#wordpress-security

[ follow ]
Information security
fromTechRepublic
4 days ago

Security Flaw in WordPress Plugin Puts 400,000 Websites at Risk

A critical vulnerability in the Ally WordPress plugin allows unauthenticated attackers to extract sensitive database data including password hashes from hundreds of thousands of affected websites.
Information security
fromTheregister
6 days ago

Crooks compromise WordPress sites, spread infostealers

Attackers compromised legitimate WordPress sites including a US Senate candidate's website to distribute infostealer malware through fake Cloudflare CAPTCHA pages that trick users into running malicious commands.
Privacy professionals
fromThe Hacker News
10 months ago

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors

A significant phishing campaign is targeting WooCommerce users with fake alerts, prompting them to download malware disguised as security patches.
[ Load more ]