Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file…
Tag: Blog – Wordfence
100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers…
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)
Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress…
Boost Engagement with Free Passkeys by Wordfence
Wordfence 9 introduces passkeys, and passkeys provide a huge friction reduction because your user no longer has to remember their password or retrieve it…
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a…
Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability…
Wordfence Bug Bounty Program Monthly Report – May 2026
In May 2026, the Wordfence Bug Bounty Program received 1095 vulnerability submissions from our growing community of security researchers working to…
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an…
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more…
Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity…
5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a…
Wordfence Argus: Moving Beyond Human Research Capability
When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to…
Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin
On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an…
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)
Last week, there were 240 vulnerabilities disclosed in 184 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence…
Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales
A year ago we wrote that we’d put AI to work across the whole company, turning everyone on the team into a capable AI operator so our defenders could stay…
400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than…
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to…
100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than…
