home.social

#wordfence — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wordfence, aggregated by home.social.

fetched live
  1. Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin

    Unauthenticated Arbitrary File Deletion (CVE-2026-8713, CVSS 9.1 Critical) in Avada Builder <= 3.15.3 lets attackers delete wp-config.php and take over sites.

    Patched in 3.15.4 update now.

    wordfence.com/blog/2026/06/cri

    #WordPress #WordPressSecurity #Wordfence

  2. 1,000,000 WordPress sites are affected by Arbitrary File Read and SQL Injection vulnerabilities in the Avada Builder plugin.

    The Arbitrary File Read (CVE-2026-4782) allows subscriber+ attackers to read sensitive files, while the SQL Injection (CVE-2026-4798) allows unauthenticated attackers to extract data from the database.

    Patched in 3.15.3. Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/05/100

    #WordPress #CyberSecurity #Wordfence

  3. 1,000,000 WordPress sites are affected by Arbitrary File Read and SQL Injection vulnerabilities in the Avada Builder plugin.

    The Arbitrary File Read (CVE-2026-4782) allows subscriber+ attackers to read sensitive files, while the SQL Injection (CVE-2026-4798) allows unauthenticated attackers to extract data from the database.

    Patched in 3.15.3. Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/05/100

    #WordPress #CyberSecurity #Wordfence

  4. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  5. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  6. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  7. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  8. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  9. Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin

    A critical arbitrary file upload vulnerability (CVE-2026-3844, CVSS 9.8) in the Breeze Cache plugin for WordPress is being actively exploited.

    Update to version 2.4.5. Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/05/att

    #WordPress #WebSecurity #Wordfence

  10. Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)

    157 vulnerabilities were disclosed in 122 WordPress Plugins and 27 WordPress Themes. 69 researchers contributed to WordPress security last week.

    6 Critical | 47 High | 104 Medium

    wordfence.com/blog/2026/04/wor

    #WordPress #WebSecurity #Wordfence

  11. Attackers Actively Exploiting Critical Vulnerability in Ninja Forms - File Upload Plugin

    A critical arbitrary file upload vulnerability (CVE-2026-0740, CVSS 9.8) in Ninja Forms - File Upload is being actively exploited. An estimated 50,000 sites are affected. Over 118,600 exploit attempts have been blocked.

    Update to version 3.3.27.

    wordfence.com/blog/2026/04/att

    #WordPress #WebSecurity #Wordfence

  12. Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)

    153 vulnerabilities disclosed in 117 WordPress Plugins and 23 WordPress Themes. 74 researchers contributed to WordPress security.

    10 Critical | 54 High | 89 Medium

    wordfence.com/blog/2026/04/wor

    #WordPress #WebSecurity #Wordfence

  13. Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin

    A critical Remote Code Execution vulnerability (CVE-2026-3584, CVSS 9.8) in Kali Forms with 10,000+ active installations is under active attack. Over 312,200 exploit attempts blocked.

    Update to version 2.4.10.

    wordfence.com/blog/2026/04/att

    #WordPress #WebSecurity #Wordfence

  14. Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin

    A critical Remote Code Execution vulnerability (CVE-2026-3584, CVSS 9.8) in Kali Forms with 10,000+ active installations is under active attack. Over 312,200 exploit attempts blocked.

    Update to version 2.4.10.

    wordfence.com/blog/2026/04/att

    #WordPress #WebSecurity #Wordfence

  15. Last week on Wordfence Security News: a critical unauthenticated file move vulnerability in MWWP Form (200,000+ installs, versions through 5.1.0) can lead to full-site takeover - patch to 5.1.1 now.

    A supply chain attack pushed backdoored Axios versions (1.14.1 and 0.30.4), linked to North Korean actor UNC 1069.

    A critical Citrix Netscaler SAML flaw with ~30,000 exposed appliances is under active exploitation.

    youtube.com/watch?v=W_0gVPzNEqs

    #WordPressSecurity #CyberSecurity #Wordfence

  16. 50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin

    CVE-2026-0740 | CVSS 9.8 (Critical) | Unauthenticated attackers can upload arbitrary files and achieve remote code execution. Update to version 3.3.27.

    Discovered by Sélim Lanouar (whattheslime).

    Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/04/500

    #WordPress #WebSecurity #Wordfence

  17. 50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin

    CVE-2026-0740 | CVSS 9.8 (Critical) | Unauthenticated attackers can upload arbitrary files and achieve remote code execution. Update to version 3.3.27.

    Discovered by Sélim Lanouar (whattheslime).

    Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/04/500

    #WordPress #WebSecurity #Wordfence

  18. 200,000 WordPress Sites Affected by Arbitrary File Deletion Vulnerability in Perfmatters WordPress Plugin

    CVE-2026-4350 (CVSS 8.1, High) allows unauthenticated attackers to delete arbitrary files, including wp-config.php, potentially leading to site takeover.

    - Affected versions: <= 2.5.9.1
    - Patched version: 2.6.0
    - Researcher: hoshino

    Review the report to ensure your site is not affected.

    wordfence.com/blog/2026/04/200

    #WordPress #WebSecurity #Wordfence

  19. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  20. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  21. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  22. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  23. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  24. A critical authentication bypass vulnerability in Tutor LMS Pro puts over 30,000 WordPress sites at risk of account takeover — including admin accounts — if an attacker knows the target's email address. Update to version 3.9.6 immediately.

    Read more: wordfence.com/blog/2026/03/300

    #WordPress #WordPressSecurity #Wordfence

  25. A critical authentication bypass vulnerability in Tutor LMS Pro puts over 30,000 WordPress sites at risk of account takeover — including admin accounts — if an attacker knows the target's email address. Update to version 3.9.6 immediately.

