home.social

#wordfence — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wordfence, aggregated by home.social.

fetched live
  1. 1,000,000 WordPress sites are affected by Arbitrary File Read and SQL Injection vulnerabilities in the Avada Builder plugin.

    The Arbitrary File Read (CVE-2026-4782) allows subscriber+ attackers to read sensitive files, while the SQL Injection (CVE-2026-4798) allows unauthenticated attackers to extract data from the database.

    Patched in 3.15.3. Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/05/100

    #WordPress #CyberSecurity #Wordfence

  2. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  3. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  4. Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin

    A critical arbitrary file upload vulnerability (CVE-2026-3844, CVSS 9.8) in the Breeze Cache plugin for WordPress is being actively exploited.

    Update to version 2.4.5. Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/05/att

    #WordPress #WebSecurity #Wordfence

  5. Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)

    157 vulnerabilities were disclosed in 122 WordPress Plugins and 27 WordPress Themes. 69 researchers contributed to WordPress security last week.

    6 Critical | 47 High | 104 Medium

    wordfence.com/blog/2026/04/wor

    #WordPress #WebSecurity #Wordfence

  6. Attackers Actively Exploiting Critical Vulnerability in Ninja Forms - File Upload Plugin

    A critical arbitrary file upload vulnerability (CVE-2026-0740, CVSS 9.8) in Ninja Forms - File Upload is being actively exploited. An estimated 50,000 sites are affected. Over 118,600 exploit attempts have been blocked.

    Update to version 3.3.27.

    wordfence.com/blog/2026/04/att

    #WordPress #WebSecurity #Wordfence

  7. Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)

    153 vulnerabilities disclosed in 117 WordPress Plugins and 23 WordPress Themes. 74 researchers contributed to WordPress security.

    10 Critical | 54 High | 89 Medium

    wordfence.com/blog/2026/04/wor

    #WordPress #WebSecurity #Wordfence

  8. Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin

    A critical Remote Code Execution vulnerability (CVE-2026-3584, CVSS 9.8) in Kali Forms with 10,000+ active installations is under active attack. Over 312,200 exploit attempts blocked.

    Update to version 2.4.10.

    wordfence.com/blog/2026/04/att

    #WordPress #WebSecurity #Wordfence

  9. Last week on Wordfence Security News: a critical unauthenticated file move vulnerability in MWWP Form (200,000+ installs, versions through 5.1.0) can lead to full-site takeover - patch to 5.1.1 now.

    A supply chain attack pushed backdoored Axios versions (1.14.1 and 0.30.4), linked to North Korean actor UNC 1069.

    A critical Citrix Netscaler SAML flaw with ~30,000 exposed appliances is under active exploitation.

    youtube.com/watch?v=W_0gVPzNEqs

    #WordPressSecurity #CyberSecurity #Wordfence

  10. 50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin

    CVE-2026-0740 | CVSS 9.8 (Critical) | Unauthenticated attackers can upload arbitrary files and achieve remote code execution. Update to version 3.3.27.

    Discovered by Sélim Lanouar (whattheslime).

    Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/04/500

    #WordPress #WebSecurity #Wordfence

  11. 200,000 WordPress Sites Affected by Arbitrary File Deletion Vulnerability in Perfmatters WordPress Plugin

    CVE-2026-4350 (CVSS 8.1, High) allows unauthenticated attackers to delete arbitrary files, including wp-config.php, potentially leading to site takeover.

    - Affected versions: <= 2.5.9.1
    - Patched version: 2.6.0
    - Researcher: hoshino

    Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/04/200

    #WordPress #WebSecurity #Wordfence

  12. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  13. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  14. A critical authentication bypass vulnerability in Tutor LMS Pro puts over 30,000 WordPress sites at risk of account takeover — including admin accounts — if an attacker knows the target's email address. Update to version 3.9.6 immediately.

    Read more: wordfence.com/blog/2026/03/300

    #WordPress #WordPressSecurity #Wordfence

  15. Wordfence disclosed 204 WordPress vulnerabilities for the week of February 23rd to March 1st, 2026 -- 162 remain unpatched.

    The spotlight is an unauthenticated SQL injection in Tutor LMS versions 3.9.6 and prior, affecting roughly 6.9 million sites.

    Full report:

    wordfence.com/blog/2026/03/wor

    #WordPress #WordPressSecurity #Wordfence

  16. Wordfence Bug Bounty Program Monthly Report – January 2026

    In January 2026, 897 vulnerability submissions were received from 151 active researchers.

    152 were validated in-scope, with $21,517 in total bounties awarded.

    Highlights:

    - 22 high threat vulnerabilities
    - 8 new WAF rules released
    - $2,145 highest single bounty

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  17. Wordfence Intelligence Weekly WordPress Vulnerability Report (February 9, 2026 to February 15, 2026)

    Last week, 174 vulnerabilities were disclosed in 139 WordPress Plugins and 28 WordPress Themes.

    Severity breakdown:

    - Critical: 6
    - High: 60
    - Medium: 108

    Review the report to ensure your site is not affected:

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  18. Wordfence Intelligence Weekly WordPress Vulnerability Report (February 2, 2026 to February 8, 2026)

    Last week, 121 vulnerabilities were disclosed in 100 WordPress Plugins and 10 WordPress Themes.

    Severity breakdown:
    - Critical: 4
    - High: 31
    - Medium: 86

    Review the report to ensure your site is not affected:

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  19. A critical arbitrary file upload vulnerability (CVE-2026-1357, CVSS 9.8) was discovered in the WPvivid Backup & Migration plugin, which is installed on over 800,000 WordPress sites.

    The flaw allows unauthenticated attackers to upload arbitrary files, potentially achieving remote code execution and full site takeover.

    Update to version 0.9.124. Wordfence Premium users received firewall protection on January 22.

    wordfence.com/blog/2026/02/800

    #WordPress #WebSecurity #Wordfence

  20. My current guess is it's a #wordpress/#wordfence plugin issue error?

    Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so.

  21. Wordfence führt API-Authentifizierung für Schwachstellendatenbank ein

    Da keine direkte Kontaktaufnahme mit bestehenden API-Nutzern möglich ist, appelliert Wordfence an die Community, die Information über die anstehende Änderung zu verbreiten.

    all-about-security.de/wordfenc

    #wordpress #wordfence #api

  22. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  23. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  24. @macmanx @threadi @ramsey @simon
    In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline.

    wordfence.com/threat-intel/vul

  25. @macmanx @threadi @ramsey @simon
    In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline.

    wordfence.com/threat-intel/vul

  26. > The Plugin "…" appears to be abandoned (updated December 18, 2023, tested to WP 6.9.0).

    Well, thanks Wordfence but I think tested up to WP 6.9.0 indicates that it isn't abandoned.

    Sometimes, plugins don't need fixes or new features. 🙄

  27. > The Plugin "…" appears to be abandoned (updated December 18, 2023, tested to WP 6.9.0).

    Well, thanks Wordfence but I think tested up to WP 6.9.0 indicates that it isn't abandoned.

    Sometimes, plugins don't need fixes or new features. 🙄

    #WordPress #Wordfence

  28. Holy crap, #Wordpress users out there, is #Wordfence the single dumbest piece of software ever made? I view a site "protected" by Wordfence, it loads fine. Then I go to a different site and read a page, then I hit back in my browser, and the original site is now "Advanced blocking in effect" on my (presumably) IP address.

  29. OK, so #Wordfence and #Wordpress.org need to get their shit together. No way do I suddenly have 2484 suspicious files in my core installation 6 hours after an update.

  30. BuddyPress 14.2.1 Maintenance & Security release

    The “Take Photo” feature (which uses the logged in user’s Webcam to capture their profile photo) was vulnerable to an authenticated (Subscriber+) directory traversal. Discovered by Domons from the Wordfence organization.

    #buddypress #wordpress #plugin #foss #opensource #software #security #wordfence

  31. My website is getting hammered with spam today! I've never seen anything like this. Thank goodness for Wordfence!

    I've deleted at least 100 email notifications like this one so far.
    #Wordfence #Wordpress #Web #Spam #DDOS