Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
12 / 12 results
criticalbug_reportVulnerabilityWordPress Core RCE "wp2shell" exploits now public, patch immediately
WordPress Core (specific versions not disclosed in provided data). Scope appears to be remote code execution vulnerabilities in core WordPress installation.
criticalbug_reportVulnerabilityWordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active
WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.
highbug_reportVulnerabilityShapedPlugin WordPress Pro plugins backdoored via compromised update channel
Multiple ShapedPlugin Pro WordPress plugins distributed through official licensed update channels. Exact plugin names and affected versions not specified.
highbug_reportVulnerabilityShapedPlugin WordPress plugins compromised in supply chain attack
Multiple WordPress plugins from ShapedPlugin vendor. Infected releases distributed to paying customers via official update mechanism. Specific plugin names and version numbers not disclosed in provided data.
criticalbug_reportVulnerabilityCritical vulnerability in Joomla Content Editor (JCE) requires urgent patching
Joomla Content Editor (JCE) extension for Joomla CMS. Specific affected versions not disclosed in advisory. All Joomla sites using the JCE extension should be considered at risk pending vendor confirmation.
highbug_reportVulnerabilityAwesome Motive CDN breach compromises WordPress plugins in supply-chain attack
WordPress plugins OptinMonster, TrustPulse, and PushEngage distributed via Awesome Motive's CDN. All versions served through the compromised CDN infrastructure are potentially affected.
criticalbug_reportVulnerabilityEverest Forms Pro WordPress plugin under active exploit for site takeover
Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.
criticalbug_reportVulnerabilityActive exploitation of RCE flaw in Everest Forms Pro WordPress plugin
Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.
criticalbug_reportVulnerabilityWP Maps Pro plugin exploited to create rogue admin accounts on WordPress
WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.
highbug_reportVulnerabilityLaravel-Lang packages compromised to deliver credential-stealing malware
Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages.
criticalbug_reportVulnerabilityCritical SQL injection in Drupal Core requires immediate patching
Drupal Core, all versions (specific affected versions not disclosed in alert). Impacts all Drupal installations until patched.
criticalbug_reportVulnerabilityReact Server Components RCE flaw enables unauthenticated remote execution
React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.