Skip to content
WordPress logo

WordPress in the Media

382 mentions across press, blogs, and newsletters

Top coverageTechCrunchThe VergeGizmodoTechRadar
2 major ·2 tech media

October 2026

therepository.email

Automattic Applies for Closed .wordpress Domain in ICANN’s First Application Round Since 2012

The application pitches .wordpress as a space stewarded for the open web, but rules out registrations by anyone outside Automattic and its affiliates.

Oct 9, 2026
therepository.email

Mary Hubbard Calls on Hosting and Plugin Companies to Fund WordPress Security Program

Automattic has paid every WordPress bug bounty since 2017. Now, WordPress's executive director wants GoDaddy, Newfold Digital, and 30 other big companies in the ecosystem to chip in.

Oct 8, 2026
therepository.email

WordPress MCP Adapter Now Available as a Canonical Plugin on WordPress.org

The official WordPress MCP Adapter plugin already has over 40,000 active installs, less than a week after launching in the WordPress.org plugin directory.

Oct 8, 2026
therepository.email

WordPress Contributors Test New Server-Aware Approach for Real-Time Collaboration

After real-time collaboration was pulled from WordPress 7.0, contributors are testing a new approach where the server, not users' browsers, merges edits and tracks who made each one.

Oct 8, 2026
Cybersecurity News

CyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks

CyberXero has emerged as an initial access broker that combines familiar hacking tools with artificial intelligence to run large-scale intrusions. The Russian-speaking operator targeted WordPress and e-commerce sites worldwide while separately probing Ukrainian energy and utility organizations. T

Oct 7, 2026
TLDR InfoSec pick

WordPress libheif RCE: Exploit Chain

How a WordPress libheif RCE uses returned pixels to bypass ASLR, trigger a heap overflow and execute commands on exact Ubuntu and Debian stacks.

Oct 7, 2026
DesignRush

Critical WordPress Flaw Draws Exploit Attempts Within 5 Hours of Patch

Attackers began probing a critical WordPress vulnerability less than five hours after its security patch became available, according to WordPress security firm Patchstack and reports by Bleeping Computer.By the...

Oct 7, 2026
Cybersecurity News

Critical WordPress Vulnerabilities Enable XSS, SQL Injection and Data Disclosure Attacks

WordPress released version 7.1.3 on October 6, 2026, addressing vulnerabilities involving cross-site scripting, SQL injection, information disclosure, and other security weaknesses. The project recommends immediate updates, with fixes also available for older affected branches. Only the latest Wo

Oct 7, 2026
therepository.email

Weglot Disrupts Itself With an AI-Native Rebuild, Launches 2.0 on WordPress

Co-founder Rémy Berda's one-month experiment to build a fictional Weglot competitor from scratch ended with paying customers, and convinced the company it needed to rebuild from the ground up.

Oct 7, 2026
BleepingComputer

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

Oct 6, 2026
Cybersecurity News

Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers

A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an attack chain that turns a normal Media Library upload into code execution in the PHP-FPM process that runs the site. The risk comes from libheif, a widely used component that

Oct 5, 2026
GBHackers

Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads

A critical heap-buffer-overflow vulnerability in libheif could allow authenticated WordPress users to achieve remote code execution by uploading a specially crafted HEIC image through the standard Media Library workflow. The issue, tracked as GHSA-x8r2-mggj-j6wr, affects the library’s uncompresse

Oct 5, 2026
PPC Land

Google Site Kit auto-tracks checkouts and form leads from 8 WordPress plugins

Version 1.187.0 lifted the Site Goals flag on September 7 across 5M+ active installs. Breakdowns start with no history, and the same events can feed Google Ads.

Oct 3, 2026
Cybersecurity News

Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to

Oct 2, 2026
therepository.email

WP Engine v. Automattic, Two Years On: Where the WordPress Drama Stands

WP Engine's lawsuit against Automattic turns two today. From a keynote and an 8% royalty demand to a jury trial that's a year away, here's where it stands and why it's far from over.

