Your WordPress News Dashboard

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms

On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible… Continue Reading →

5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin

On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations. This vulnerability makes it possible for unauthenticated attackers to… Continue Reading →

Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin

On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulnerability makes it possible for unauthenticated attackers to gain administrator access when Hub… Continue Reading →

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)

Last week, there were 240 vulnerabilities disclosed in 184 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 105 Vulnerability Researchers that contributed to WordPress Security last week. Review those… Continue Reading →

Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales

A year ago we wrote that we’d put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay ahead of the threat actors attacking the sites we protect…. Continue Reading →

400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin

On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for unauthenticated attackers to obtain an administrator’s password reset link,… Continue Reading →

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)

Last week, there were 259 vulnerabilities disclosed in 199 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 142 Vulnerability Researchers that contributed to WordPress Security last week. Review those… Continue Reading →

100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin

On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator and perform various administrator… Continue Reading →

Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin

On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including… Continue Reading →

© 2026 WP News Desk — Powered by WordPress and WP RSS Aggregator | Hosted by WP Engine

Up ↑