Some of the most dangerous vulnerabilities in modern web apps are the default features left switched on where they were never meant to be reachable. The first entry in our Findings from the AP series looks at an exposed actuator endpoint. On paper, this finding started the same…
In short, WordPress security plugins are tools you add to your site to strengthen your settings, scan for malware, watch for file changes, and block suspicious activity from within WordPress. Most sites should use one, along with a firewall that filters traffic before WordPress…
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files…
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission…
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary…
The conversation focused on the rapidly evolving landscape of WordPress security, emphasising the impact of AI on both attack complexity and defence strategies. We talked about the accelerating pace at which vulnerabilities are discovered and exploited, prompting the need for…
Yesterday we released a new version of Jetpack, 16.1.3. This release contains a critical security update. While we have no evidence that this vulnerability has been exploited, please update your Jetpack version as soon as possible to keep your site secure. To help you through…
Product Name: Package UpSnap Vulnerability: Authenticated Remote Code Execution in UpSnap Vulnerable Version:<= 5.3.5 CVE: CVE-2026-49481 On 26/05/2026, a security researcher at Astra Security found a critical Remote Code Execution (RCE) vulnerability in UpSnap, a web-based…
We have fixed a bug in how the MalCare plugin handles a rare invalid request. We haven’t seen it being abused, but it was possible, so we have closed it. If you’re a MalCare customer, please rest assured that you’re already protected. In short: a request with a specific…
On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it…
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations.
If you operate a website, you’re already aware that a single unpatched vulnerability can render your site inaccessible, compromise your reputation, or necessitate extensive remediation following an attack. Most security breaches we observe originate from automated attacks that…
About the CompanyOne of the fastest-growing and most trusted companies in blockchain security, CertiK is a true market leader. To date, CertiK has worked with over 4,798 clients, secured over...
I am requesting an estimate for a whole-account WordPress security assessment and the clean rebuilding of one compromised website. My WebHostingHub/cPanel account contains five domains: arealwholelot.com — document root: /public_html kaneconsultingandcoaching.com — document…
More than 100 organizations, including OpenAI, Google, and Microsoft, urge governments and website owners to prepare now for escalating AI cyberattacks.
This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which, on the versions…