02 Oct, 2026

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. Threat actors can exploit the flaw by tricking a logged-in administrator into opening a malicious link, causing the victim’s authenticated session to perform a REST API action permitted by their account. On default installations, […]

2 mins read

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. Initial attack traffic was only for reconnaissance and started less than five hours after the patch was released in WordPress 7.1.2. Malicious activity increased by ten times, and attackers […]

3 mins read

Brevo supply-chain attack injected ClickFix scripts on customer sites

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. The customer relationship management and digital marketing company says the attackers used the API key to create a malicious Cloudflare Worker that modified content at […]

4 mins read

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Over the past months, researchers identified more than 5,400 hacked websites, most of them built on WordPress and PrestaShop. The initial compromise method remains unknown, but each site was injected […]

2 mins read

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. The plugin is used to back up, export, import, and move entire websites, including their databases, media, themes, and plugins, between servers or domains. The security flaw […]

2 mins read

Google Blogger locks hundreds of blogs in malware false positive

Google has locked hundreds of Blogger websites after a false positive claimed they violated its “Malware and Similar Malicious Content” policy, with some sites actually deleted from the platform. The issue began on August 4, and it appears to affect many legitimate blogs that do not host malware or have malicious scripts. As seen by […]

2 mins read

Australia warns of global campaign targeting vulnerable CMS platforms

The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. The government agency says that many Australian businesses have already been affected by the malicious activity, with webshells being deployed on their sites. Webshells provide persistent access to the compromised sites and allow […]

2 mins read

ShapedPlugin update flow hacked to infect WordPress sites

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor’s official update system. The malware delivered this way installed a fake plugin that impersonates WooCommerce components, steals credentials, and grants operators remote file-writing capabilities. ShapedPlugin is a WordPress plugin vendor specializing in front-end/UI […]

3 mins read

WP Maps Pro bug exploited to create admin accounts on WordPress sites

Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication. The vulnerability, tracked as CVE-2026-8732, has a critical severity rating and impacts WP Maps Pro versions 6.1.0 and older. It was discovered and reported by security researcher David Brown. WP Maps Pro […]

2 mins read

Drupal critical update to fix bug with high exploitation risk

Drupal has announced a “core security release” scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure. Administrators are urged to reserve time for core updates on May 20 between 17:00 and 21:00 UTC. Website administrators running versions 8 or 9 are strongly recommended to upgrade to at […]

1 min read