#plugin


Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

Sep 18, 2026 // 23:48

A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a […]

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Sep 16, 2026 // 14:10

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the […]

Acronis warns of actively exploited flaw in its cPanel backup plugin

Sep 16, 2026 // 00:56

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in […]

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Sep 15, 2026 // 23:57

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the […]

Hackers target WordPress sites via third-party WooCommerce plugin

Sep 15, 2026 // 17:56

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. The flaw is […]

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

Sep 14, 2026 // 19:00

WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as […]

WordPress backup plugin flaw exposes millions of sites to takeover attacks

Sep 3, 2026 // 00:17

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control […]

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Aug 29, 2026 // 19:30

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to […]

GiveWP WordPress donation plugin flaw lets hackers execute server commands

Aug 28, 2026 // 21:37

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. The security issue is […]

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

Jul 24, 2026 // 13:31

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up […]

1 2 3 4 Next