Your WordPress News Dashboard

WordPress Vulnerability Report — November 12, 2025

In this report, 199 vulnerabilities have been publicly disclosed. Security patches for 104 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — November 5, 2025

In this report, 108 vulnerabilities have been publicly disclosed. Security patches for 77 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in AI Engine WordPress Plugin

On October 4th, 2025, we received a submission for a Sensitive Information Exposure vulnerability in AI Engine, a WordPress plugin with more than 100,000 active installations. This vulnerability can be exploited by unauthenticated attackers to extract the bearer token and… Continue Reading →

400,000 WordPress Sites Affected by Account Takeover Vulnerability in Post SMTP WordPress Plugin

On October 11th, 2025, we received a submission for an Account Takeover via Email Log Disclosure vulnerability in Post SMTP, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for an unauthenticated attacker to view… Continue Reading →

Attackers Actively Exploiting Critical Vulnerability in WP Freeio Plugin

On September 25th, 2025, we received a submission for a Privilege Escalation vulnerability in WP Freeio, a WordPress plugin bundled in the Freeio premium theme with more than 1,700 sales. This vulnerability makes it possible for an unauthenticated attacker to… Continue Reading →

Rogue WordPress Plugin Conceals Multi-Tiered Credit Card Skimmers in Fake PNG Files

The Wordfence Threat Intelligence Team recently discovered a sophisticated malware campaign targeting WordPress e-commerce sites, specifically those using the WooCommerce plugin. This malware exhibits advanced features including custom encryption methods, fake images used to conceal malicious payloads, a robust persistence… Continue Reading →

WordPress Vulnerability Report — October 29, 2025

In this report, 118 vulnerabilities have been publicly disclosed. Security patches for 66 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

100,000 WordPress Sites Affected by Arbitrary File Read Vulnerability in Anti-Malware Security and Brute-Force Firewall WordPress Plugin

On October 3rd, 2025, we received a submission for an Arbitrary File Read vulnerability in Anti-Malware Security and Brute-Force Firewall, a WordPress plugin with more than 100,000 active installations. This vulnerability makes it possible for an authenticated attacker, with subscriber-level… Continue Reading →

WordPress Vulnerability Report — October 22, 2025

In this report, 139 vulnerabilities have been publicly disclosed. Security patches for 87 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

Wordfence Bug Bounty Program Monthly Report – September 2025

Last month in September 2025, the Wordfence Bug Bounty Program received 374 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by… Continue Reading →

WordPress Vulnerability Report — October 15, 2025

In this report, 64 vulnerabilities have been publicly disclosed. Security patches for 46 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — October 8, 2025

In this report, 99 vulnerabilities have been publicly disclosed. Security patches for 32 of these plugins and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — October 1, 2025

In this report, 476 vulnerabilities have been publicly disclosed. Security patches for 136 vulnerabilities in WordPress Core, plugins, and themes are now available. Please run these updates as soon as possible. If you’re a Solid Security Pro user, the version… Continue Reading →

WordPress Vulnerability Report — September 24, 2025

In this report, 354 vulnerabilities have been publicly disclosed. Security patches for 89 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

Wordfence Bug Bounty Program Monthly Report – August 2025

Last month in August 2025, the Wordfence Bug Bounty Program received 438 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by… Continue Reading →

WordPress Vulnerability Report — September 17, 2025

In this report, 199 vulnerabilities have been publicly disclosed. Security patches for 50 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

WordPress Vulnerability Report — September 10, 2025

In this report, 297 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

WordPress Vulnerability Report — September 3, 2025

In this report, 114 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

WordPress Vulnerability Report — August 27, 2025

In this report, 169 vulnerabilities have been publicly disclosed. Security patches for 71 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

WordPress Vulnerability Report — August 20, 2025

In this report, 191 vulnerabilities have been publicly disclosed. Security patches for 93 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

WordPress Vulnerability Report — August 13, 2025

In this report, 83 vulnerabilities have been publicly disclosed. Security patches for 51 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

WordPress Vulnerability Report — August 6, 2025

In this report, 133 vulnerabilities have been publicly disclosed. Security patches for 98 of these plugins and themes are now available, so please run those updates as soon as possible. If you’re a Solid Security Pro user, the version management… Continue Reading →

WordPress Vulnerability Report — July 30, 2025

In this report, 113 vulnerabilities have been publicly disclosed. Security patches for 60 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — July 23, 2025 - iThemes

In this report, 167 vulnerabilities have been publicly disclosed. Security patches for 125 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — July 16, 2025 - iThemes

In this report, 109 vulnerabilities have been publicly disclosed. Security patches for 65 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — July 9, 2025 - iThemes

In this report, 149 vulnerabilities have been publicly disclosed. Security patches for 65 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

Seamless SolidWP Licensing Across All Your Environments - iThemes

For WordPress professionals, managing staging and development sites is an essential part of a robust workflow. We understand the need for every iteration of your site to be fully functional and secure. That’s why we’re introducing new licensing notices within… Continue Reading →

WordPress Vulnerability Report — July 2, 2025 - iThemes

In this report, 213 vulnerabilities have been publicly disclosed. Security patches for 64 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — June 25, 2025 - iThemes

In this report, 177 vulnerabilities have been publicly disclosed. Security patches for 59 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

WordPress Vulnerability Report — June 18, 2025 - iThemes

In this report, 138 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool… Continue Reading →

« Older posts

© 2025 WP News Desk — Powered by WordPress and WP RSS Aggregator | Hosted by WP Engine

Up ↑