Sucuri says a WordPress backdoor it calls SC keeps itself in at least eight places across files, the database and shared memory. Cleaning the plugin or wiping files on disk does not clear it, because any surviving copy rewrites the rest on the next page load.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Wordfence and Patchstack disclosed five critical bugs in WPMU DEV Dashboard, Avada, TranslatePress, Pods and GiveWP. Only one of them fires with no configuration precondition. That is what sets the patch order.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
Wordfence has blocked nearly 200,000 attempts against CVE-2026-32475 since August 19. Because the payload is a PHP file already sitting in the uploads tree, upgrading to 4.2.2 tells you nothing about whether you were hit.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 65%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption70
- Hype gap+15
- Incentives45
- Confidence70
The flaw reaches code execution only where the active theme has a top-level directory starting with page- and a readable local .php file such as pearcmd.php sits on the server. Previdian has logged 68 attempts.
Reality
- Evidence66
- Adoption45
- Hype gap+12
- Incentives68
- Confidence60
build1 publisherOne report GreyNoise reports the WordPress intrusion and the Zyxel switch harvest as separate operations run from shared scanning infrastructure by a suspected Chinese-speaking actor it tracks as Kapibala.
Reality
- Evidence46
- Adoption57
- Hype gap+12
- Incentives58
- Confidence52
GreyNoise traced scans from a single IP address, running since early June 2026, to a Chinese-speaking actor that breached 49 organizations through WordPress Core and stripped configs and root hashes from 996 ZyXEL switches.
Reality
- Evidence45
- Adoption68
- Hype gap+22
- Incentives55
- Confidence52
build1 publisherOne report The WordPress Core bug alone scores 5.3. In a research proof of concept it installs an official catalog theme inside the administrator's browser, the Customizer preview loads that theme's functions.php, and a second bug runs the attacker's PHP.
Reality
- Evidence52
- Adoption25
- Hype gap+15
- Incentives55
- Confidence50
Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.
Perspective Coverage
3 publishers
- Builder
- Builder 34%
- Operator
- Operator 48%
- Investor
- Investor 18%
Reality
- Evidence78
- Adoption60
- Hype gap+20
- Incentives58
- Confidence72
pwn.ai rated the forced theme install 7.1 on its own and 9.6 once chained through a theme's unauthenticated handler. The fix shipped on September 17 in a security release reaching branches back to 4.7.
Reality
- Evidence60
- Adoption30
- Hype gap+12
- Incentives62
- Confidence58
Melapress surveyed 319 WordPress professionals about the incidents they had handled. Its numbers say the decisions about isolating, restoring and notifying customers are mostly being made in the middle of the outage.
Reality
- Evidence38
- Adoption28
- Hype gap+12
- Incentives65
- Confidence45
Janis Elsts pulled the trojanised Admin Menu Editor Pro 2.35 after about seven hours and shipped 2.36 at 19:00 UTC. The intruder still held his server and backdoored that build too. At least 230 customers took the first one.
Reality
- Evidence62
- Adoption60
- Hype gap−8
- Incentives55
- Confidence64
CVE-2026-14894 gives an unauthenticated attacker code execution on a WordPress site, and the fix is Super Forms 6.3.314. Microsoft separately reports invisible Unicode tag characters at up to 2.37 million messages a day.
Reality
- Evidence45
- Adoption30
- Hype gap+10
- Incentives40
- Confidence45
build1 publisherOne report Patchstack logged 11,334 ecosystem vulnerabilities last year, and 46% had no developer fix when they went public. That turns a care plan built on clicking Update All into a plugin inventory problem.
Reality
- Evidence42
- Adoption52
- Hype gap+28
- Incentives62
- Confidence45
The StopAndProtect campaign keeps its payloads, command channel and stolen-file storage on other people's blogs. That makes domain reputation a weaker signal, and cleanup somebody else's bill.
Reality
- Evidence66
- Adoption68
- Hype gap+14
- Incentives61
- Confidence64