Oct 2, 2026
GBHackers

TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks

A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning. The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler nam

Oct 2, 2026
therepository.email

WordPress Takes Its Turn Leading the Open Website Alliance as Mary Hubbard Eyes AI Regulation

WordPress Executive Director wants the coalition, which includes Drupal, Joomla!, and TYPO3, to build on its Cyber Resilience Act work and give open source a stronger voice as governments regulate AI.

Oct 2, 2026
therepository.email

Court Filings Reveal WordPress.org’s “Mission Control” Dashboard Tracked WP Engine’s ACF Pro Installs

A WordPress .org dashboard called "Mission Control" tracked installs of ACF Pro — a plugin the site doesn't host — and Matt Mullenweg raised an M&A "exit" before the WP Engine fight went public, according to newly public testimony.

Oct 1, 2026
Cybersecurity News

WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor

A WordPress backdoor is bringing deleted malware back within seconds, turning routine cleanup into a cycle of reinfection. Called SC, the infection spreads its working parts across website files, the database, and server memory, allowing surviving components to restore those removed. The investig

Oct 1, 2026
GBHackers

SC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence

A newly analyzed WordPress malware family, tracked as SC for the “SC_” markers embedded in its injected code, uses a self-healing persistence mesh that can restore a deleted backdoor within seconds. Researchers found that SC does not rely on a single web shell or plugin. Instead, the malware crea

Oct 1, 2026

September 2026

Practical Ecommerce

New Ecommerce Tools: September 30, 2026

New services this week include agentic commerce, product reviews, local businesses, returns management, WordPress development, and cross-border selling. The post New Ecommerce Tools: September 30, 2026 a

Sep 30, 2026
therepository.email

WordPress 7.2 Roadmap Includes New Security Features, Suggestion Mode for Notes, and Ipsum Default Theme

Collaborative editing has been deliberately left off the roadmap, and the December release will be livestreamed instead of launched during the State of the Word.

Sep 29, 2026
WebProNews

Automattic Purges Board After Failed Coup Against CEO Matt Mullenweg

Automattic, the company behind WordPress.com and open-source WordPress, purged its board after a failed coup attempt to oust CEO Matt Mullenweg. The move, driven by disagreements ov

Sep 28, 2026
GizmodoTech Media

WordPress Owner Automattic’s Board Reportedly Purged After Failed ‘Coup’ Against CEO

Automattic reportedly has new board members, advisers, and counsel after the old board failed to oust CEO Matt Mullenweg.

Sep 27, 2026
infoq.com

Cloudflare Details Its Migration from WordPress to EmDash

Cloudflare recently documented the migration of its main blog from WordPress to EmDash, the open source content management system developed internally. The new platfor

Sep 26, 2026
PPC Land

20i finds 88% of WordPress sites running outdated software as attacks rise

New analysis of 44 million sites shows outdated versions span all business sizes, with $391 billion in enterprise revenue exposed to unpatched flaws.

Sep 25, 2026
Cybersecurity News

WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments

WordPress administrators are being urged to patch a high-severity core vulnerability that can turn an anonymous comment into server-side command execution. Tracked as CVE-2026-93485 and demonstrated by the Comment2Shell proof-of-concept, the flaw is an unauthenticated stored cross-site scripting

Sep 25, 2026
Cybersecurity News

Hackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code

The critical WordPress vulnerability CVE-2026-87902 is being actively exploited, with activity progressing from reconnaissance to attempts to write malicious PHP files on vulnerable servers. The flaw affects WordPress Core versions 4.7.0 through 7.1.1 and has been fixed in WordPress 7.1.2 and bac

Sep 25, 2026
GBHackers

Exvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites

A new Malware-as-a-Service platform, Exvicy, is actively abusing compromised WordPress websites to deliver ClickFix lures disguised as Cloudflare Turnstile verification pages. Researchers at Sekoia assess with high confidence that the service is a copycat of the established ErrTraffic framework,

