CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.
Perspective Coverage
7 publishers
- Builder
- Builder 35%
- Operator
- Operator 62%
- Investor
- Investor 3%
Reality
- Evidence79
- Adoption42
- Hype gap+14
- Incentives67
- Confidence70
WordPress released 7.1.2 on 22 September 2026 to fix remote file inclusion flaw CVE-2026-87902, and the first exploit attempt was recorded the same day. The fix was back-ported to every maintained branch down to 4.7, so an exposed site has hours before scanners find it.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
Sucuri says a WordPress backdoor it calls SC keeps itself in at least eight places across files, the database and shared memory. Cleaning the plugin or wiping files on disk does not clear it, because any surviving copy rewrites the rest on the next page load.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Cloudflare's EmDash 1.0 CMS starts each sandboxed plugin with only its own storage and blocks seven kinds of site resource until an admin approves. It answers the WordPress model, where every plugin shares the site's PHP process with direct access to its database, files and network.
Reality
- Evidence55
- Adoption25
- Hype gap+25
- Incentives70
- Confidence60
Dartmouth and Lancaster researchers tie 88 non-consensual deepfake sites to five mainstream web providers led by Cloudflare, Google and Namecheap. The sites surfaced in keyword searches and every provider already bans illegal use, so the gap the study points to is enforcement.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Cloudflare's EmDash 1.0 runs each CMS plugin in its own isolate capped at 50ms of CPU per request, a dev.to breakdown says. Isolation limits what a bad plugin can reach, and choosing which publisher keys to trust stays with the site owner.
Reality
- Evidence45
- Adoption30
- Hype gap+25
- Incentives65
- Confidence50
Matt Mullenweg's 84% vote returned him to control of Automattic 33 hours after its board put him on leave. For businesses on WordPress.com, WooCommerce or Tumblr, that vote is the governance they are buying into, whoever he names to the board.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 28%
- Investor
- Investor 45%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence62
Professional IT Services reviewed all 15 volume-backed Deployments on its K3s cluster after a routine node upgrade caused a three-hour outage. Three now use Recreate, because the default rolling update can stall on a ReadWriteOnce volume.
Reality
- Evidence60
- Adoption15
- Hype gap+5
- Incentives30
- Confidence55
Unauthenticated attackers can drop PHP onto WordPress sites running Forminator 1.56.1 or earlier. The install base is 600,000; the exposed subset depends on how the forms were built.
Reality
- Evidence72
- Adoption45
- Hype gap+30
- Incentives
- Insufficient
- Confidence68
Check Point Research says exposed directories revealed the logs, source code and management tooling behind StopAndProtect, a campaign it links to more than 5,000 infected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 63%
- Investor
- Investor 7%
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives55
- Confidence65
CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence68
Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 55%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption60
- Hype gap+10
- Incentives30
- Confidence74
CTM360 tracked more than 17,000 compromised URLs serving a fake Cloudflare check whose next hostname arrives from an on-chain lookup. Microsoft put 47 percent of its 2025 initial-access cases down to the technique.
Reality
- Evidence45
- Adoption72
- Hype gap+20
- Incentives70
- Confidence50
Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.
Perspective Coverage
5 publishers
- Builder
- Builder 32%
- Operator
- Operator 56%
- Investor
- Investor 12%
Reality
- Evidence70
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence68
Matt Mullenweg has named four new Automattic directors weeks after the old board's leave vote against him lasted 33 hours and 20 minutes. He controls 84% of the voting power, so the people who oversee him are people he chose.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Cloudflare moved its main blog from WordPress to EmDash, its own TypeScript CMS, on a Worker stack tested to 7,000 requests per second. The test ran on a cached blog built from Cloudflare services, so the figure carries over only to sites whose pages cache as well.
Reality
- Evidence35
- Adoption10
- Hype gap+30
- Incentives70
- Confidence45
Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.
Perspective Coverage
3 publishers
- Builder
- Builder 40%
- Operator
- Operator 52%
- Investor
- Investor 8%
Reality
- Evidence68
- Adoption45
- Hype gap+15
- Incentives30
- Confidence70
Wordfence and Patchstack disclosed five critical bugs in WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Only one of them fires with no configuration precondition. That is what sets the patch order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+8
- Incentives38
- Confidence60
Wordfence blocked more than 250,000 attempts against Super Forms and 190,000 against Elementor Pro. The Super Forms campaign has been running since July 14, so unpatched sites need a look through their uploads directories.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence64
Earlier coverage
- A URL substring match lets Elementor's Editor Events skip WordPress's REST nonce
Build · September 25, 2026 · 1 publisher
- Attackers started dropping webshells through Elementor Pro forms on patch day
Security · September 3, 2026 · 3 publishers
- Mullenweg declares himself back in control of Automattic while the company still says he is on leave
Product · September 11, 2026 · 3 publishers
- Wordfence blocked 100,000 exploit attempts against a WooCommerce plugin with 6,000 installs
Security · September 16, 2026 · 3 publishers
- An unapproved comment triggers RCE in The Events Calendar before moderation sees it
Security · September 16, 2026 · 2 publishers
- Click2Shell runs attacker PHP on WordPress servers after a single administrator click
Security · September 21, 2026 · 2 publishers
- Exvicy built its ClickFix subscription on code lifted from rival ErrTraffic
Security · September 21, 2026 · 2 publishers
- Exploit attempts for WordPress CVE-2026-87902 began the same day its patch shipped
Security · September 24, 2026 · 1 publisher
- Chrome ships an llms.txt audit that a spec-valid file can fail
Build · September 24, 2026 · 1 publisher
- ClickFix crews are staging the second stage inside Binance Smart Chain smart contracts
Security · September 23, 2026 · 1 publisher
- GreyNoise ties 18,566 stolen government records and 996 harvested Zyxel switches to one actor
Build · September 22, 2026 · 1 publisher
- Red Heron-linked actor turned mid-July wp2shell exploits into 18,566 stolen government records
Security · September 22, 2026 · 1 publisher
- Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server
Build · September 22, 2026 · 1 publisher
- One line of curl is enough to make a site's dashboard log you as ClaudeBot
Build · September 21, 2026 · 1 publisher
- A log audit can only catch the nine AI agents that send an HTTP request
Build · September 21, 2026 · 1 publisher
- Excluding WPML translation sets cut a duplicate-image scan from hundreds of groups to 29
Build · September 20, 2026 · 1 publisher
- One shared hosting login puts ten client sites in a single failure domain
Build · September 19, 2026 · 1 publisher
- Attackers rewrote Brevo's embedded scripts at Cloudflare's edge with a hardcoded full-permission key
Security · September 17, 2026 · 3 publishers
- A vague asset request postpones the build Claude Code finished by evening
Build · September 18, 2026 · 1 publisher
- WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme
Security · September 18, 2026 · 1 publisher
- A path-only cache bypass lets Cloudflare serve one shopper's cart header to another
Build · September 18, 2026 · 1 publisher
- Fewer than three in ten of 319 WordPress professionals have a breach recovery plan
Security · September 17, 2026 · 1 publisher
- Meta's training crawler outpaced its citation crawler 39 to 1 on a single WordPress site
Build · September 17, 2026 · 1 publisher
- Previewing an unapproved comment triggers do_blocks() on the entire event page
Build · September 17, 2026 · 1 publisher
- Two Automattic executives signed each other's severance in the 33 hours their CEO was out
Product · September 16, 2026 · 1 publisher
- Automattic's CFO held the CEO job for 2,000 minutes
Build · September 16, 2026 · 1 publisher
- Admin Menu Editor Pro's own update channel delivered the web shell to 1,500 sites
Build · September 16, 2026 · 1 publisher
- Attackers are telling a WooCommerce plugin that PHP is an allowed upload extension
Build · September 16, 2026 · 1 publisher
- A 60-day notice clause is Automattic's documented way out of $8.15M in severance
Build · September 16, 2026 · 1 publisher
- Three in four VAPID signatures return 401 until the DER wrapper comes off
Build · September 16, 2026 · 1 publisher
- WordPress's .htaccess kept the old /en/blog/ path after the docroot moved to a subdomain
Build · September 15, 2026 · 1 publisher
- Voss rests the case against license-level charging on three reversals and one buyout between 2017 and 2025
Build · September 15, 2026 · 1 publisher
- Attacker with root on the Admin Menu Editor site poisoned the fix as well as the original update
Security · September 15, 2026 · 1 publisher
- Confirmed exploitation now lands 40 days sooner after a CVE goes public
Product · September 15, 2026 · 1 publisher
- Silent WordPress bugs point at the hook that fired one step too late
Build · September 15, 2026 · 1 publisher
- WordPress puts an automated security score between a plugin commit and the update API
Security · September 14, 2026 · 1 publisher
- Control of Automattic's Slack workspace outlasted the resolution naming an interim CEO
Build · September 12, 2026 · 1 publisher
- A zero border radius rule caused more arguments with Claude Code than the 1C sync did
Build · September 13, 2026 · 1 publisher
- A layout-break check ignores up to 81,920 changed pixels in a 1280x800 frame
Build · September 11, 2026 · 1 publisher
- The board vote that sidelined Mullenweg left WordPress.org's patch pipeline in his hands
Product · September 11, 2026 · 2 publishers