Your WordPress News Dashboard

100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS

On August 23rd, 2026, Wordfence Argus, our AI research agent specializing in complex vulnerability chains, discovered a PHP Object Injection vulnerability in Tutor LMS, a WordPress e-learning plugin active on more than 100,000 websites. This vulnerability allows any authenticated attacker… Continue Reading →

Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)

Last week, there were 260 vulnerabilities disclosed in 207 WordPress Plugins that have been added to the Wordfence Intelligence Vulnerability Database, and there were 147 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report… Continue Reading →

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary… Continue Reading →

Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin

On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugin active on more than 600,000 websites. Both chains begin in the… Continue Reading →

Wordfence Bug Bounty Program Monthly Report – May 2026

In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem. These submissions are reviewed, triaged, and processed by the Wordfence… Continue Reading →

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)

Last week, there were 277 vulnerabilities disclosed in 187 WordPress Plugins and 7 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 153 Vulnerability Researchers that contributed to WordPress Security last week. Review those… Continue Reading →

The Definitive Guide to SSL and WordPress

The Importance of SSL in Today’s Web Environment It’s become commonplace for a majority of internet users to share personal information on the internet. With the disregard for protecting personal data becoming second nature, how do we protect ourselves and… Continue Reading →

© 2026 WP News Desk — Powered by WordPress and WP RSS Aggregator | Hosted by WP Engine

Up ↑