Sep 23, 2026
Press Gazette

Fifth of News UK website traffic was ‘non-human’ in past six months

<img alt="(Left to right) Brian Alvey, chief technology officer at Wordpress VIP, Tom Jackson, chief technology officer at News UK, and Carly Steven, director of SEO and editorial e-commerce at Daily Mail, speaking at Press Gazette's Future of Media Technology Conference sitting in armchai

Sep 23, 2026
Beta News

Update to WordPress 7.1.2 to fix a critical security flaw

WordPress has released an important update to address a serious security issue. The release of WordPress 7.1.2 fixes a critical unauthenticated path traversal vulnerability which is tracked as s CVE-2026-87902 and has a CVSS v4.0 score of 9.2 (Critical). Left unpatched, the flaw could allow an attac

Sep 23, 2026
therepository.email

WordPress 7.1.2 Patches Critical RCE Vulnerability, Attackers Begin Probing Within Hours

Attackers built probes from the patch diff and started scanning within hours of a fix for a critical WordPress core vulnerability that security engineer Robert Ressl first reported in July.

Sep 23, 2026
GBHackers

Critical WordPress Flaw Lets Unauthenticated Attackers Execute Remote Code

WordPress has released version 7.1.2 to address a critical path-traversal vulnerability, tracked as CVE-2026-87902, which could allow unauthenticated remote code execution (RCE) under specific server and theme configurations. This flaw carries a CVSS v4 score of 9.2 and affects WordPress versions

Sep 23, 2026
Help Net Security

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker

Sep 23, 2026
Cybersecurity News

Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In

WordPress has released version 7.1.2 to address a critical security vulnerability that could allow unauthenticated attackers to execute code on vulnerable websites under specific conditions. Site administrators should update immediately because successful exploitation may not require attackers to

Sep 23, 2026
Cybersecurity News

WordPress Malware Uses Hidden Plugin and Blockchain C2 to Stay Undetected

A newly identified WordPress malware strain is using a hidden plugin, stolen administrator access, and a blockchain-based command channel to remain active on compromised websites. The threat is built to survive common cleanup efforts while quietly collecting sensitive data from affected servers.

Sep 23, 2026
GBHackers

Stealthy WordPress Malware Uses Must-Use Plugin and Ethereum EtherHiding for Persistent Backdoor Access

A newly analyzed WordPress malware implant combines must-use plugin persistence, hidden administrator accounts, credential theft, cross-site propagation, and Ethereum-based EtherHiding to create an unusually resilient backdoor. The malicious code masquerades as an automated health-check and repor

Sep 23, 2026
scworld.com

New Exvicy malware-as-a-service framework copies rival's code

Exvicy operates as a ClickFix framework, distributing malware through compromised WordPress websites, according to Sekoia's Threat Detection & Research team.

Sep 22, 2026
BleepingComputer

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]

Sep 22, 2026
The Hacker News

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixe

Sep 22, 2026
Cybersecurity News

Hackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords

A suspected Chinese-speaking threat actor has used WordPress vulnerabilities to break into at least 49 organizations across 29 countries. The campaign exposed how a compromised website can become a launchpad for database theft, credential abuse, and wider network intrusion. The attackers exploite

Sep 22, 2026
GBHackers

Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data

A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business targets across 29 countries, stealing at least 18,566 sensitive records from one Western government organization. GreyNoise linked the activity

Sep 22, 2026
BleepingComputer

WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]

Sep 21, 2026
GBHackers

Click2Shell WordPress Flaw Lets Hackers Execute PHP Code and Take Over Websites

A recently disclosed WordPress vulnerability, known as Click2Shell, could let attackers execute remote PHP code on vulnerable sites after convincing a logged-in administrator to click a specially crafted link. WordPress version 7.1.1, released on September 17, 2026, addresses this issue. Research

Sep 21, 2026
Cybersecurity News

Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link

WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-

Sep 19, 2026
scworld.com

Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617

Podcast Segment: Bacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet – SWN #617. Bacteria, Spartans Invade Athens, Agentic AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet, and More on this episode of the Security Weekly News.

Sep 18, 2026
TechCrunchMajor Publication

Automattic names interim CFO after exec departures

Jeremy Klaperman, the CFO of the company's WordPress VIP Enterprise business unit, will act as CFO for the time being.

Sep 18, 2026
Cybersecurity News

Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution

A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than 100,000 sites that use the e-learning plugin, particularly installations that allow visitors to register as students. Tracked as CVE-2026-78175, t

Sep 18, 2026
GBHackers

Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability

More than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on August 23, 2026, by Wordfence Argus, an AI-a

Sep 18, 2026
Cybersecurity News

Brevo Supply Chain Attack Pushes WordPress Backdoors and ClickFix Malware to 100,000+ Sites

A supply-chain compromise involving Brevo briefly turned widely used website tools into a delivery channel for malware. Attackers inserted hostile JavaScript into services that customer websites load, exposing both visitors and WordPress administrators. The activity reached more than 100,000 cust

Sep 18, 2026
GBHackers

WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal

WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urged to update immediately due to the potential

Sep 18, 2026
Cybersecurity News

WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities

WordPress has released version 7.1.1, a security and maintenance update that fixes 11 vulnerabilities affecting the widely used content management system. Website owners and administrators are urged to install the update immediately to reduce the risk of cross-site scripting, authorization bypass

Sep 18, 2026
GBHackers

Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widgets to distribute a WordPress backdoor and Cl

Sep 18, 2026
Help Net Security

Most WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across t

Sep 18, 2026
therepository.email

WordPress 7.1.1 Ships 11 Security Fixes, Credits Anthropic and pwn.ai Again

More than 90 people contributed to WordPress 7.1.1, patching 11 vulnerabilities, including two reported by Anthropic and one by AI pentest firm pwn.ai.

Sep 18, 2026
scworld.com

Flaws in The Events Calendar WordPress plugin enable unauthenticated RCE

Both flaws can be exploited by leaving an anonymous comment on an event page.

Sep 17, 2026
BleepingComputer

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

Sep 15, 2026
The Zvi

The Bad Guy With An AI Named Claude

A lot of bad guys try to use Claude to do bad things. Mostly they fail. We think. Anthropic has disrupted a bunch of them, and offers an extensive report. If Anthropic is sharing the worst cases, or anything close … <a href="https://thezvi.wordpress.com/2026/09/15/the-bad-guy-with-an-ai-named-

Sep 15, 2026
GBHackers

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects p

Sep 15, 2026
Cybersecurity News

Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login

Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue affects Wholesale Lead Capture and turns a routine file-upload feature into a direct path to server access. The vulnerability, tracked as CVE-

Sep 15, 2026
GBHackers

WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites

Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in

Sep 15, 2026
Cybersecurity News

Critical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover

Two critical vulnerabilities in The Events Calendar WordPress plugin could allow unauthenticated attackers to take over vulnerable websites. The flaws affect more than 600,000 active installations. They can lead to remote code execution, administrator password resets, malware deployment, and full

Sep 15, 2026
The Cyber Express

4 in 5 Singapore Business Websites Have WordPress Vulnerabilities

<s

Sep 15, 2026
The Hacker News

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the di

Sep 14, 2026
WebProNews

Mullenweg’s Swift Return to Automattic Helm Exposes Boardroom Fractures at WordPress Parent

Matt Mullenweg reclaimed the CEO role at Automattic just two days after his board placed him on leave and installed the CFO as interim chief. The swift reversal, executed through in

Sep 14, 2026
WebProNews

Matt Mullenweg’s 48-Hour CEO Coup: How the WordPress Founder Reclaimed Automattic

Matt Mullenweg was placed on paid leave by Automattic's board on Sept. 9 after accusing directors of conspiracy. Two days later he declared himself back in control via Slack. The ra

Sep 11, 2026
GBHackers

WordPress Blocks High-Risk Plugin Releases With New AI-Powered Automated Security Review

WordPress has launched an automated security review system that uses multiple AI models and Jetpack Scan to analyze every plugin release before distributing it to websites via the WordPress.org update API. This new control is designed to prevent vulnerable or malicious plugin updates from reachin

Sep 11, 2026
Computer World

Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?

<p class

Sep 11, 2026
therepository.email

WordPress.org Can Now Automatically Block High-Risk Plugin Updates Before They Ship

AI and Jetpack Scan now review every plugin release during the Protect the Shire cooldown window, with risky updates blocked before they reach users.

Sep 10, 2026
Cybersecurity News

WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding a critical checkpoint to a distribution pipeline that had previously lacked one. The move follows a real-world incident in which a backdoor was

Sep 10, 2026
TechRadarTech Media

Automattic CEO Matt Mullenweg 'forced' into leave of absence by WordPress parent company board

Mullenweg apparently forced out as CEO – we don't know when (or if) he will return.

Sep 10, 2026
Help Net Security

WordPress adds automated security checks to block risky plugin releases

WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in

Sep 10, 2026
Implicator

Automattic Board Puts WordPress Co-Founder Matt Mullenweg on Paid Leave

Automattic's board voted on September 9 to put co-founder Matt Mullenweg on paid leave, installing finance chief Mark Davies as interim CEO. Mullenweg said he voted against it and got 50 minutes' notice. He still controls WordPress.org, which Automattic does not.

Sep 10, 2026
The VergeMajor Publication

Automattic CEO Matt Mullenweg placed on leave

Matt Mullenweg, the CEO of WordPress.com owner Automattic, has been placed on a paid leave of absence, as reported earlier by 404 Media. In an internal message by the outlet, Mullenweg claims Automattic chief financial officer Mark Davies "conspired" with board members to place him on leave. "They v

Sep 9, 2026
Digiday

ShopMy, Google and WordPress are among this year’s Digiday Technology Awards finalists

This year’s Digiday Technology Awards finalists reflect an industry adapting to a rapidly changing digital landscape, with AI-ready infrastructure, first-party data, privacy and operational efficiency emerging as defining priorities. Across publishing, commerce and advertising, technology lead

Sep 8, 2026
WebProNews

WordPress Under Siege: Critical Flaws in Popular Plugins Expose Millions to Takeover

Wordfence researchers uncovered critical unauthenticated file upload flaws in Elementor Pro and Super Forms affecting over six million WordPress sites. Both vulnerabilities, now pat

Sep 8, 2026
GBHackers

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to

Sep 4, 2026
scworld.com

SQL injection vulnerability in WordPress plugin affects millions of sites

The vulnerability, tracked as CVE-2026-19949, is a second-order SQL injection that impacts versions prior to 7.110.

Sep 3, 2026
therepository.email

Andy Peatling Left Automattic After 17 Years and Built Miles, an AI Design Agent for WordPress

He left Automattic thinking he was done with WordPress. Fourteen months later and after a lot of buzz, Andy Peatling has launched an AI design agent built entirely on native blocks.

Sep 3, 2026
GBHackers

WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover

A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely us

Sep 3, 2026
Cybersecurity News

WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks

A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 million active installations and has been fixed in version 7.110. The issue was re

Sep 3, 2026
therepository.email

WordPress Tightens Bug Bounty Scope After Monthly Security Reports Nearly Double to 773

Monthly reports to WordPress's HackerOne program have surged from a decade-long baseline of 20–30 to 773 in August, prompting the WordPress Security Team to change what it will accept.

Sep 2, 2026
therepository.email

Rank Math Pulls Controversial Support Agent as Matt Mullenweg Calls for Plugin Audits

The Rank Math plugin created admin-level passwords and sent them to group.one's servers before users accepted terms. Now, Matt Mullenweg wants mandatory audits for every plugin hosted on WordPress .org that phones home.

Sep 2, 2026
Cybersecurity News

WordPress Is Using AI to Find Security Flaws Before Hackers Can Exploit Them

WordPress has launched a new security effort that uses artificial intelligence to identify vulnerabilities in its core software before attackers can abuse them. The initiative comes as the project receives an increasing number of security reports, driven in part by rapid improvements in AI tools

Sep 1, 2026
GBHackers

WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited

The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the world’s most widely used content management system. This initiative, known as the Core Security Initiative, responds to a significant

Sep 1, 2026
therepository.email

WordPress Announces Core Security Initiative as AI-Driven Vulnerability Reports Hit Record Levels

The WordPress project has formalized a core security effort in response to 15x spike in reports and an unprecedented period of core security releases.

Sep 1, 2026

August 2026

therepository.email

Enqueue Returns to Sydney to Explore What AI Means for WordPress Developers

Last year's debut drew 80 people and proved the concept. Now The Code Company is going it alone, with an AI-first program and a spot on the AI Week Sydney calendar.

Aug 31, 2026
Rapid7 Blog

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, CheckPoint, Langflow, Ruby, and SPIP.

Aug 28, 2026
Marketing Tech News

DMWF Spotlight: Enterprise teams spend 16.6 hours a week trying to get named by AI. Better writing isn’t what fixes it.

Marketing teams now spend over 16 hours a week on how their brand turns up in AI answers. That’s two working days every week according to WordPress VIP’s “Future of the Web 2026” report. Most teams have no idea what it buys them. What’s really happening Someone asks ChatGPT or G

Aug 28, 2026
Cybersecurity News

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the backgrou

Aug 28, 2026
GBHackers

Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.

Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted payloads, fake reCAPTCHA prompts and fileless execution to deploy the Amatera information stealer on Windows systems. The campaign stands out

Aug 28, 2026
therepository.email

WordPress Signs Open Weights AI Letter Alongside Automattic and GoDaddy

More than 270 companies have asked US policymakers not to restrict open weight AI models. Automattic, GoDaddy, and now WordPress are among them.

Aug 28, 2026
Cybersecurity News

Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data

A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear research body and a marine engineering company that serves the Philippine Navy. The intrusion shows how unpatched internet-facing systems can expose d

Aug 27, 2026
therepository.email

WP Rocket Publishes WordPress 7.1 Fatal Error Post-Mortem, Estimates 10% of Sites Were Hit

A July 6 GitHub report identified the bug that led to fatal errors and suggested a fix. A post mortem reveals WP Rocket reviewed it, couldn't reproduce it, and moved on.

Aug 27, 2026
therepository.email

Wordfence’s New AI Agent Chains Six Flaws Into a Critical Unauthenticated RCE in Popular Avada Theme

Wordfence launched an AI agent earlier this year that hunts wide. Now, it has one that hunts deep, and its first big find is a critical RCE in one of the most popular WordPress themes.

Aug 26, 2026
GBHackers

Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts

A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19632, has a CVSS score of 9.8 and affects all TranslatePre

Aug 26, 2026
Cybersecurity News

WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. Tran

Aug 26, 2026
Martech Zone

SaaS Isn’t Dead. Your UI Is.

Yesterday: I uploaded questions about some content for approval in Google Workspace. I never logged in. I updated Trello and found my new tasks. Without logging in. I updated landing pages and their forms in WordPress. I never logged in. I updated a disqualification picklist in our pipeline process

Aug 25, 2026
therepository.email

Playground Team Ships Legacy Version Support, Making 23 Years of WordPress History Available in the Browser

Playground can now boot any of 55 WordPress versions in seconds, no old PHP runtimes, database configs, and local server stacks required.

Aug 25, 2026
Cybersecurity News

Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts

Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have been linked

Aug 25, 2026

Toolradar Research

See WordPress in context: The SaaS Press Index 2026

We analyzed 6,704 press mentions across 290 outlets to rank which SaaS tools win coverage. Find WordPress's position relative to the 488 most-covered tools.

Read the report

Explore WordPress

Press coverage is one signal. See the full picture.