#wordfence — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #wordfence, aggregated by home.social.
-
Wordfence reports active exploitation of a flaw in WooCommerce Wholesale Lead Capture, a WordPress plugin with more than 6,000 active installations.
The issue affects versions up to 2.0.3.1 and could let an unauthenticated attacker upload files and run commands on an affected site.
Wordfence says it blocked more than 100,000 attack attempts since June 2026, including 99 in the last 24 hours of…
#Wordfence #WordPress #WooCommerceWholesaleLeadCapture #TheEventsCalendar
-
Two critical flaws in The Events Calendar WordPress plugin put 600,000+ installations at risk, allowing unauthenticated attackers to execute code or take over sites.
Listen/Read: https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/
-
Two critical flaws in The Events Calendar WordPress plugin put 600,000+ installations at risk, allowing unauthenticated attackers to execute code or take over sites.
Listen/Read: https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/
-
Two critical flaws in The Events Calendar WordPress plugin put 600,000+ installations at risk, allowing unauthenticated attackers to execute code or take over sites.
Listen/Read: https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/
-
Two critical flaws in The Events Calendar WordPress plugin put 600,000+ installations at risk, allowing unauthenticated attackers to execute code or take over sites.
Listen/Read: https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/
-
Two critical flaws in The Events Calendar WordPress plugin put 600,000+ installations at risk, allowing unauthenticated attackers to execute code or take over sites.
Listen/Read: https://hackread.com/critical-calendar-wordpress-plugin-flaws-site-takeover/
-
Wordfence reports more than 440,000 blocked attack attempts targeting two WordPress plugins: about 250,000 against Super Forms – Drag & Drop Form Builder and 190,000 against Elementor Pro.
The issues could allow attackers to upload files and potentially take control of affected sites.
Super Forms is fixed in version 6.3.314; Elementor Pro in 4.2.2.
Site owners should update and check for unfamiliar files or unexplained…
-
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
-
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
-
Wordfence's AI system Argus uncovered a six-step vulnerability chain in the Avada WordPress theme, rated 9.8 critical, enabling unauthenticated remote code execution.
-
Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
-
Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
-
Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
-
Wordfence found CVE-2026-19598, a critical unauthenticated flaw in the Pods WordPress plugin (100,000+ installs) letting attackers reset any password, including the admin's.
#PodsPlugin #CVE202619598 #WordPress #Wordfence #PrivilegeEscalation
-
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
----------
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical[…]
WordPress #Security #Tools #Wordfence #WordfencePRISM -
Wordfence: 1,764 CVEs, 528 critical/high. Avg CVSS 6.38, max 10. 0% unpatched, Trust Score A. But 2025→2026 CVEs +1,513. XSS (CWE-79) dominates. Vigilance still key. #Wordfence #infosec #cybersecurity
-
Wordfence: 1,764 CVEs, 528 critical/high. Avg CVSS 6.38, max 10. 0% unpatched, Trust Score A. But 2025→2026 CVEs +1,513. XSS (CWE-79) dominates. Vigilance still key. #Wordfence #infosec #cybersecurity
-
Wordfence: 1,764 CVEs, 528 critical/high. Avg CVSS 6.38, max 10. 0% unpatched, Trust Score A. But 2025→2026 CVEs +1,513. XSS (CWE-79) dominates. Vigilance still key. #Wordfence #infosec #cybersecurity
-
📣🚨 Critical backdoor found in #ARVE, a WordPress plugin used by 20,000+ sites to embed responsive videos from YouTube, Vimeo, Rumble, Odysee, TikTok, Twitch, Facebook, Dailymotion, Kick, and other platforms.
Listen/Read: https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
📣🚨 Critical backdoor found in #ARVE, a WordPress plugin used by 20,000+ sites to embed responsive videos from YouTube, Vimeo, Rumble, Odysee, TikTok, Twitch, Facebook, Dailymotion, Kick, and other platforms.
Listen/Read: https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
📣🚨 Critical backdoor found in #ARVE, a WordPress plugin used by 20,000+ sites to embed responsive videos from YouTube, Vimeo, Rumble, Odysee, TikTok, Twitch, Facebook, Dailymotion, Kick, and other platforms.
Listen/Read: https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
📣🚨 Critical backdoor found in #ARVE, a WordPress plugin used by 20,000+ sites to embed responsive videos from YouTube, Vimeo, Rumble, Odysee, TikTok, Twitch, Facebook, Dailymotion, Kick, and other platforms.
Listen/Read: https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
📣🚨 Critical backdoor found in #ARVE, a WordPress plugin used by 20,000+ sites to embed responsive videos from YouTube, Vimeo, Rumble, Odysee, TikTok, Twitch, Facebook, Dailymotion, Kick, and other platforms.
Listen/Read: https://hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
How To Unblock An IP Address in Wordfence WordPress Plugin https://www.youtube.com/watch?v=IyWJ9D0c1WU 🌐🛡🔓 #Wordfence #WordPress #Plugin #IP #Address #Unblock #Guide
-
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
Unauthenticated Arbitrary File Deletion (CVE-2026-8713, CVSS 9.1 Critical) in Avada Builder <= 3.15.3 lets attackers delete wp-config.php and take over sites.
