#wordfence — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #wordfence, aggregated by home.social.
-
Wordfence reports more than 440,000 blocked attack attempts targeting two WordPress plugins: about 250,000 against Super Forms – Drag & Drop Form Builder and 190,000 against Elementor Pro.
The issues could allow attackers to upload files and potentially take control of affected sites.
Super Forms is fixed in version 6.3.314; Elementor Pro in 4.2.2.
Site owners should update and check for unfamiliar files or unexplained…
-
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
-
Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
-
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
----------
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical[…]
WordPress #Security #Tools #Wordfence #WordfencePRISM -
Wordfence: 1,764 CVEs, 528 critical/high. Avg CVSS 6.38, max 10. 0% unpatched, Trust Score A. But 2025→2026 CVEs +1,513. XSS (CWE-79) dominates. Vigilance still key. #Wordfence #infosec #cybersecurity
-
📣🚨 Critical backdoor found in #ARVE, a WordPress plugin used by 20,000+ sites to embed responsive videos from YouTube, Vimeo, Rumble, Odysee, TikTok, Twitch, Facebook, Dailymotion, Kick, and other platforms.
Listen/Read: https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
My current guess is it's a #wordpress/#wordfence plugin issue error?
Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so. -
Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
https://schacknetz.de/stolperstein-2fa-bei-wordpress-zugriff-per-xml-rpc-wordfence/ -
@macmanx @threadi @ramsey @simon
In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline. -
> The Plugin "…" appears to be abandoned (updated December 18, 2023, tested to WP 6.9.0).
Well, thanks Wordfence but I think tested up to WP 6.9.0 indicates that it isn't abandoned.
Sometimes, plugins don't need fixes or new features. 🙄
-
Mass Attack Targets WordPress via GutenKit and Hunk Companion Plugins https://hackread.com/wordpress-mass-attack-gutenkit-hunk-companion-plugins/ #Cybersecurity #HunkCompanion #Vulnerability #Wordfence #Wordpress #Security #GutenKit
-
Auth Bypass Flaw in Service Finder WordPress Plugin Under Active Exploit https://hackread.com/auth-bypass-service-finder-wordpress-plugin-exploit/ #Cybersecurity #ServiceFinder #Vulnerability #Wordfence #Wordpress #Security
-
Holy crap, #Wordpress users out there, is #Wordfence the single dumbest piece of software ever made? I view a site "protected" by Wordfence, it loads fine. Then I go to a different site and read a page, then I hit back in my browser, and the original site is now "Advanced blocking in effect" on my (presumably) IP address.
-
WordPress Security Alert: CVE-2025-6043 Enables Remote File Deletion via Malcure Plugin https://thecyberexpress.com/malcure-vulnerability-cve-2025-6043/ #MalcureMalwareScanner #TheCyberExpressNews #Vulnerabilities #TheCyberExpress #FirewallDaily #CVE20256043 #CyberNews #Wordfence #WordPress
-
New WordPress Malware Hides on Checkout Pages and Imitates Cloudflare https://hackread.com/wordpress-malware-checkout-pages-imitates-cloudflare/ #Cybersecurity #CyberAttack #Wordfence #Wordpress #Security #security #Malware #Plugin #Scam
-
Flawed WordPress theme may allow admin account takeover on 22,000+ sites (CVE-2025-4322) https://www.helpnetsecurity.com/2025/05/21/wordpress-motors-theme-cve-2025-4322-admin-account-takeover/ #accounthijacking #vulnerability #Don'tmiss #Wordfence #WordPress #Hotstuff #News
-
Sneaky WordPress Malware Disguised as Anti-Malware Plugin – Source:hackread.com https://ciso2ciso.com/sneaky-wordpress-malware-disguised-as-anti-malware-plugin-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Vulnerability #Wordfence #WordPress #Hackread #security #malware #Plugin #PHP
-
Sneaky WordPress Malware Disguised as Anti-Malware Plugin https://hackread.com/wordpress-malware-disguised-as-anti-malware-plugin/ #Cybersecurity #Vulnerability #Wordfence #Wordpress #Security #Malware #Plugin #PHP
-
100,000+ WordPress Sites at Risk as SureTriggers Exploit Goes Live https://thecyberexpress.com/suretriggers-vulnerability/ #SureTriggersVulnerability #TheCyberExpressNews #Vulnerabilities #TheCyberExpress #wordpressplugin #FirewallDaily #CVE20253102 #CyberNews #Wordfence #OttoKit
-
OK, so #Wordfence and #Wordpress.org need to get their shit together. No way do I suddenly have 2484 suspicious files in my core installation 6 hours after an update.
-
BuddyPress 14.2.1 Maintenance & Security release
The “Take Photo” feature (which uses the logged in user’s Webcam to capture their profile photo) was vulnerable to an authenticated (Subscriber+) directory traversal. Discovered by Domons from the Wordfence organization.
#buddypress #wordpress #plugin #foss #opensource #software #security #wordfence
-
Wordfence Launches WordPress Superhero Challenge with Big Rewards. https://wptavern.com/wordfence-launches-wordpress-superhero-challenge-with-big-rewards #WordFence #WordPressSecurity
-
Compromised plugins found on WordPress.org https://www.helpnetsecurity.com/2024/06/26/compromised-plugins-wordpress/ #supplychaincompromise #Don'tmiss #Wordfence #WordPress #Hotstuff #backdoor #plugin #News