Sucuri's SC backdoor hides in eight places and rebuilds itself from any one that survives cleanup.
WordPress 7.1.2 closes a path traversal in get_page_template() that needs no account and can end in code execution on some…
An anonymous commenter could plant a script that ran in an administrator's browser and, from there, uploaded a web shell…
Attackers used a long-lived Cloudflare API key stored in Brevo's own source code to push malware through the marketing platform's…
WordPress 7.1.1 fixes a chain that installs a theme from the official directory from a single crafted link.
Wordfence and Defiant detail critical flaws in WooCommerce Wholesale Lead Capture and The Events Calendar, both reachable without credentials.
Wordfence counts 440,000 exploit attempts against Super Forms and Elementor Pro file-upload flaws.
Five critical flaws across WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP open sites to takeover and code execution.