Security

Newly found weaknesses, attacks doing the rounds, and how to keep your site safe.

119 headlines · 8 publishers

Latest headlines

All Security headlines
Astra Security

Autonomous Pentest Findings: Unauthenticated Kill Switch

Some of the most dangerous vulnerabilities in modern web apps are the default features left switched on where they were never meant to be reachable. The first entry in our Findings from the AP series looks at an exposed actuator endpoint. On paper, this finding started the same…

By Ananda Krishna

Sucuri

WordPress Security Plugins: How to Choose the Right One

In short, WordPress security plugins are tools you add to your site to strengthen your settings, scan for malware, watch for file changes, and block suspicious activity from within WordPress. Most sites should use one, along with a firewall that filters traffic before WordPress…

By Sucuri

Wordfence

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files…

By István Márton

Wordfence

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary…

By István Márton

Astra Security

CVE-2026-49481: Vulnerability in UpSnap

Product Name: Package UpSnap Vulnerability: Authenticated Remote Code Execution in UpSnap Vulnerable Version:<= 5.3.5 CVE: CVE-2026-49481 On 26/05/2026, a security researcher at Astra Security found a critical Remote Code Execution (RCE) vulnerability in UpSnap, a web-based…

By Ephrim Holyson

MalCare

Security Update: Improved Parameter Validation Checks

We have fixed a bug in how the MalCare plugin handles a rare invalid request. We haven’t seen it being abused, but it was possible, so we have closed it. If you’re a MalCare customer, please rest assured that you’re already protected. In short: a request with a specific…

By Akshat Choudhary

Sucuri

Vulnerability & Patch Roundup — August 2026

If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that…

By Sucuri Malware Research Team

Patchstack

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP

This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions…

By Patchstack

Astra Security

Autonomous Pentesting for SaaS Companies in 2026: The Complete Guide

Key Takeaways You ship to production every day while your last pentest happened 11 months ago. Just say that sentence out loud, and we ought to rest our entire case of autonomous pentesting for SaaS companies right there. Everything below is just the supporting evidence. The…

By Jinson Varghese

MalCare

How to Add CAPTCHA WordPress: Protect Login, Forms, and Comments

If you are searching for a captcha WordPress solution because bots are filling your comments, contact forms, registrations, or login page, you can reduce that activity without putting a challenge in front of every visitor. The best setup protects the action attracting abuse…

By Akshat Choudhary

Patchstack

Case study: ManageWP Blocks 11.9M+ Threats in 6 Months with Patchstack

Run one WordPress site and a vulnerability is a single bad day. Run an agency, and it’s a portfolio-wide panic event that results in lost sleep and enough caffeine to take down a horse. Updates can’t close that gap alone, especially when attackers weaponize the most-targeted…

By Lana Rafaela

Publishers

All publishers