Skip to content

Topic

WordPress Security

Vulnerabilities, patches and compromise activity affecting WordPress core, plugins and the sites running them.

Current stories

security3 publishersConfirmed

Attackers started dropping webshells through Elementor Pro forms on patch day

Wordfence has blocked nearly 200,000 attempts against CVE-2026-32475 since August 19. Because the payload is a PHP file already sitting in the uploads tree, upgrading to 4.2.2 tells you nothing about whether you were hit.

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 65%
Investor
Investor 7%

Reality

Evidence72
Adoption70
Hype gap+15
Incentives45
Confidence70
security3 publishersConfirmed

Attackers rewrote Brevo's embedded scripts at Cloudflare's edge with a hardcoded full-permission key

Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.

Perspective Coverage

3 publishers
Builder
Builder 34%
Operator
Operator 48%
Investor
Investor 18%

Reality

Evidence78
Adoption60
Hype gap+20
Incentives58
Confidence72