Skip to content

project

WordPress

WordPress is an open-source content management system powering websites and blogs via themes and plugins, available hosted (WordPress.com) or self-hosted.

Known aliases

  • Pix for WooCommerce
  • WordPress CMS
  • WordPress.com
  • WordPress.com core software
  • WordPress core
  • WP
  • WP2Shell

Relationships

No evidence-backed relationships are recorded.

Current stories

security7 publishers

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

7 publishers
Builder
Builder 35%
Operator
Operator 62%
Investor
Investor 3%

Reality

Evidence79
Adoption42
Hype gap+14
Incentives67
Confidence70
build1 publisher

Exploit attempts for WordPress CVE-2026-87902 began the day 7.1.2 shipped

WordPress released 7.1.2 on 22 September 2026 to fix remote file inclusion flaw CVE-2026-87902, and the first exploit attempt was recorded the same day. The fix was back-ported to every maintained branch down to 4.7, so an exposed site has hours before scanners find it.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
security2 publishers

Cloudflare's EmDash 1.0 blocks sandboxed plugins from site data until an admin approves

Cloudflare's EmDash 1.0 CMS starts each sandboxed plugin with only its own storage and blocks seven kinds of site resource until an admin approves. It answers the WordPress model, where every plugin shares the site's PHP process with direct access to its database, files and network.

Reality

Evidence55
Adoption25
Hype gap+25
Incentives70
Confidence60
product3 publishers

Matt Mullenweg fills Automattic's board with two authors and two IRL co-founders after a failed ouster

Matt Mullenweg's 84% vote returned him to control of Automattic 33 hours after its board put him on leave. For businesses on WordPress.com, WooCommerce or Tumblr, that vote is the governance they are buying into, whoever he names to the board.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 28%
Investor
Investor 45%

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives70
Confidence62
security4 publishers

Two loops, one blocklist bypass: Elementor Pro's upload field becomes unauthenticated RCE

CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence68
security3 publishers

One clicked link creates an attacker admin on Elementor 4.3.0 and 4.3.1

Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 55%
Investor
Investor 7%

Reality

Evidence72
Adoption60
Hype gap+10
Incentives30
Confidence74
security5 publishers

Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told

Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.

Perspective Coverage

5 publishers
Builder
Builder 32%
Operator
Operator 56%
Investor
Investor 12%

Reality

Evidence70
Adoption30
Hype gap+15
Incentives
Insufficient
Confidence68
security3 publishers

GiveWP issues accounts to unauthenticated attackers on sites where registration is off

Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.

Perspective Coverage

3 publishers
Builder
Builder 40%
Operator
Operator 52%
Investor
Investor 8%

Reality

Evidence68
Adoption45
Hype gap+15
Incentives30
Confidence70
security3 publishers

Suspected Chinese-speaking operator drained a Philippine nuclear agency via a 2023 ownCloud bypass

Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.

Publishers:hunt.ioscworld.comsecurityaffairs.com

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 57%
Investor
Investor 10%

Reality

Evidence64
Adoption
Insufficient
Hype gap+8
Incentives38
Confidence60

Earlier coverage

  1. A URL substring match lets Elementor's Editor Events skip WordPress's REST nonce

    Build · September 25, 2026 · 1 publisher

  2. Attackers started dropping webshells through Elementor Pro forms on patch day

    Security · September 3, 2026 · 3 publishers

  3. Mullenweg declares himself back in control of Automattic while the company still says he is on leave

    Product · September 11, 2026 · 3 publishers

  4. Wordfence blocked 100,000 exploit attempts against a WooCommerce plugin with 6,000 installs

    Security · September 16, 2026 · 3 publishers

  5. An unapproved comment triggers RCE in The Events Calendar before moderation sees it

    Security · September 16, 2026 · 2 publishers

  6. Click2Shell runs attacker PHP on WordPress servers after a single administrator click

    Security · September 21, 2026 · 2 publishers

  7. Exvicy built its ClickFix subscription on code lifted from rival ErrTraffic

    Security · September 21, 2026 · 2 publishers

  8. Exploit attempts for WordPress CVE-2026-87902 began the same day its patch shipped

    Security · September 24, 2026 · 1 publisher

  9. Chrome ships an llms.txt audit that a spec-valid file can fail

    Build · September 24, 2026 · 1 publisher

  10. ClickFix crews are staging the second stage inside Binance Smart Chain smart contracts

    Security · September 23, 2026 · 1 publisher

  11. GreyNoise ties 18,566 stolen government records and 996 harvested Zyxel switches to one actor

    Build · September 22, 2026 · 1 publisher

  12. Red Heron-linked actor turned mid-July wp2shell exploits into 18,566 stolen government records

    Security · September 22, 2026 · 1 publisher

  13. Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server

    Build · September 22, 2026 · 1 publisher

  14. One line of curl is enough to make a site's dashboard log you as ClaudeBot

    Build · September 21, 2026 · 1 publisher

  15. A log audit can only catch the nine AI agents that send an HTTP request

    Build · September 21, 2026 · 1 publisher

  16. Excluding WPML translation sets cut a duplicate-image scan from hundreds of groups to 29

    Build · September 20, 2026 · 1 publisher

  17. One shared hosting login puts ten client sites in a single failure domain

    Build · September 19, 2026 · 1 publisher

  18. Attackers rewrote Brevo's embedded scripts at Cloudflare's edge with a hardcoded full-permission key

    Security · September 17, 2026 · 3 publishers

  19. A vague asset request postpones the build Claude Code finished by evening

    Build · September 18, 2026 · 1 publisher

  20. WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme

    Security · September 18, 2026 · 1 publisher

  21. A path-only cache bypass lets Cloudflare serve one shopper's cart header to another

    Build · September 18, 2026 · 1 publisher

  22. Fewer than three in ten of 319 WordPress professionals have a breach recovery plan

    Security · September 17, 2026 · 1 publisher

  23. Meta's training crawler outpaced its citation crawler 39 to 1 on a single WordPress site

    Build · September 17, 2026 · 1 publisher

  24. Previewing an unapproved comment triggers do_blocks() on the entire event page

    Build · September 17, 2026 · 1 publisher

  25. Two Automattic executives signed each other's severance in the 33 hours their CEO was out

    Product · September 16, 2026 · 1 publisher

  26. Automattic's CFO held the CEO job for 2,000 minutes

    Build · September 16, 2026 · 1 publisher

  27. Admin Menu Editor Pro's own update channel delivered the web shell to 1,500 sites

    Build · September 16, 2026 · 1 publisher

  28. Attackers are telling a WooCommerce plugin that PHP is an allowed upload extension

    Build · September 16, 2026 · 1 publisher

  29. A 60-day notice clause is Automattic's documented way out of $8.15M in severance

    Build · September 16, 2026 · 1 publisher

  30. Three in four VAPID signatures return 401 until the DER wrapper comes off

    Build · September 16, 2026 · 1 publisher

  31. WordPress's .htaccess kept the old /en/blog/ path after the docroot moved to a subdomain

    Build · September 15, 2026 · 1 publisher

  32. Voss rests the case against license-level charging on three reversals and one buyout between 2017 and 2025

    Build · September 15, 2026 · 1 publisher

  33. Attacker with root on the Admin Menu Editor site poisoned the fix as well as the original update

    Security · September 15, 2026 · 1 publisher

  34. Confirmed exploitation now lands 40 days sooner after a CVE goes public

    Product · September 15, 2026 · 1 publisher

  35. Silent WordPress bugs point at the hook that fired one step too late

    Build · September 15, 2026 · 1 publisher

  36. WordPress puts an automated security score between a plugin commit and the update API

    Security · September 14, 2026 · 1 publisher

  37. Control of Automattic's Slack workspace outlasted the resolution naming an interim CEO

    Build · September 12, 2026 · 1 publisher

  38. A zero border radius rule caused more arguments with Claude Code than the 1C sync did

    Build · September 13, 2026 · 1 publisher

  39. A layout-break check ignores up to 81,920 changed pixels in a 1280x800 frame

    Build · September 11, 2026 · 1 publisher

  40. The board vote that sidelined Mullenweg left WordPress.org's patch pipeline in his hands

    Product · September 11, 2026 · 2 publishers