Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

10 / 12 results
Active filter:vendor: wordpress✕ clear
StopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

StopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Delivery

StopAndProtect is a global cybercrime operation tracked by Check Point Research since mid-May 2026. The operation is named after a ransomware family discovered during initial investigation.

WordPress19 Aug · 09:25 UTC
WordPress pre-auth XSS on login page enables RCE via admin interactionhighbug_reportVulnerability
bug_reportVulnerability

WordPress pre-auth XSS on login page enables RCE via admin interaction

WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.

CVE-2026-646387 Aug · 10:56 UTC
WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit

WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.

CVE-2026-6013722 Jul · 14:09 UTC
WordPress Core wp2shell flaws actively exploited for webshell deploymentcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core wp2shell flaws actively exploited for webshell deployment

WordPress Core (specific versions not disclosed). Both CVE-2026-63030 and CVE-2026-60137 affect core WordPress installations, enabling remote attackers to deploy webshells and malicious plugins.

CVE-2026-6013721 Jul · 14:41 UTC
WordPress wp2shell flaws enable unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress wp2shell flaws enable unauthenticated RCE, active exploitation

WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.

CVE-2026-6013721 Jul · 06:59 UTC
WordPress Core RCE "wp2shell" exploits now public, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE "wp2shell" exploits now public, patch immediately

WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".

WordPress18 Jul · 15:22 UTC
WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update activecriticalbug_reportVulnerability
bug_reportVulnerability

WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active

WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.

WordPress17 Jul · 19:20 UTC
SocGholish Infrastructure Disrupted in Operation Endgame Takedownhighperson_alertThreat Actor
person_alertThreat Actor

SocGholish Infrastructure Disrupted in Operation Endgame Takedown

SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.

WordPress19 Jun · 13:07 UTC
Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servershighperson_alertThreat Actor
person_alertThreat Actor

Evil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers

Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…

WordPress18 Jun · 11:25 UTC
Malware campaign infects 2,000 WordPress sites using Steam profiles for C2highbug_reportVulnerability
bug_reportVulnerability

Malware campaign infects 2,000 WordPress sites using Steam profiles for C2

Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).

WordPress1 Jun · 15:04 UTC