Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
25 / 25 results
criticalbug_reportVulnerabilityElementor Pro CVE-2026-32475 actively exploited for webshell uploads
Elementor Pro plugin for WordPress versions 4.2.1 and earlier. Affects sites with published Elementor Pro Form widgets containing File Upload fields. Over 6 million active installations potentially at risk.
criticalbug_reportVulnerabilityAll-in-One WP Migration plugin SQL injection enables site takeover
All-in-One WP Migration and Backup plugin for WordPress, versions through 7.109. Over 5 million active installations, with approximately 3.25 million sites (65%) still running vulnerable versions. Fixed in version 7.110.
criticalbug_reportVulnerabilityCritical WordPress plugin flaws enable auth bypass and RCE on popular sites
WPMU DEV Dashboard plugin ≤5.0.1 (CVE-2026-76581), Avada theme ≤7.16 with Fusion Builder ≤3.16 (CVE-2026-18431), TranslatePress ≤3.3.1 with specific config (CVE-2026-19632), Pods plugin ≤3.3.9 (CVE-2026-19598), GiveWP plugin ≤4.16.7.1 (CVE-2026-82222…
criticalbug_reportVulnerabilityAvada WordPress theme RCE chain affects sites with theme + plugin active
Avada WordPress theme versions up to 7.16 and Fusion Builder plugin versions up to 3.16. Exploitation requires both components to be active simultaneously.
criticalbug_reportVulnerabilityminiOrange SAML SSO plugin flaws actively exploited for WordPress admin access
miniOrange SAML 2.0 Single Sign On plugin for WordPress. Vulnerable versions: Free <5.4.5, Premium single-site <13.0.4, Standard single-site <17.06, Premium/Enterprise/All-Inclusive multisite <20.2.8, Enterprise/All-Inclusive single-site <26.0.3, VIP…
criticalbug_reportVulnerabilityElementor Pro WordPress plugin allows arbitrary file upload and RCE
Elementor Pro WordPress plugin. Specific vulnerable versions not disclosed in available data. Affects WordPress sites with Elementor Pro installed.
criticalbug_reportVulnerabilityForminator WordPress plugin RCE affects 600K+ sites via file upload bypass
Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.
highbug_reportVulnerabilityWordPress pre-auth XSS on login page enables RCE via admin interaction
WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.
criticalbug_reportVulnerabilityWordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit
WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.
criticalbug_reportVulnerabilityWordPress Core wp2shell flaws actively exploited for webshell deployment
WordPress Core (specific versions not disclosed). Both CVE-2026-63030 and CVE-2026-60137 affect core WordPress installations, enabling remote attackers to deploy webshells and malicious plugins.
criticalbug_reportVulnerabilityWordPress wp2shell flaws enable unauthenticated RCE, active exploitation
WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.
criticalbug_reportVulnerabilityWordPress Core RCE "wp2shell" exploits now public, patch immediately
WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".
criticalbug_reportVulnerabilityWordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active
WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.
FFmpeg 'PixelSmash' flaw enables RCE on Jellyfin, DoS on multiple apps
FFmpeg (version details not specified). Downstream impact: Jellyfin (remote code execution), Kodi, Emby, Nextcloud, PhotoPrism, OBS Studio (denial-of-service). Affects media processing and streaming applications using vulnerable FFmpeg libraries.
highbug_reportVulnerabilityGravity SMTP WordPress plugin under active exploit for info disclosure
Gravity SMTP WordPress plugin, affecting approximately 100,000 websites. Specific vulnerable versions not disclosed in available data.
criticalbug_reportVulnerabilityCritical vulnerability in Joomla Content Editor (JCE) requires urgent patching
Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.
criticalbug_reportVulnerabilityCISA: Widget Factory Joomla JCE flaw exploited in the wild (CVSS 10.0)
Widget Factory Joomla Content Editor (JCE). Specific affected versions not disclosed. Impacts Joomla CMS installations using the JCE component.
highbug_reportVulnerabilityAwesome Motive CDN breach compromises WordPress plugins in supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.
criticalbug_reportVulnerabilitySupply chain attack hits PushEngage, OptinMonster, TrustPulse plugins
WordPress sites using PushEngage, OptinMonster, and TrustPulse plugins. All versions loading compromised JavaScript files from vendor infrastructure are affected.
criticalbug_reportVulnerabilityEverest Forms Pro WordPress plugin under active exploit for site takeover
Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.
highbug_reportVulnerabilityMalware campaign infects 2,000 WordPress sites using Steam profiles for C2
Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).
highbug_reportVulnerabilityWP Maps Pro plugin under active attack via admin account creation flaw
WP Maps Pro WordPress plugin (version details not specified). Affects WordPress sites with the plugin installed. Vulnerability allows unauthenticated attackers to create administrator accounts.
criticalbug_reportVulnerabilityGhost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign
Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.
criticalperson_alertThreat ActorClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.
criticalbug_reportVulnerabilityCritical SQL injection in Drupal Core requires immediate patching
Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.