Issue 16: Six Critical Flaws, One Perfect Score
A CVSS 10 flaw in GiveWP lets attackers hijack donation sites without logging in. Five more critical plugin and theme bugs demanded updates this week.
Critical Flaw in WPMU DEV Dashboard Lets Attackers Become Your Site Admin
A critical flaw in WPMU DEV Dashboard lets unauthenticated attackers become your site admin if Hub Single Sign-On is enabled. Update to 5.0.2 now.
Critical Flaw in the Avada Theme Lets Attackers Take Over Your Site Without Logging In
A critical, unauthenticated flaw in the Avada theme and its Fusion Builder plugin lets attackers take over your site. Update to 7.16.1 now.
Critical Flaw in TranslatePress Lets Attackers Take Over Your Admin Account
An unauthenticated TranslatePress flaw can expose an admin password reset link when a secondary language is active. Update the plugin now.
Two Critical Flaws in miniOrange SAML SSO Let Attackers Log In as Your Admin
Two critical flaws in the miniOrange SAML SSO plugin let attackers log in as your admin. Paid editions were missed by update checkers. Patch now.
Critical Flaw in the Pods Plugin Lets Attackers Become Your Site Admin
A critical flaw in the Pods plugin lets attackers become your site admin without logging in. Update to version 3.3.9.1 now if you run Pods.
Issue 15: Zero Logins Needed
Three unauthenticated plugin flaws hit Elementor Pro, Forminator, and User Profile Builder this week. WordPress 7.1 also launched with responsive styling.
Critical Flaw in Elementor Pro Lets Attackers Take Over Your Site Without Logging In
An unauthenticated flaw in Elementor Pro lets attackers upload malicious files and take over your site. Update to version 4.2.2 now.
Critical Flaw in Forminator Forms Lets Attackers Take Over Your Site Without Logging In
A critical flaw in Forminator Forms lets attackers upload malicious files and take over your site without logging in. Update to 1.56.2 now.
Critical Flaw in User Profile Builder Lets Attackers Log In as Your Admin
A critical flaw in User Profile Builder can let attackers log in as your site admin. Update to version 3.16.5 now if Automatic Log In is enabled.
Issue 14: When a PNG Isn't a PNG
WordPress 7.0.4 patches an Imagick RCE flaw, its third security release in weeks. Two plugin backdoors hit official update channels this week too.
WordPress 7.0.4 Fixes a Flaw That Let a Disguised Image Run Code on Your Server
WordPress 7.0.4 fixes a flaw where a disguised image upload lets an Author-level account run code on your server. Update now.
Supply Chain Attack Hits Seven BdThemes Elementor Plugins With Hidden Backdoors
Attackers hijacked a promotional banner feed in seven BdThemes Elementor plugins to plant rogue admin accounts and hidden backdoors. Check your site now.
Issue 13: A Backdoor Rode In Through the Front Door
WordPress 7.0.3 patches 12 flaws, one leading to remote code execution. A backdoored update hit Fluent Forms and Ninja Tables Pro for five hours.
WordPress 7.0.3 Patches 12 Security Flaws, One Could Lead to Remote Code Execution
WordPress 7.0.3 fixes 12 security flaws, including a login screen bug that can lead to remote code execution. Update your site now.
WordPress Security Reports Jumped From 30 a Month to 450 as AI Tools Take Over the Hunting
WordPress security reports jumped from about 30 a month to 450 in July, as AI tools like Anthropic and pwn.ai now find and prove exploitable bugs.
A Forgotten Server Let Attackers Backdoor Fluent Forms Pro and Ninja Tables Pro Updates
A forgotten server let attackers backdoor Fluent Forms Pro and Ninja Tables Pro updates for five hours. Check your site if you updated on July 31.
Patchstack: WordPress.org Holds Security Patches as Long as Cosmetic Updates
Patchstack found WordPress.org holds critical security patches for the same delay as cosmetic updates, leaving known flaws exposed for hours longer.
Critical Flaw in WooCommerce Social Login Lets Anyone Log In as Your Admin
A critical flaw in WooCommerce Social Login lets attackers log in as any user, including admins, by faking an Apple sign-in token. Update to 2.8.8 now.
Issue 12: WordPress's New Safety Net Just Passed Its First Real Test
A plugin backdoor never reached a single WordPress site, but WP2Shell attacks have topped 11 million attempts. WordPress 7.1 nears its August 19 release.
Wordfence: WordPress's WP2Shell Attack Has Now Topped 11 Million Attempts
Wordfence has blocked over 11 million attempts to exploit WordPress's WP2Shell flaw. If your site reads 7.0.2, 6.9.5, or 6.8.6, you're already protected.
Wordfence's AI Caught a Backdoored Plugin With 20,000 Installs in Under Two Hours
Wordfence's AI tool caught a backdoored plugin with 20,000 installs within two hours. If you use Advanced Responsive Video Embedder, uninstall it now.
Issue 11: AI found WordPress's worst RCE in years, attackers followed in 90 minutes
Attackers hit WordPress's critical RCE within 90 minutes of the patch. An AI found the flaw in 10 hours. WordPress 7.1 drops a feature over security fears.
Wordfence's AI Researcher Is Now Finding More WordPress Flaws Than Any Human
Wordfence's AI tool PRISM found 202 WordPress vulnerabilities since May and is now its top researcher. Keep auto-updates on as patches arrive faster.