WordPress WP2Shell vulnerabilities expose millions of unpatched sites to full remote takeover - update to 7.0.2 now to stay protected.
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated ...
Attackers have found a way to escalate the benign WordPress REST API flaw and use it to gain full access to a victim's server by installing a hidden backdoor. On January 26, the WordPress team ...
Hackers are chaining together two newly discovered flaws to achieve remote code execution.
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress ...
The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS. More than 20,000 WordPress sites are vulnerable to malicious code injection, phishing ...
Pakistan’s National Cyber Emergency Response Team (National CERT) has issued a high-severity cybersecurity advisory, warning ...