WordPress Security

13
Mar
Formidable Forms Vulnerability Let Attackers Reuse Low-Value Stripe Payments for Higher-Cost Purchases

Formidable Forms Vulnerability Let Attackers Reuse Low-Value Stripe Payments for Higher-Cost Purchases

A Formidable Forms vulnerability affecting WordPress sites could let attackers reuse low-value Stripe payments to complete more expensive purchases without paying the full amount.
3 min read
12
Mar
WordPress Releases 6.9.4 After Incomplete Security Fixes in Versions 6.9.2 and 6.9.3

WordPress Releases 6.9.4 After Incomplete Security Fixes in Versions 6.9.2 and 6.9.3

WordPress released version 6.9.4 after discovering that earlier updates failed to fully apply fixes for ten security vulnerabilities affecting versions up to 6.9.1.
4 min read
31
Dec
Vulnerability Discovered in Redirection for Contact Form 7 WordPress Plugin

Vulnerability Discovered in Redirection for Contact Form 7 WordPress Plugin

A vulnerability in the Redirection for Contact Form 7 WordPress plugin allows unauthenticated attackers to upload or copy files under certain server configurations. Users are advised to update to version 3.2.8 or later.
1 min read
24
Nov
Critical W3 Total Cache Vulnerability Exposes Over One Million WordPress Sites to Remote Code Execution

Critical W3 Total Cache Vulnerability Exposes Over One Million WordPress Sites to Remote Code Execution

A critical vulnerability in the W3 Total Cache WordPress plugin allows unauthenticated PHP command injection, leaving hundreds of thousands of sites exposed. Learn how CVE-2025-9501 works, its risks, and the urgent steps administrators should take to secure their sites.
2 min read
16
Oct
WPBakery Plugin Vulnerability Could Let Insiders Slip in Malicious Code

WPBakery Plugin Vulnerability Could Let Insiders Slip in Malicious Code

A newly disclosed vulnerability in the WPBakery Page Builder plugin allows authenticated users to inject malicious code into WordPress sites. Learn what’s affected, why it matters, and how to secure your site from this stored XSS flaw.
2 min read
13
Oct
Severe WordPress Plugin Flaws Put 20,000+ Travel Websites at Risk

Severe WordPress Plugin Flaws Put 20,000+ Travel Websites at Risk

Two critical vulnerabilities in the WP Travel Engine plugin put over 20,000 WordPress travel sites at risk. Both allow unauthenticated attackers to take full control of websites. Immediate updates are strongly advised.
2 min read
27
Nov
Critical Vulnerability in WordPress Anti-Spam Plugin Exposes 200,000+ Websites to Attack

Critical Vulnerability in WordPress Anti-Spam Plugin Exposes 200,000+ Websites to Attack

Discover the critical vulnerability in the CleanTalk Anti-Spam WordPress plugin, affecting 200k+ sites. Learn how attackers exploit reverse DNS spoofing for unauthorized access and how to secure your site with updates and proactive measures. Stay protected with these essential tips!
2 min read