    Read more: wordfence.com/blog/2026/03/300

    #WordPress #WordPressSecurity #Wordfence

  26. Wordfence disclosed 204 WordPress vulnerabilities for the week of February 23rd to March 1st, 2026 -- 162 remain unpatched.

    The spotlight is an unauthenticated SQL injection in Tutor LMS versions 3.9.6 and prior, affecting roughly 6.9 million sites.

    Full report:

    wordfence.com/blog/2026/03/wor

    #WordPress #WordPressSecurity #Wordfence

  27. Wordfence disclosed 204 WordPress vulnerabilities for the week of February 23rd to March 1st, 2026 -- 162 remain unpatched.

    The spotlight is an unauthenticated SQL injection in Tutor LMS versions 3.9.6 and prior, affecting roughly 6.9 million sites.

    Full report:

    wordfence.com/blog/2026/03/wor

    #WordPress #WordPressSecurity #Wordfence

  28. Wordfence Bug Bounty Program Monthly Report – January 2026

    In January 2026, 897 vulnerability submissions were received from 151 active researchers.

    152 were validated in-scope, with $21,517 in total bounties awarded.

    Highlights:

    - 22 high threat vulnerabilities
    - 8 new WAF rules released
    - $2,145 highest single bounty

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  29. Wordfence Bug Bounty Program Monthly Report – January 2026

    In January 2026, 897 vulnerability submissions were received from 151 active researchers.

    152 were validated in-scope, with $21,517 in total bounties awarded.

    Highlights:

    - 22 high threat vulnerabilities
    - 8 new WAF rules released
    - $2,145 highest single bounty

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  30. Wordfence Intelligence Weekly WordPress Vulnerability Report (February 9, 2026 to February 15, 2026)

    Last week, 174 vulnerabilities were disclosed in 139 WordPress Plugins and 28 WordPress Themes.

    Severity breakdown:

    - Critical: 6
    - High: 60
    - Medium: 108

    Review the report to ensure your site is not affected:

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  31. Wordfence Intelligence Weekly WordPress Vulnerability Report (February 9, 2026 to February 15, 2026)

    Last week, 174 vulnerabilities were disclosed in 139 WordPress Plugins and 28 WordPress Themes.

    Severity breakdown:

    - Critical: 6
    - High: 60
    - Medium: 108

    Review the report to ensure your site is not affected:

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  32. Wordfence Intelligence Weekly WordPress Vulnerability Report (February 2, 2026 to February 8, 2026)

    Last week, 121 vulnerabilities were disclosed in 100 WordPress Plugins and 10 WordPress Themes.

    Severity breakdown:
    - Critical: 4
    - High: 31
    - Medium: 86

    Review the report to ensure your site is not affected:

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  33. Wordfence Intelligence Weekly WordPress Vulnerability Report (February 2, 2026 to February 8, 2026)

    Last week, 121 vulnerabilities were disclosed in 100 WordPress Plugins and 10 WordPress Themes.

    Severity breakdown:
    - Critical: 4
    - High: 31
    - Medium: 86

    Review the report to ensure your site is not affected:

    wordfence.com/blog/2026/02/wor

    #WordPress #WebSecurity #Wordfence

  34. A critical arbitrary file upload vulnerability (CVE-2026-1357, CVSS 9.8) was discovered in the WPvivid Backup & Migration plugin, which is installed on over 800,000 WordPress sites.

    The flaw allows unauthenticated attackers to upload arbitrary files, potentially achieving remote code execution and full site takeover.

    Update to version 0.9.124. Wordfence Premium users received firewall protection on January 22.

    wordfence.com/blog/2026/02/800

    #WordPress #WebSecurity #Wordfence

  35. A critical arbitrary file upload vulnerability (CVE-2026-1357, CVSS 9.8) was discovered in the WPvivid Backup & Migration plugin, which is installed on over 800,000 WordPress sites.

    The flaw allows unauthenticated attackers to upload arbitrary files, potentially achieving remote code execution and full site takeover.

    Update to version 0.9.124. Wordfence Premium users received firewall protection on January 22.

    wordfence.com/blog/2026/02/800

    #WordPress #WebSecurity #Wordfence

  36. My current guess is it's a #wordpress/#wordfence plugin issue error?

    Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so.

  37. My current guess is it's a #wordpress/#wordfence plugin issue error?

    Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so.

  38. My current guess is it's a #wordpress/#wordfence plugin issue error?

    Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so.

  39. My current guess is it's a #wordpress/#wordfence plugin issue error?

    Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so.

  40. Wordfence führt API-Authentifizierung für Schwachstellendatenbank ein

    Da keine direkte Kontaktaufnahme mit bestehenden API-Nutzern möglich ist, appelliert Wordfence an die Community, die Information über die anstehende Änderung zu verbreiten.

    all-about-security.de/wordfenc

    #wordpress #wordfence #api

  41. Wordfence führt API-Authentifizierung für Schwachstellendatenbank ein

    Da keine direkte Kontaktaufnahme mit bestehenden API-Nutzern möglich ist, appelliert Wordfence an die Community, die Information über die anstehende Änderung zu verbreiten.

    all-about-security.de/wordfenc

    #wordpress #wordfence #api

  42. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  43. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  44. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  45. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  46. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  47. @macmanx @threadi @ramsey @simon
    In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline.

    wordfence.com/threat-intel/vul

  48. @macmanx @threadi @ramsey @simon
    In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline.

    wordfence.com/threat-intel/vul

  49. @macmanx @threadi @ramsey @simon
    In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline.

    wordfence.com/threat-intel/vul