hiding malware also demand attention.

Attackers Are Actively Exploiting the WordPress Flaw From Yesterday's Patch

Attackers are actively exploiting the critical WordPress flaw patched this week, writing files to servers that have not updated. Patch to 7.1.2 now.

Wordfence Found WordPress Malware That Hides on the Ethereum Blockchain

Wordfence found WordPress malware disguised as a must-use plugin that reinstalls itself and hides its control server inside the Ethereum blockchain.

WordPress 7.1.2 Fixes a Critical Bug That Let Anyone Take Over Your Site

WordPress 7.1.2 fixes a critical, unauthenticated flaw that can let attackers run code on your site. It affects versions back to 2016. Update now.

Click2Shell: The Full Story Behind the WordPress Theme Install Bug Patched This Week

A CSRF and selector injection chain called Click2Shell could let attackers run code by tricking an admin into clicking one link. Update to WordPress 7.1.1.

A Critical Flaw in the Library That Opens iPhone Photos Could Expose Your Server

A critical flaw in libheif, the library servers use to process iPhone photos, can expose files or run code. Ask your host if it is patched.

A High-Severity Flaw in Tutor LMS Lets Subscribers Take Over Your Server

A high-severity flaw in Tutor LMS lets any subscriber-level user take over your server. The plugin runs on 100,000+ sites. Update to 4.0.8 now.

Issue 19: No-Login Site Takeovers, and a New Look for WordPress's Default Theme

Two critical WordPress plugin flaws are being exploited with no login required. WordPress 7.1.1 patches 11 more bugs, and passkey login goes free.

WordPress 7.1.1 Fixes 11 Security Bugs, Including Two Found by Anthropic

A security release for WordPress fixes 11 vulnerabilities, including two reported by Anthropic. Update your site to 7.1.1 now.

Wordfence 9 Lets Your Site's Users Log In Without a Password

Wordfence 9 adds free passkey login, letting WooCommerce and WordPress users sign in with a fingerprint or face scan instead of a password.

Two Critical Flaws in The Events Calendar Can Hand Attackers Full Site Control

Two critical flaws in The Events Calendar let attackers take over a site with no login required. The plugin runs on 600,000+ sites. Update to 6.17.5.

Attackers Are Exploiting a Critical Flaw in WooCommerce Wholesale Lead Capture

A critical flaw in WooCommerce Wholesale Lead Capture lets attackers upload malicious files without logging in. Update to 2.0.3.2 now.

Issue 18: A New Backstop for Bad Plugin Updates, and a Shake-Up at Automattic

WordPress.org now blocks malicious plugin updates before they ship. Automattic's board put founder Matt Mullenweg on leave, naming a new interim CEO.

Issue 17: Five Critical Fixes and Two Flaws Under Attack

Five plugins shipped critical fixes this week. Two older flaws are under attack, and Rank Math paused a feature that created credentials without consent.

Attackers Have Been Exploiting a Critical Super Forms Flaw Since July

Attackers have exploited a critical Super Forms plugin flaw since July, and Wordfence has blocked over 250,000 attempts. Update to 6.3.314 now.

Attackers Are Now Actively Exploiting That Critical Elementor Pro Flaw

Wordfence has blocked over 190,000 exploit attempts against the critical Elementor Pro file upload flaw. Update to 4.2.2 now if you haven't already.

SQL Injection Flaw in All-in-One WP Migration and Backup Can Lead to a Full Site Takeover

A SQL injection flaw in All-in-One WP Migration and Backup, used on 5 million sites, can lead to a full takeover during a backup restore. Update to 7.110.

Critical Flaw in Gravity Forms Lets Attackers Upload Malicious Files Without Logging In

A critical flaw in Gravity Forms lets attackers upload malicious files without logging in, if a form allows multiple file uploads. Update to 3.0.3 now.

Rank Math Pauses Its Support Agent Feature After Consent Backlash

Rank Math paused its Support Agent feature after users said it created login credentials without clear consent. It returns once consent flow is rebuilt.

Rank Math's New 'Support Agent' Creates an Admin Password Without Asking First

Rank Math 1.0.277 reportedly creates an admin-level Application Password when you open Help and Support, without asking first. Revoke it now.

Critical Flaw in GiveWP Lets Attackers Take Over Your Site Without Logging In

A CVSS 10 flaw in GiveWP lets attackers take over donation sites without logging in. Update to version 4.16.7.2 immediately.

Pods' Solo Developer Raced to Patch a Critical Flaw Across Six Plugin Versions

Pods shipped patches across six plugin versions after a critical flaw let attackers become admin. Its solo developer took the week off his job to fix it.