Security vulnerabilities with critical risk ratings are present in widespread WordPress plugins. One is already being attacked.
In its write-up, Patchstack said the flaw is already being exploited in the wild, and that first attacks were detected on ...
A critical-severity vulnerability in the Advanced Custom Fields: Extended (ACF Extended) plugin for WordPress can be ...
Web Photo Gallery plugin vulnerability enables attacker to delete image comments. Impacts all plugin versions up to and ...
A vulnerability in an ACF addon plugin exposes up to 100,000 installations to a complete site takeover by unauthenticated ...
A critical WordPress Modular DS plugin flaw (CVE-2026-23550) allows unauthenticated attackers to gain admin access; patched ...
Thousands of sites running WordPress remain unpatched against a critical security flaw in a widely used plugin that was being actively exploited in attacks that allow for unauthenticated execution of ...
Hackers are actively exploiting a maximum severity flaw in the Modular DS WordPress plugin that allows them to bypass ...