Security

Vulnerabilities, patches, malware campaigns, and practical hardening guidance for WordPress and the wider web stack.

1 today · 14 this week

Astra Security

Autonomous Pentest Findings: Unauthenticated Kill Switch

Some of the most dangerous vulnerabilities in modern web apps are the default features left switched on where they were never meant to be reachable. The first entry in our Findings from the AP series looks at an exposed actuator endpoint. On paper, this finding started the same…

By Ananda Krishna

Sucuri

WordPress Security Plugins: How to Choose the Right One

In short, WordPress security plugins are tools you add to your site to strengthen your settings, scan for malware, watch for file changes, and block suspicious activity from within WordPress. Most sites should use one, along with a firewall that filters traffic before WordPress…

By Sucuri

Wordfence

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files…

By István Márton

Wordfence

Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin

On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary…

By István Márton

WP Tavern

#232 – Aaron D Campbell on Navigating WordPress Security in the AI Era

The conversation focused on the rapidly evolving landscape of WordPress security, emphasising the impact of AI on both attack complexity and defence strategies. We talked about the accelerating pace at which vulnerabilities are discovered and exploited, prompting the need for…

By Nathan Wrigley

Jetpack

Jetpack 16.1.3: Critical Security Update

Yesterday we released a new version of Jetpack, 16.1.3. This release contains a critical security update. While we have no evidence that this vulnerability has been exploited, please update your Jetpack version as soon as possible to keep your site secure. To help you through…

By Brandon Kraft

Astra Security

CVE-2026-49481: Vulnerability in UpSnap

Product Name: Package UpSnap Vulnerability: Authenticated Remote Code Execution in UpSnap Vulnerable Version:<= 5.3.5 CVE: CVE-2026-49481 On 26/05/2026, a security researcher at Astra Security found a critical Remote Code Execution (RCE) vulnerability in UpSnap, a web-based…

By Ephrim Holyson

MalCare

Security Update: Improved Parameter Validation Checks

We have fixed a bug in how the MalCare plugin handles a rare invalid request. We haven’t seen it being abused, but it was possible, so we have closed it. If you’re a MalCare customer, please rest assured that you’re already protected. In short: a request with a specific…

By Akshat Choudhary

Sucuri

Vulnerability & Patch Roundup — August 2026

If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that…

By Sucuri Malware Research Team

Jobicy

Solidity Compiler Frontend Engineer

About the CompanyOne of the fastest-growing and most trusted companies in blockchain security, CertiK is a true market leader. To date, CertiK has worked with over 4,798 clients, secured over...

Patchstack

Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP

This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions…

By Patchstack