#wordfence — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #wordfence, aggregated by home.social.
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
Unauthenticated Arbitrary File Deletion (CVE-2026-8713, CVSS 9.1 Critical) in Avada Builder <= 3.15.3 lets attackers delete wp-config.php and take over sites.
Patched in 3.15.4 update now.
-
200,000 WordPress Sites at Risk from Critical Authentication Bypass Vulnerability in Burst Statistics Plugin
Patched in 3.4.2, update now.
-
200,000 WordPress Sites at Risk from Critical Authentication Bypass Vulnerability in Burst Statistics Plugin
Patched in 3.4.2, update now.
-
1,000,000 WordPress sites are affected by Arbitrary File Read and SQL Injection vulnerabilities in the Avada Builder plugin.
The Arbitrary File Read (CVE-2026-4782) allows subscriber+ attackers to read sensitive files, while the SQL Injection (CVE-2026-4798) allows unauthenticated attackers to extract data from the database.
Patched in 3.15.3. Review the report to ensure your site is not affected.
-
1,000,000 WordPress sites are affected by Arbitrary File Read and SQL Injection vulnerabilities in the Avada Builder plugin.
The Arbitrary File Read (CVE-2026-4782) allows subscriber+ attackers to read sensitive files, while the SQL Injection (CVE-2026-4798) allows unauthenticated attackers to extract data from the database.
Patched in 3.15.3. Review the report to ensure your site is not affected.
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin
A critical arbitrary file upload vulnerability (CVE-2026-3844, CVSS 9.8) in the Breeze Cache plugin for WordPress is being actively exploited.
Update to version 2.4.5. Review the report to ensure your site is not affected.
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)
157 vulnerabilities were disclosed in 122 WordPress Plugins and 27 WordPress Themes. 69 researchers contributed to WordPress security last week.
6 Critical | 47 High | 104 Medium
-
Attackers Actively Exploiting Critical Vulnerability in Ninja Forms - File Upload Plugin
A critical arbitrary file upload vulnerability (CVE-2026-0740, CVSS 9.8) in Ninja Forms - File Upload is being actively exploited. An estimated 50,000 sites are affected. Over 118,600 exploit attempts have been blocked.
Update to version 3.3.27.
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)
153 vulnerabilities disclosed in 117 WordPress Plugins and 23 WordPress Themes. 74 researchers contributed to WordPress security.
10 Critical | 54 High | 89 Medium
-
Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin
A critical Remote Code Execution vulnerability (CVE-2026-3584, CVSS 9.8) in Kali Forms with 10,000+ active installations is under active attack. Over 312,200 exploit attempts blocked.
Update to version 2.4.10.
-
Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin
A critical Remote Code Execution vulnerability (CVE-2026-3584, CVSS 9.8) in Kali Forms with 10,000+ active installations is under active attack. Over 312,200 exploit attempts blocked.
Update to version 2.4.10.
-
Last week on Wordfence Security News: a critical unauthenticated file move vulnerability in MWWP Form (200,000+ installs, versions through 5.1.0) can lead to full-site takeover - patch to 5.1.1 now.
A supply chain attack pushed backdoored Axios versions (1.14.1 and 0.30.4), linked to North Korean actor UNC 1069.
A critical Citrix Netscaler SAML flaw with ~30,000 exposed appliances is under active exploitation.
-
50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin
CVE-2026-0740 | CVSS 9.8 (Critical) | Unauthenticated attackers can upload arbitrary files and achieve remote code execution. Update to version 3.3.27.
Discovered by Sélim Lanouar (whattheslime).
Review the report to ensure your site is not affected.
-
50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin
CVE-2026-0740 | CVSS 9.8 (Critical) | Unauthenticated attackers can upload arbitrary files and achieve remote code execution. Update to version 3.3.27.
Discovered by Sélim Lanouar (whattheslime).
Review the report to ensure your site is not affected.
-
200,000 WordPress Sites Affected by Arbitrary File Deletion Vulnerability in Perfmatters WordPress Plugin
CVE-2026-4350 (CVSS 8.1, High) allows unauthenticated attackers to delete arbitrary files, including wp-config.php, potentially leading to site takeover.
- Affected versions: <= 2.5.9.1
- Patched version: 2.6.0
- Researcher: hoshinoReview the report to ensure your site is not affected.
-
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
A critical authentication bypass vulnerability in Tutor LMS Pro puts over 30,000 WordPress sites at risk of account takeover — including admin accounts — if an attacker knows the target's email address. Update to version 3.9.6 immediately.
-
A critical authentication bypass vulnerability in Tutor LMS Pro puts over 30,000 WordPress sites at risk of account takeover — including admin accounts — if an attacker knows the target's email address. Update to version 3.9.6 immediately.
-
Wordfence disclosed 204 WordPress vulnerabilities for the week of February 23rd to March 1st, 2026 -- 162 remain unpatched.
