Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Tag: Blog – Wordfence
Wordfence Bug Bounty Program Monthly Report – April 2026
In April 2026, the Wordfence Bug Bounty Program received 1288 vulnerability submissions from our growing community of security researchers working to…
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 20, 2026 to July 26, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced…
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by…
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)
Last week, there were disclosed in WordPress Core, and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to…
A New Threat Landscape Meets A New Kind of Defender
PRISM, our autonomous AI researcher, is now our #1 vulnerability researcher. A look at AI’s new threat landscape — and the new kind of defender it demands. The post A New Threat Landscape Meets A New Kind of Defender appeared…
wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
wp2shell is a critical unauthenticated RCE chain in WordPress Core, patched July 17, 2026. See who’s affected, the exploitation timeline, and what to do now. The post wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade…
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase…
Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 8, 2026 to June 14, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
On May 13th, 2026, we received a submission for a critical Unauthenticated Arbitrary File Deletion vulnerability in Avada Builder, a premium WordPress plugin with an estimated 1,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to delete arbitrary…
Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin
On March 30th, 2026, we publicly disclosed a Sensitive Information Exposure vulnerability in Gravity SMTP, a WordPress plugin with an estimated 100,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to retrieve detailed system configuration data and, critically,…
PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels
The Wordfence Threat Intelligence Team was notified on June 11th, 2026 of a potential supply chain compromise affecting ShapedPlugin, a WordPress plugin vendor with over 400,000 active free plugin installations. Fortunately, Wordfence customers have already had malware signature detection for…
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not…