Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. […]
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. […]
Chaos Communication Congress zieht umheise online Quelle: Heise Security Ticker
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.
BCG und Cradle to Cradle NGO fordern ein Umdenken: Zirkuläres Design soll wertvolle Metalle aus Altgeräten sichern und Importe senken. (Elektronikschrott, IFA2007)
WordPress All-in-One WP Migration: Angreifer können Admin-Falle auslegenAlertheise security Quelle: Heise Security Ticker
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
In einem WordPress-Plug-in mit über 5 Millionen Installationen klafft eine gefährliche Sicherheitslücke. Admins sollten dringend handeln. (Sicherheitslücke, WordPress)
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. […]
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. […]