Vulnerabilities

Emerging attack types, vulnerability disclosures, breach reports, security red flags

All Articles

  • Masteriyo LMS Vulnerability Lets Students Hijack WordPress Admin — Here’s What You Need to Know

    A missing authorization check just handed student-level users the keys to your entire WordPress site discovered By: SecurityLab Blogger (Hunter Jensen / skid — original researcher) Published: March 25, 2026 · Updated: March 27, 2026 Imagine this. You run a thriving online course business on WordPress. You’re using Masteriyo LMS to deliver content to hundreds of…

  • Top 5 Security Breaches in WordPress History: Learn from the Past

    Top 5 Security Breaches in WordPress History: Learn from the Past

    A security breach in the WordPress context means one of three things: unauthorized access to site files or the database, mass exploitation of a vulnerability across thousands of sites simultaneously, or a supply chain attack where the infection arrives through a trusted update or package. The breaches in this list qualify on at least one…

  • What Is a CVE? WordPress Vulnerabilities and Exposures Explained

    What Is a CVE? WordPress Vulnerabilities and Exposures Explained

    WordPress powers over 43% of the web. That popularity makes it a prime target. In 2024 alone, security researchers discovered and registered 7,966 new vulnerabilities across WordPress plugins, themes, and core — a 34% jump from 2023. Each one got a CVE. If you run a WordPress site and don’t know what a CVE is,…

  • Spectra Gutenberg Blocks Remote Code Execution Vulnerability CVE-2026-7465 Disclosed

    Spectra Gutenberg Blocks Remote Code Execution Vulnerability CVE-2026-7465 Disclosed

    Security researchers have identified a critical remote code execution vulnerability in the Spectra Gutenberg Blocks plugin for WordPress, a widely used extension for building Gutenberg-based layouts. The flaw allows authenticated users with contributor-level permissions to execute arbitrary PHP code under certain conditions involving block attributes. If exploited, this vulnerability can lead to full site compromise,…

  • WP Maps Pro Privilege Escalation Exploit Explained

    WP Maps Pro Privilege Escalation Exploit Explained

    A critical vulnerability has been discovered in WP Maps Pro (versions ≤ 6.1.0) that allows unauthenticated attackers to create administrator accounts via the wpgmp_temp_access_ajax AJAX action. This plugin security flaw enables privilege escalation without requiring login credentials, effectively allowing remote attackers to take full control of affected WordPress sites. Site administrators using WP Maps Pro…

  • WordPress Security Intelligence Report – May 2026

    WordPress Security Intelligence Report – May 2026

    In May 2026, security researchers disclosed over 500 WordPress plugin vulnerabilities, including 28 critical issues, 118 high-severity flaws, and 344 medium-risk vulnerabilities. The high number of critical issues points to a clear pattern: attackers and researchers continue to uncover severe flaws in unauthenticated privilege escalation, arbitrary file uploads, and authentication bypass mechanisms. Most vulnerabilities now…

  • Hippoo Mobile App for WooCommerce Plugin Flaw Allows Admin Account Takeover

    Hippoo Mobile App for WooCommerce Plugin Flaw Allows Admin Account Takeover

    A critical authentication bypass in the Hippoo Mobile App for WooCommerce plugin lets unauthenticated attackers seize administrator accounts with a single API call. No credentials required. A severe security flaw in the Hippoo Mobile App for WooCommerce plugin gives any anonymous attacker administrator-level access to affected WordPress sites. No username. No password. Just a single…

  • Weekly WordPress Vulnerability Report: June 1–7, 2026

    74 new WordPress vulnerabilities were disclosed this week. Kirki hits 500,000 sites. Volume dropped 73% from last week’s 277. Here is every plugin and theme your team needs to check right now. Page contents: Quick Numbers · Critical Vulnerabilities · Full Disclosure Table · Threat Trends · Defensive Checklist · FAQ Quick Numbers The volume…

  • WordPress Blocksy Theme Flaw Allows Hackers to Take Over Websites (CVE-2026-8365)

    WordPress Blocksy Theme Flaw Allows Hackers to Take Over Websites (CVE-2026-8365)

    A major security flaw has shaken up the WordPress community. Security researchers found a critical zero-day vulnerability, tracked as CVE-2026-8365, in the popular Blocksy WordPress theme. Blocksy is a favorite choice for digital agencies and large business websites because it is fast and highly customizable. However, if you are running Blocksy version 2.1.41 or older,…

  • Weekly Most Exploited WordPress Vulnerabilities

    Is Your WordPress Site Already Exposed? Here’s a question that should keep every WordPress site owner up at night: how many plugins on your site haven’t been updated in the last 30 days? If you’re like most WordPress users, the honest answer is a few, maybe more. And that’s exactly how hackers get in. This…