WordPress SAML SSO vulnerability in the miniOrange plugin is being actively exploited -- attackers can log in as any WordPress administrator with no credentials. Enterprise sites running paid editions ...
WordPress backup plugin vulnerability CVE-2026-19949 in All-in-One WP Migration exposes 3.25 million unpatched sites to unauthenticated remote code execution, with a weaponized proof-of-concept ...
A WordPress plugin has been found to contain "easily exploitable" security issues that can be exploited to completely take over vulnerable websites. The plugin at the heart of the matter, WP Database ...
Malicious activity targeting a critical severity flaw in the ‘Better Search Replace’ WordPress plugin has been detected, with researchers observing thousands of attempts in the past 24 hours. Better ...
Researcher Ryan Dewhurst released the WPScan Vulnerability Database, a database housing security vulnerabilities in WordPress core code, plug-ins and themes. It’s available for pen-testers, WordPress ...
The WordPress plugin WP Fastest Cache is vulnerable to an SQL injection vulnerability that could allow unauthenticated attackers to read the contents of the site’s database. WP Fastest Cache is a ...