BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...
A critical security vulnerability in the Pods WordPress plugin could allow unauthenticated attackers to seize ...
Selular.ID – Pakar keamanan siber mengungkapkan temuan bahaya mengenai lebih dari 2.000 situs web berbasis WordPress yang ...
A ransomware affiliate weaponized Claude Code to autonomously steal LDAP credentials, backdoor VPNs, and exfiltrate SQL ...
You’ve probably heard of GitHub. If you’re anywhere near the tech world, it’s virtually impossible to avoid. It’s the undisputed king of version control for ...
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign ...
More than 40,000 WordPress sites have been exposed to an authentication bypass flaw in the User Profile Builder plugin that ...
WordPress sites face active attacks exploiting two miniOrange SAML flaws that can be chained to bypass authentication and ...
Wordfence was notified of the compromise on August 7 and published its analysis the following day. It affects BdThemes, an Elementor add-on vendor whose plugins are distributed through the official ...
WordPress has patched CVE-2026-65640, a high-severity vulnerability that allows authenticated attackers to execute arbitrary code.
The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication.