#plugin


Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Jun 20, 2026 // 13:21

Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites. The vulnerability, tracked as […]

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

Jun 19, 2026 // 23:57

Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. The flaw is tracked as CVE-2026-4020 […]

CISA orders feds to patch max severity Joomla plugin flaw by Friday

Jun 17, 2026 // 15:17

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) […]

CISA warns of another cPanel plugin flaw exploited in attacks

Jun 16, 2026 // 14:17

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) […]

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

Jun 16, 2026 // 09:10

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring […]

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

Jun 16, 2026 // 08:50

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring […]

OptinMonster WordPress plugin hacked in CDN supply-chain attack

Jun 15, 2026 // 22:57

WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive’s content distribution network (CDN). Of the three products, the […]

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

Jun 15, 2026 // 22:50

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into […]

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Jun 5, 2026 // 13:16

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, […]

CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

May 27, 2026 // 13:16

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the […]