The spotlight is an unauthenticated SQL injection in Tutor LMS versions 3.9.6 and prior, affecting roughly 6.9 million sites.
Full report:
-
Wordfence disclosed 204 WordPress vulnerabilities for the week of February 23rd to March 1st, 2026 -- 162 remain unpatched.
The spotlight is an unauthenticated SQL injection in Tutor LMS versions 3.9.6 and prior, affecting roughly 6.9 million sites.
Full report:
-
Wordfence Bug Bounty Program Monthly Report – January 2026
In January 2026, 897 vulnerability submissions were received from 151 active researchers.
152 were validated in-scope, with $21,517 in total bounties awarded.
Highlights:
- 22 high threat vulnerabilities
- 8 new WAF rules released
- $2,145 highest single bountyhttps://www.wordfence.com/blog/2026/02/wordfence-bug-bounty-program-monthly-report-january-2026/
-
Wordfence Bug Bounty Program Monthly Report – January 2026
In January 2026, 897 vulnerability submissions were received from 151 active researchers.
152 were validated in-scope, with $21,517 in total bounties awarded.
Highlights:
- 22 high threat vulnerabilities
- 8 new WAF rules released
- $2,145 highest single bountyhttps://www.wordfence.com/blog/2026/02/wordfence-bug-bounty-program-monthly-report-january-2026/
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (February 9, 2026 to February 15, 2026)
Last week, 174 vulnerabilities were disclosed in 139 WordPress Plugins and 28 WordPress Themes.
Severity breakdown:
- Critical: 6
- High: 60
- Medium: 108Review the report to ensure your site is not affected:
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (February 9, 2026 to February 15, 2026)
Last week, 174 vulnerabilities were disclosed in 139 WordPress Plugins and 28 WordPress Themes.
Severity breakdown:
- Critical: 6
- High: 60
- Medium: 108Review the report to ensure your site is not affected:
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (February 2, 2026 to February 8, 2026)
Last week, 121 vulnerabilities were disclosed in 100 WordPress Plugins and 10 WordPress Themes.
Severity breakdown:
- Critical: 4
- High: 31
- Medium: 86Review the report to ensure your site is not affected:
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (February 2, 2026 to February 8, 2026)
Last week, 121 vulnerabilities were disclosed in 100 WordPress Plugins and 10 WordPress Themes.
Severity breakdown:
- Critical: 4
- High: 31
- Medium: 86Review the report to ensure your site is not affected:
-
A critical arbitrary file upload vulnerability (CVE-2026-1357, CVSS 9.8) was discovered in the WPvivid Backup & Migration plugin, which is installed on over 800,000 WordPress sites.
The flaw allows unauthenticated attackers to upload arbitrary files, potentially achieving remote code execution and full site takeover.
Update to version 0.9.124. Wordfence Premium users received firewall protection on January 22.
-
A critical arbitrary file upload vulnerability (CVE-2026-1357, CVSS 9.8) was discovered in the WPvivid Backup & Migration plugin, which is installed on over 800,000 WordPress sites.
The flaw allows unauthenticated attackers to upload arbitrary files, potentially achieving remote code execution and full site takeover.
Update to version 0.9.124. Wordfence Premium users received firewall protection on January 22.
-
My current guess is it's a #wordpress/#wordfence plugin issue error?
Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so. -
My current guess is it's a #wordpress/#wordfence plugin issue error?
Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so. -
My current guess is it's a #wordpress/#wordfence plugin issue error?
Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so. -
My current guess is it's a #wordpress/#wordfence plugin issue error?
Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so. -
Wordfence führt API-Authentifizierung für Schwachstellendatenbank ein
Da keine direkte Kontaktaufnahme mit bestehenden API-Nutzern möglich ist, appelliert Wordfence an die Community, die Information über die anstehende Änderung zu verbreiten.
-
Wordfence führt API-Authentifizierung für Schwachstellendatenbank ein
Da keine direkte Kontaktaufnahme mit bestehenden API-Nutzern möglich ist, appelliert Wordfence an die Community, die Information über die anstehende Änderung zu verbreiten.
-
Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
https://schacknetz.de/stolperstein-2fa-bei-wordpress-zugriff-per-xml-rpc-wordfence/ -
Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
https://schacknetz.de/stolperstein-2fa-bei-wordpress-zugriff-per-xml-rpc-wordfence/ -
Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
https://schacknetz.de/stolperstein-2fa-bei-wordpress-zugriff-per-xml-rpc-wordfence/ -
Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
https://schacknetz.de/stolperstein-2fa-bei-wordpress-zugriff-per-xml-rpc-wordfence/ -
Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
https://schacknetz.de/stolperstein-2fa-bei-wordpress-zugriff-per-xml-rpc-wordfence/ -
@macmanx @threadi @ramsey @simon
In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline. -
@macmanx @threadi @ramsey @simon
In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline. -
@macmanx @threadi @ramsey @simon
In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline.