Skip to content
WordPress logo

WordPress in the Media

158 mentions across press, blogs, and newsletters

Top coverageWiredTechCrunchThe VergeTechRadarMashable
3 major ·22 tech media

June 2026

TechRadarTech Media

‘Companies that can serve both human and agent audiences will be the ones that survive’: WordPress VIP CTO spells out the future of SEO, GEO and more

‘For decades, we’ve all built websites for Google’: WordPress VIP’s CTO argues that publishers must optimize websites for both human readers and AI agents, without forgetting about trust.

Jun 13, 2026
Martech Zone

Formidable Forms: How to Build a WordPress Plugin That Automatically Assigns Sales Territories

Formidable Forms has built-in conditional logic, and it's genuinely good. You can show or hide fields, branch confirmation messages, and route email actions based on rules. We've had exceptional responses to sending a confirmation back to the dealers who submitted a demo request, with most of them u

Jun 12, 2026
Dataconomy

Critical UpdraftPlus flaw puts 3 million WordPress sites at risk

<img alt="Critical UpdraftPlus flaw puts 3 million WordPress sites at risk" class="webfeedsFeaturedVisual wp-post-image" height="780" src="https://dataconomy.com/wp-content/uploads/2026/06/critical-updraftplus-flaw-puts-3-million-wordpress.jpg" style="display: block; margin: auto; margin-bottom: 10p

Jun 11, 2026
PPC Land

Kinsta adds free bot protection to all WordPress plans

Kinsta on June 9 launched Bot Protection for all plans, giving WordPress owners control over AI crawlers and automated traffic inside MyKinsta at no added cost.

Jun 10, 2026
therepository.email

CERN Moves the Birthplace of the Web to WordPress

A six-month CMS evaluation, more than 183,000 items of content, and 580 websites later, CERN's years-long WordPress migration is entering its final phase.

Jun 10, 2026
therepository.email

WordPress.org Launches ‘Protect the Shire’ Initiative, Adds 24-Hour Cooldown for Plugin and Theme Auto-Updates

Every release across WordPress.org's 78,000 plugins and themes now faces AI-powered review before auto-updates roll out — and a Wapuu named Gandalf is on the job.

Jun 9, 2026
therepository.email

WordCamp Europe Draws 2,458 to Kraków, Bouncing Back From Basel Dip as CERN Goes Live on WordPress

A 43% jump in ticket sales, CERN's flagship site going live on WordPress, and an eight-hour afterparty. Kraków delivered the WCEU the community wanted.

Jun 9, 2026
TechRadarTech Media

WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin

A popular WordPress plugin is once again being leveraged in website takeover attacks.

Jun 9, 2026
Security Affairs

Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access

Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked. Researcher h0xilo submitted a flaw in Everest Forms Pro for WordPress, tracked as CVE-2026-3300, to Wordfence&#8217;s bug bounty program and earned $325 for it. W

Jun 8, 2026
SecurityWeek

Everest Forms Vulnerability Exploited to Hack WordPress Sites

The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites a

Jun 8, 2026
BleepingComputer

Critical Everest Forms Pro flaw exploited to take over WordPress sites

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]

Jun 6, 2026
Ahrefs BlogTech Media

Automated SEO: What It Is and How It Works in 2026

It cleans and filters the data, then builds an updated WordPress draft for each. It then emails me preview links. I skim the drafts, make sure all looks okay, then click one button (“Approve all”) and they go live, restamped&#8230;Read more &#8250

Jun 5, 2026
The Hacker News

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution

Jun 5, 2026
Infosecurity Magazine

Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites

Critical Everest Forms Pro RCE flaw exploited to create rogue WordPress admin accounts

Jun 4, 2026
Cybersecurity News

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable websites. The flaw, tracked as CVE-2026-3300 with a CVSS score of 9.8, affects

Jun 4, 2026
TechRadarTech Media

In the AI era, is Shopify the new WordPress?

WordPress saw a generation of creators and Shopify has done something similar for commerce. Could there be parallels?

Jun 4, 2026
therepository.email

Gutenberg 23.3 Ships Experimental Customizable WordPress Dashboard

A drag-and-drop, widget-based dashboard has landed in the Gutenberg plugin as an experiment, and it's the admin's biggest structural shakeup in years.

Jun 4, 2026
therepository.email

Contributors Launch FSE-Style Outreach Program to Get Real-Time Collaboration Ready for WordPress 7.1

A new outreach program modeled on the FSE experiment wants early adopters testing collaborative editing across hosting environments before Beta 1 on July 15.

Jun 4, 2026
therepository.email

WordPress.org Overhauls 20-Year-Old Jobs Board, Adds Career Features to Profiles

WordPress.org's long-dormant jobs board has been redesigned with profile integration and an "open to work" toggle in the first major overhaul of the site in over a decade.

Jun 4, 2026
Cybersecurity News

WordPress Plugin Vulnerability Exposes 500,000+ Websites to Privilege Escalation Attacks

A critical security flaw in the widely used Kirki WordPress plugin has exposed over 500,000 websites to potential account takeover attacks, with researchers warning that approximately 150,000 sites are actively vulnerable due to affected versions. Tracked as CVE-2026-8206 with a CVSS score of 9.8

Jun 3, 2026
SiliconAngle

WP Engine bolts bot management onto Global Edge Security as AI crawlers surge

WordPress hosting company WP Engine Inc. today added bot management to its Global Edge Security service, giving site operators a way to filter the growing volume of automated and artificial intelligence traffic reaching their sites. The Austin, Texas-based company runs more than 5 million WordPre

Jun 3, 2026
SecurityWeek

Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs

Threat actors are exploiting vulnerable Kirki and Burst Statistics deployments to elevate privileges and take over websites. The post Kirki, Burst Statistics WordPress Plugin Flaws

Jun 3, 2026
GBHackers

WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites

A critical security flaw in the Kirki – Freeform Page Builder, Website Builder &#38; Customizer WordPress plugin is exposing sites to account takeover and privilege escalation attacks, with roughly 150,000 estimated to be running vulnerable versions introduced in the 6.0 release. Tracked as CVE-2

Jun 3, 2026
TechRadarTech Media

Steam Community Profiles abused as C2 network in new WordPress malware infection campaign

A new cheeky malware campaign abuses the comment section as a roadsign to malware

Jun 3, 2026
BleepingComputer

Critical Kirki flaw exploited to hijack WordPress admin accounts

Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators. [...]

Jun 2, 2026
Cybersecurity News

WordPress Malware Abuses Steam Community Profiles for C2 Operations

A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to communicate with infected sites, hiding command instructions inside Steam Community profile comments and

Jun 2, 2026
Hackread

New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions

GoDaddy researchers found WordPress malware using Steam Community profile comments to hide encoded command and control data, with nearly 1,980 sites affected.

Jun 2, 2026
dev.to

Four HTTP security headers every WordPress site should set

TL;DR: Four response headers, a few minutes of work, most of the header-level security gap closed. Exact values below, plus a one-line curl to check any site. Run this against your own site first: <pre class=

Jun 2, 2026
MashableTech Media

Stop paying monthly for web hosting — this 5-website lifetime subscription is only $80

Hostnirvana is a WordPress web hoster for 5 websites, and it's only $80 for life

Jun 2, 2026
Cybersecurity News

Critical WP Maps Pro Vulnerability Allow Attackers to Create Administrator Account

A critical security vulnerability in the popular WP Maps Pro WordPress plugin could allow attackers to gain full control of affected websites by creating unauthorized administrator accounts. The flaw, tracked as CVE-2026-8732 with a CVSS score of 9.8, impacts all plugin versions up to 6.1.0 and h

Jun 2, 2026
SecurityWeek

WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites

The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vulnerability Exploited to Tak

Jun 1, 2026
TechRadarTech Media

WP Maps Pro plugin flaw to create admin accounts on WordPress sites saw 3,600 attempts in a single day

Thousands of attacks were seen in a single day as a patch is rolled out.

Jun 1, 2026

May 2026

BleepingComputer

WP Maps Pro bug exploited to create admin accounts on WordPress sites

Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication. [...]

May 31, 2026
The Cyber Express

WP Maps Pro Vulnerability Exposed 15,000 WordPress Sites to Site Takeover

A critical vul

May 29, 2026
GBHackers

Fake Adobe Document Cloud Pages Spread ScreenConnect Malware

Hackers are actively exploiting trust in Adobe Document Cloud by using fake delivery pages to install remote access malware. The campaign leverages a sophisticated phishing kit named “RatPressto,” which abuses compromised WordPress sites and legitimate software to evade detection while targeting

May 29, 2026
Neowin

A year of web hosting for Managed WordPress on Hostinger is now 91% off

Launch Up to 50 WordPress Sites With Free Domain, SSL, Email, Backups &amp; Lightning-Fast LiteSpeed Hosting. <a href="https://www.neowin.net/d

May 28, 2026
Cybersecurity News

Russian Hacker Used Jailbroken Gemini to Steal Admin Credentials and Drain Crypto Wallets

A solo Russian-speaking threat actor leveraged a jailbroken instance of Google Gemini to run a five-year MAGA-themed influence operation, crack WordPress administrator credentials, and empty at least one victim&#8217;s cryptocurrency wallet, all at near-zero cost using stolen API keys. In May 202

May 25, 2026
Help Net Security

$20 per zero-day is already the WordPress plugin reality

Vulnerability researchers have spent the past year arguing about whether AI agents can find real bugs at scale or whether they mostly generate noise. A pipeline built in three days by researchers from TrendAI and CHT Security supplies an answer, along with a price tag that the security industry w

May 22, 2026
TechRadarTech Media

Another top WordPress plugin exploited — hackers target credit card details, here's what you need to know

Funnel Builder WordPress plugin is being exploited to steal people's credit cards but the flaw has since been patched.

May 18, 2026
Cybersecurity News

1 Million WordPress Sites Affected by Avada Builder File Read and SQL Injection Flaws

A widely used WordPress plugin powering over one million websites has been hit by two serious vulnerabilities that could allow attackers to steal sensitive data and access server files. Security researchers warn that the flaws in the Avada Builder plugin could be actively exploited if sites remai

May 18, 2026
GBHackers

1 Million WordPress Websites Exposed by Avada Builder Security Vulnerabilities

A widely used WordPress plugin powering over one million websites has been found vulnerable to two serious security flaws that could expose sensitive data and server files. Security researchers warn that the issues in the Avada Builder plugin could allow both authenticated and unauthenticated att

May 18, 2026
Cybersecurity News

Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks

A critical vulnerability in a widely used WordPress plugin has exposed over 200,000 websites to full account takeover, raising urgent concerns across the security community. Discovered on May 8, 2026, by Wordfence’s AI-powered PRISM threat intelligence platform, the flaw affects the Burst Statist

May 18, 2026
Security Affairs

Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores

Attackers are exploiting a critical flaw in the WordPress Funnel Builder plugin to inject skimming code into WooCommerce checkout pages. A critical vulnerability in the WordPress Funnel Builder plugin is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages, accordi

May 17, 2026
BleepingComputer

Funnel Builder WordPress plugin bug exploited to steal credit cards

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]

May 15, 2026
BleepingComputer

Avada Builder WordPress plugin flaws allow site credential theft

Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database. [...]

May 15, 2026
WiredMajor Publication

HostGator Promo Codes: 76% Off for April 2026

Unlock massive savings on HostGator web hosting, WordPress, VPS, and business email plans with our exclusive HostGator promo codes and deals.

May 15, 2026
BleepingComputer

Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin

Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites. [...]

May 14, 2026
TechRadarTech Media

Over a million WordPress sites hit in plugin flaw — so patch now or face the consequences

A popular WordPress plugin was found carrying two flaws that can cause data leaks.

May 14, 2026
GBHackers

Critical WordPress Plugin Flaw Allows Unauthorized Access to Websites

A critical vulnerability in a widely used WordPress plugin has exposed more than 200,000 websites to potential takeover, raising urgent concerns across the security community. Security researchers at Wordfence, using their AI-driven PRISM platform, have uncovered a severe authentication bypass fl

May 14, 2026
TechRadarTech Media

GoDaddy aims to solve WordPress complexity with new AI tool

Airo brings conversational AI to the world’s most popular CMS

May 14, 2026
CMOtech UK

Cloudways launches Site Manager for WordPress agencies

The new tool aims to cut manual upkeep for agencies juggling dozens of WordPress sites, with updates and checks now handled in one place.

May 14, 2026
Infosecurity Magazine

Avada Builder Flaws Expose One Million WordPress Sites

Avada Builder flaws allowed file read and SQL injection on one million WordPress sites

May 13, 2026
Cybersecurity News

Hackers Abuse Google Ads to Steal Users GoDaddy ManageWP login Credentials

Hackers are using fake Google ads to steal login credentials from ManageWP users, GoDaddy&#8217;s popular platform for managing WordPress websites from a single dashboard. The campaign, which researchers have dubbed &#8220;WrongPress,&#8221; plants a fraudulent sponsored search result directly ab

May 7, 2026
BleepingComputer

Hackers abuse Google ads for GoDaddy ManageWP login phishing

A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy's platform for managing fleets of WordPress websites. [...]

May 6, 2026
Search Engine Land

Your managed WordPress might be blocking AI bots and you can’t see it

<img alt="Your managed WordPress might be blocking AI bots and you can&#039;t see it" class="attachment-large size-large wp-post-image" height="1080" src="https://searchengineland.com/wp-content/seloads/2026/05/Your-managed-WordPress-might-be-blocking-AI-bots-and-you-cant-see-it.png" width="192

May 6, 2026
Nerds.xyz

Rocket.net adds MCP integration, lets AI agents run your WordPress sites

<img alt="Rocket.net adds MCP integration, lets AI agents run your WordPress sites" class="attachment-large size-large wp-post-image" height="469" src="https://nerds.xyz/wp-content/uploads/2026/05/rocketne

May 5, 2026
GBHackers

CISA Alert Highlights Active Exploitation of cPanel & WHM Security Bug

The US Cybersecurity and Infrastructure Security Agency (CISA) has raised the alarm over a critical security vulnerability affecting WebPros cPanel &#38; WebHost Manager (WHM) and WP2 (WordPress Squared). On April 30, 2026, CISA officially added this flaw to its Known Exploited Vulnerabilities (K

May 4, 2026
CMOtech UK

Chancery Lane Project launches AI-friendly WordPress plugin

Chancery Lane Project launches AI-friendly WordPress plugin to cut token use and energy demand as websites adapt to machine readers.

May 4, 2026
TechRadarTech Media

This free WordPress tool could save businesses billions every year by slashing the AI tokens needed to read the web — saving enough electricity to power the entire USA for 24 hours

Free WordPress plugin could slash AI web traffic data use enough to rival daily USA electricity consumption if widely adopted.

May 2, 2026

April 2026

TechRadarTech Media

Tired of WordPress? It's time to consider Joomla

If you're looking for another solution, this could be it

Apr 30, 2026
Cybersecurity News

WordPress Plugin Hacked Since 2020 to Inject Malicious Code Silently

A massive supply chain attack has been uncovered in the Quick Page/Post Redirect Plugin, a popular WordPress plugin with over 70,000 active installations. Security researcher Austin Ginder discovered a dormant backdoor introduced five years ago that silently injects arbitrary code into websites.

Apr 30, 2026
GBHackers

Backdoored WordPress Plugin Abuses Remote Update Checker for Silent Code Delivery

A long-dormant backdoor has been uncovered in the &#8220;Quick Page/Post Redirect Plugin,&#8221; a popular WordPress add-on with over 70,000 active installations. The tampered plugin, specifically version 5.2.3, contained two distinct malicious features. First, it featured a passive content injec

Apr 30, 2026
Security Affairs

Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844)

Attackers exploit a Breeze Cache flaw (CVE-2026-3844) to upload files without login. Wordfence researchers detected over 170 attacks. Threat actors are exploiting a critical flaw, tracked as CVE-2026-3844 (CVSS score of 9.8), in the Breeze Cache WordPress plugin, allowing them to upload files to a s

Apr 25, 2026
TechRadarTech Media

I took an easier route to create my new website, and so should you

If you're tired of WordPress bloat, you might want to consider ClassicPress.

Apr 25, 2026
BleepingComputer

Hackers exploit file upload bug in Breeze Cache WordPress plugin

Hackers are actively exploiting a critical vulnerability in the Breeze Cache plugin for WordPress that allows uploading arbitrary files on the server without authentication. [...]

Apr 23, 2026
WebProNews

Mullenweg’s Override: Akismet’s Last-Minute Slot in WordPress 7.0 Sparks Core Clash

Matt Mullenweg overruled WordPress core committers to add Automattic's Akismet to the 7.0 Connectors screen, igniting process fights and exposing Automattic tensions amid release de

Apr 20, 2026
WebProNews

Buyer Spends Six Figures on WordPress Plugins, Plants Backdoors in All 31 for Mass Compromise

A six-figure Flippa buyout turned 31 trusted WordPress plugins malicious, backdooring thousands of sites with SEO spam after eight months dormant. No ownership alerts from WordPress

Apr 19, 2026
TechRadarTech Media

'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to create hidden admin accounts

A critical WordPress plugin flaw allows attackers to bypass authentication and gain full administrative control, exposing websites to data theft and malware attacks.

Apr 18, 2026
TechRepublicTech Media

Malicious WordPress Plugins with Backdoors Compromise Thousands of Websites

More than 30 WordPress plugins were shut down after a supply-chain backdoor compromised thousands of sites through the Essential Plugin portfolio. The post Malicious WordPress Plugins with

Apr 16, 2026
BleepingComputer

WordPress plugin suite hacked to push malware to thousands of sites

More than 30 WordPress plugins in the EssentialPlugin package have been compromised with malicious code that allows unauthorized access to websites running them. [...]

Apr 15, 2026
Techspot

Popular WordPress plugins backdoored after ownership change, putting thousands of websites at risk

<img height="560" src="https://www.techspot.com/images2/news/ts3_thumbs/2026/04/2026-04-15-ts3_thumbs-c1a.jpg" style="padding: 15px 0;" title="Popular WordPress plu

Apr 15, 2026
TechRadarTech Media

WordPress websites under attack — expert report says dozens of plugins hijacked to target thousands of sites

A malicious actor found a struggling WordPress plugin company, bought it, and introduced malware to each product.

Apr 15, 2026
The Next WebTech Media

Someone bought 30 WordPress plugins and planted backdoors in all of them

An attacker bought 30+ WordPress plugins (Essential Plugin portfolio) on Flippa for six figures, planted a PHP deserializati

Apr 15, 2026
FirstPost

WordPress plugins used across thousands of websites found with malicious backdoors - Is your site at risk?

Dozens of WordPress plugins were taken offline after a suspected supply-chain attack involving a malicious backdoor added following a change in ownership

Apr 15, 2026
Cybersecurity News

Hackers Hide Backdoor in Trusted WordPress Plugins for 8 Months Before Activating Malware

A group of trusted WordPress plugins quietly carried a hidden backdoor for eight full months, and nobody noticed until the damage had already been done. The attack, uncovered in April 2026, did not begin with a dramatic breach. It started with the silent purchase of a legitimate plugin business o

Apr 15, 2026
GBHackers

Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign

Hackers secretly planted a remote code-execution backdoor in more than 30 popular WordPress plugins, leaving it dormant for about 8 months before activating malware that rewrote wp-config.php and injected cloaked SEO spam at scale. The incident centers on “Essential Plugin,” a portfolio of 30+ fr

Apr 15, 2026
WebProNews

The Quiet Sabotage: How Backdoors Were Planted in Dozens of WordPress Plugins Powering Thousands of Websites

Attackers planted backdoors in dozens of WordPress plugins through the official repository, compromising thousands of websites by exploiting stolen developer credentials and abandon

Apr 15, 2026
Cybernews

WordPress plugins taken offline after a developer found 30 injected with malicious code

WordPress plugins taken offline after a

Apr 15, 2026
Dataconomy

Dozens of WordPress plug-ins removed after backdoor discovered

<img alt="Dozens of WordPress plug-ins removed after backdoor discovered" class="webfeedsFeaturedVisual wp-post-image" height="1015" src="https://dataconomy.com/wp-content/uploads/2026/04/dozens-of-wordpress-plug-ins-removed-after-backdoo.jpg" style="display: block; margin: auto; margin-bottom: 10px

Apr 15, 2026
TechCrunchMajor Publication

Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites

Dozens of WordPress plug-ins were allegedly hijacked to push malware after they were sold to a new corporate owner.

Apr 14, 2026
GBHackers

WordPress Plugin Vulnerability Enables Admin Takeover via Auth Bypass

A newly disclosed vulnerability, tracked as CVE-2026-1492, has been identified in the User Registration &#38; Membership plugin for WordPress, exposing websites to critical authentication bypass and privilege escalation risks. Affecting versions up to 5.1.2, the vulnerability allows remote attack

Apr 13, 2026
WebProNews

Cloudflare’s Quiet Power Play: How a $40 Billion Infrastructure Giant Is Trying to Reshape the Open Web

Cloudflare's acquisition of Em Dash and aggressive courtship of disaffected WordPress developers signals a serious bid to build a competing CMS on its global infrastructure — raisin

Apr 10, 2026
The VergeMajor Publication

Cloudflare made a WordPress for AI agents

Cloudflare, the cloud provider that connects millions of sites to the internet, wants to "fix" another digital giant: WordPress. It announced a new open-source system, called EmDash, that's supposed to address the "core problems that WordPress cannot solve" - and they want to do it by allowing AI ag

Apr 10, 2026
TechRadarTech Media

Top WordPress Slider plugin hijacked to spread malware — here's what to look out for

A tainted version was pushed as an update to more than 800,000 active websites.

Apr 10, 2026
BleepingComputer

Smart Slider updates hijacked to push malicious WordPress, Joomla versions

Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors. [...]

Apr 9, 2026
TechRadarTech Media

'A more secure, scalable platform that runs on modern infrastructure and supports AI-native workflows': Why Cloudflare's new EmDash is the "spiritual successor" to WordPress

Cloudflare outlines its vision for EmDash as a modern CMS designed to improve security, support AI-native workflows, and modernize how websites are built and managed.

Apr 8, 2026
Infosecurity Magazine

Critical Vulnerability in Ninja Forms Exposes WordPress Sites

Ninja Forms File Upload RCE via unauthenticated arbitrary file upload; update to 3.3.27 immediately

Apr 8, 2026
SecurityWeek

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover

The vulnerability allows hackers to upload arbitrary files to a site’s server and achieve remote code execution. The post Hackers Targeting Ninja Forms Vulnerability

Apr 8, 2026
TechRepublicTech Media

Build Faster, Launch Smarter: $207 off WordPress Hosting

Launch and manage up to 50 WordPress sites with fast, reliable hosting, built-in tools, plus 24/7 support. The post Build Faster, Launch Smarter: $207 off WordPress Hosting appeared first on <a href="https://

Apr 8, 2026
BleepingComputer

Hackers exploit critical flaw in Ninja Forms WordPress plugin

A critical vulnerability in the Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, which can lead to remote code execution. [...]

Apr 7, 2026
MashableTech Media

Launch 50 websites for just $20 with this all-in-one hosting plan

Building and growing websites has never been easier with this Hostinger Business Web Hosting for Managed WordPress subscription.

Apr 7, 2026
GBHackers

50,000 WordPress Sites Running Ninja Forms Vulnerable to Critical File Upload RCE

A severe security flaw has been discovered in the Ninja Forms File Upload plugin, a widely utilized WordPress add-on that allows website administrators to accept documents, images, and other media from their visitors. Tracked officially as CVE-2026-0740, this unauthenticated arbitrary file upload

Apr 7, 2026
Hackread

Cloudflare Targets WordPress With New AI-Powered EmDash CMS

Cloudflare launches EmDash CMS, an AI-powered platform built to fix WordPress security flaws with sandboxed plugins, serverless scaling, and passkey auth.

Apr 6, 2026
GBHackers

Hackers Breach ILSpy WordPress Domain to Deliver Malware

The official WordPress website for ILSpy, a highly popular open-source tool used by software developers to examine .NET code, has been compromised. Hackers successfully breached the site to redirect visitors and deliver malware, turning a trusted developer resource into a dangerous trap. The Redi

Apr 6, 2026
Neowin

[Deal Alert] 1-Year subscription to Hostinger Web Hosting for Managed WordPress now 91% off

Launch Up to 50 WordPress Sites With Free Domain, SSL, Email, Backups &amp; Lightning-Fast LiteSpeed Hosting. <a href="https://www.neowin.net/d

Apr 5, 2026
WebProNews

The CMS Isn’t Dead — It Just Doesn’t Look Like It Used To

The monolithic CMS — where content storage, editing, and rendering live under one roof — is giving way to decoupled, API-first architectures. A veteran WordPress developer's essay c

Apr 4, 2026
DevClass

Cloudflare previews 'EmDash' – an AI-driven rebuild of WordPress in TypeScript

The world's most popular CMS has been remade with the help of AI. Cloudflare has released EmDash version 0.1, described as a rebuild of the WordPress CMS (content management system) but using TypeScript rather than PHP. In contrast to the one week claimed for recreating Next.js using agentic AI, Cl

Apr 3, 2026
TechRadarTech Media

'I think EmDash was created to sell more Cloudflare services': WordPress co-founder Matt Mullenweg gives his verdict on Cloudflare's EmDash

WordPress co-founder Mullenweg isn't too critical about EmDash or Cloudflare, says he sees it as a commercial opportunity, not a 'spiritual successor'.

Apr 3, 2026
CSO Online

Cloudflare’s new CMS is not a WordPress killer, it’s a WordPress alternative

Cloud

Apr 3, 2026
Computer World

Cloudflare’s new CMS is not a WordPress killer, it’s a WordPress alternative

Cloud

Apr 3, 2026

Toolradar Research

See WordPress in context: The SaaS Press Index 2026

We analyzed 6,704 press mentions across 290 outlets to rank which SaaS tools win coverage. Find WordPress's position relative to the 488 most-covered tools.

Read the report

Explore WordPress

Press coverage is one signal. See the full picture.