Patched in 3.15.4 update now.
-
200,000 WordPress Sites at Risk from Critical Authentication Bypass Vulnerability in Burst Statistics Plugin
Patched in 3.4.2, update now.
-
200,000 WordPress Sites at Risk from Critical Authentication Bypass Vulnerability in Burst Statistics Plugin
Patched in 3.4.2, update now.
-
1,000,000 WordPress sites are affected by Arbitrary File Read and SQL Injection vulnerabilities in the Avada Builder plugin.
The Arbitrary File Read (CVE-2026-4782) allows subscriber+ attackers to read sensitive files, while the SQL Injection (CVE-2026-4798) allows unauthenticated attackers to extract data from the database.
Patched in 3.15.3. Review the report to ensure your site is not affected.
-
1,000,000 WordPress sites are affected by Arbitrary File Read and SQL Injection vulnerabilities in the Avada Builder plugin.
The Arbitrary File Read (CVE-2026-4782) allows subscriber+ attackers to read sensitive files, while the SQL Injection (CVE-2026-4798) allows unauthenticated attackers to extract data from the database.
Patched in 3.15.3. Review the report to ensure your site is not affected.
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?
-
Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin
A critical arbitrary file upload vulnerability (CVE-2026-3844, CVSS 9.8) in the Breeze Cache plugin for WordPress is being actively exploited.
Update to version 2.4.5. Review the report to ensure your site is not affected.
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 20, 2026 to April 26, 2026)
157 vulnerabilities were disclosed in 122 WordPress Plugins and 27 WordPress Themes. 69 researchers contributed to WordPress security last week.
6 Critical | 47 High | 104 Medium
-
Attackers Actively Exploiting Critical Vulnerability in Ninja Forms - File Upload Plugin
A critical arbitrary file upload vulnerability (CVE-2026-0740, CVSS 9.8) in Ninja Forms - File Upload is being actively exploited. An estimated 50,000 sites are affected. Over 118,600 exploit attempts have been blocked.
Update to version 3.3.27.
-
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)
153 vulnerabilities disclosed in 117 WordPress Plugins and 23 WordPress Themes. 74 researchers contributed to WordPress security.
10 Critical | 54 High | 89 Medium
-
Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin
A critical Remote Code Execution vulnerability (CVE-2026-3584, CVSS 9.8) in Kali Forms with 10,000+ active installations is under active attack. Over 312,200 exploit attempts blocked.
Update to version 2.4.10.
-
Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin
A critical Remote Code Execution vulnerability (CVE-2026-3584, CVSS 9.8) in Kali Forms with 10,000+ active installations is under active attack. Over 312,200 exploit attempts blocked.
Update to version 2.4.10.
-
Last week on Wordfence Security News: a critical unauthenticated file move vulnerability in MWWP Form (200,000+ installs, versions through 5.1.0) can lead to full-site takeover - patch to 5.1.1 now.
A supply chain attack pushed backdoored Axios versions (1.14.1 and 0.30.4), linked to North Korean actor UNC 1069.
A critical Citrix Netscaler SAML flaw with ~30,000 exposed appliances is under active exploitation.
-
50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin
CVE-2026-0740 | CVSS 9.8 (Critical) | Unauthenticated attackers can upload arbitrary files and achieve remote code execution. Update to version 3.3.27.
Discovered by Sélim Lanouar (whattheslime).
Review the report to ensure your site is not affected.
-
50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin
CVE-2026-0740 | CVSS 9.8 (Critical) | Unauthenticated attackers can upload arbitrary files and achieve remote code execution. Update to version 3.3.27.
Discovered by Sélim Lanouar (whattheslime).
Review the report to ensure your site is not affected.
-
200,000 WordPress Sites Affected by Arbitrary File Deletion Vulnerability in Perfmatters WordPress Plugin
CVE-2026-4350 (CVSS 8.1, High) allows unauthenticated attackers to delete arbitrary files, including wp-config.php, potentially leading to site takeover.
- Affected versions: <= 2.5.9.1
- Patched version: 2.6.0
- Researcher: hoshinoReview the report to ensure your site is not affected.
-
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
📬 WordPress-Lücke in Smart Slider 3 lässt einfache Benutzer Server-Dateien lesen
#Cyberangriffe #Internet #Softwareentwicklung #actionExportAll #Nonce #SmartSlider3 #vulnerability #Wordfence #WordpressLücke #WPBlog https://sc.tarnkappe.info/a595dd -
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!
-
A critical authentication bypass vulnerability in Tutor LMS Pro puts over 30,000 WordPress sites at risk of account takeover — including admin accounts — if an attacker knows the target's email address. Update to version 3.9.6 immediately.
-
A critical authentication bypass vulnerability in Tutor LMS Pro puts over 30,000 WordPress sites at risk of account takeover — including admin accounts — if an attacker knows the target's email address. Update to version 3.9.6 immediately.
-
Wordfence disclosed 204 WordPress vulnerabilities for the week of February 23rd to March 1st, 2026 -- 162 remain unpatched.
The spotlight is an unauthenticated SQL injection in Tutor LMS versions 3.9.6 and prior, affecting roughly 6.9 million sites.
Full report: