CuraSec

tag: Wordpress · 18 items

2026-08-30 · The Hacker News · source ↗ #wordpress#rce#authentication-bypass
  • Engineer — Act: CVSS 9.8 authentication bypass and RCE affecting commonly deployed plugins (Avada, GiveWP, TranslatePress, Pods, WPMU DEV Dashboard), with a public PoC already on GitHub; patch all five to their latest patched releases before the PoC accelerates exploitation.
  • SOC/IR — Plan: No active exploitation confirmed (EPSS 0.00, not on KEV), but the public PoC shortens the window; build or tune detections for anomalous WordPress admin account creation and unauthenticated POST requests targeting these plugin endpoints this sprint.
  • Leader — Skip
  • Signals: CVE-2026-76581 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
2026-08-28 · BleepingComputer · source ↗ #wordpress#rce#plugin-vulnerability
  • Engineer — Plan: Maximum-severity unauthenticated RCE in GiveWP is serious, but no KEV listing, public PoC, or active exploitation is confirmed in the signals; update GiveWP to the patched version this sprint and audit any WordPress instances running it.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-27 · BleepingComputer · source ↗ #wordpress#rce#web-security
  • Engineer — Plan: Avada is among the most widely deployed commercial WordPress themes, and unauthenticated PHP code execution is a maximum-severity primitive — update Avada to the patched release this sprint. No KEV listing or public PoC is confirmed yet, so this is urgent but not emergency-weekend work.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-25 · BleepingComputer · source ↗ #wordpress#saml#auth-bypass
  • Engineer — Act: If you run the miniOrange SAML 2.0 SSO plugin on any WordPress site, update it immediately — active exploitation attempts are underway and successful attacks yield unauthenticated admin access via forged SAML responses. Audit recent admin accounts and session logs for signs of unauthorized logins.
  • SOC/IR — Act: Active exploitation is in progress; hunt for anomalous SAML authentication events and unexpected admin account creation or logins on any WordPress instances in your estate, and tune detections for unusual authentication source patterns against WordPress admin endpoints.
  • Leader — Plan: If your organization operates WordPress sites with the miniOrange SAML SSO plugin, direct teams to patch this week — a successful exploit grants full admin takeover, which could expose customer data or be used as a pivot point. Verify your WordPress plugin inventory and patch cadence.
2026-08-25 · The Hacker News · source ↗ #wordpress#saml#privilege-escalation
  • Engineer — Plan: If you run the miniOrange SAML 2.0 SSO WordPress plugin, update it immediately — unauthenticated privilege escalation to admin is high-severity, and active exploitation is claimed by Patchstack, though enrichment signals (EPSS 0.00, no KEV) don’t corroborate it yet.
  • SOC/IR — Learn: No IOCs, ATT&CK mappings, or behavioral TTPs are published; if your estate includes WordPress with SAML SSO, note this as a precursor to watching for unexpected admin account creation, but there is no actionable detection surface today.
  • Leader — Skip
  • Signals: CVE-2026-61979 — CISA KEV: not listed, EPSS 0.00, no public PoC found
2026-08-21 · BleepingComputer · source ↗ #wordpress#rce#plugin-vulnerability
  • Engineer — Plan: Update Elementor Pro to the patched version immediately; no active exploitation or PoC confirmed in signals, but RCE via file upload on a widely-deployed WordPress plugin warrants prompt patching within your normal critical window.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Act: CVSS 9.0 with a public PoC on GitHub means opportunistic exploitation is imminent; update Elementor Pro to the latest patched release immediately and audit WordPress upload directories for any unexpected PHP files already dropped via the Forms module.
  • SOC/IR — Act: A public PoC for unauthenticated RCE means mass scanning is likely underway; hunt for unauthorized PHP files in WordPress upload paths and review web server and WAF logs for suspicious POST requests targeting the Elementor Pro Forms endpoint since the disclosure date.
  • Leader — Skip
  • Signals: CVE-2026-32475 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
2026-08-19 · The Hacker News · source ↗ #wordpress#malware#data-theft
  • Engineer — Plan: Any team running WordPress should audit their installations for indicators of compromise — compromised sites are being weaponized as C2/exfil infrastructure. No specific CVE or patch is named, but review file-integrity monitoring, outbound connections, and recent plugin changes on all WordPress properties.
  • SOC/IR — Learn: The campaign involves a multi-tool malware toolkit exfiltrating documents and screenshots, but the summary provides no IOCs, ATT&CK mappings, or log signatures to hunt with — file for actor awareness and revisit if a detailed technical writeup with indicators surfaces.
  • Leader — Skip
2026-08-18 · The Hacker News · source ↗ #wordpress#rce#cve
  • Engineer — Act: A public PoC exists for this unauthenticated file upload RCE (CVSS 9.8) affecting 600,000+ WordPress installs; update Forminator Forms to the patched version immediately and verify no malicious PHP files were uploaded to wp-content directories.
  • SOC/IR — Plan: With a public PoC available, exploitation attempts are likely imminent; build or tune WAF/SIEM rules to detect unauthenticated multipart file upload requests to Forminator endpoints and alert on unexpected PHP file creation under wp-content.
  • Leader — Skip
  • Signals: CVE-2026-15748 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
2026-08-11 · BleepingComputer · source ↗ #supply-chain#wordpress#credential-access
  • Engineer — Act: Supply-chain compromise of a plugin developer pushing malicious content to admin browsers is an Act trigger regardless of KEV status. Audit all WordPress admin accounts for unauthorized additions made recently, disable BdThemes plugins until a clean version is confirmed, and rotate admin credentials on affected sites.
  • SOC/IR — Act: The attack results in rogue admin account creation — a concrete, detectable IOC. Sweep WordPress site logs and admin user tables for accounts created in the past week that were not provisioned through normal change management; flag and disable any unauthorized entries.
  • Leader — Act: If the organization runs WordPress properties using BdThemes plugins, this is an active vendor supply-chain event requiring same-week exposure confirmation. Verify whether any company or client WordPress instances use BdThemes products and request an integrity check of admin accounts from the teams responsible.
2026-08-11 · The Hacker News · source ↗ #supply-chain#wordpress#web-security
  • Engineer — Act: Active supply chain compromise affecting BdThemes WordPress plugins meets the Act threshold even without formal enrichment signals — audit all WordPress installations for BdThemes plugins and check admin user lists for unauthorized accounts created during the compromise window.
  • SOC/IR — Act: The attack surface is concrete: hunt for unexpected WordPress administrator account creation events across managed sites, correlating with BdThemes plugin presence to identify compromised instances.
  • Leader — Plan: Add WordPress plugin vendor risk to your third-party/supply chain review process; if BdThemes plugins are in use anywhere in the organization, confirm with responsible teams that no rogue admins were introduced.
2026-08-09 · The Hacker News · source ↗ #wordpress#xss#rce
  • Engineer — Act: Public PoC exists on GitHub for a flaw affecting every WordPress version; update WordPress core to the patched release immediately, as the chain to server-side PHP execution is demonstrated even though it requires an admin to visit an attacker page.
  • SOC/IR — Plan: With a public PoC but EPSS of 0.01 and no KEV listing, active exploitation is not yet confirmed; build or tune a detection for anomalous reflected XSS patterns hitting the WordPress login endpoint and alert on unexpected admin-session activity following external link clicks.
  • Leader — Skip
  • Signals: CVE-2026-64638 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
2026-07-22 · BleepingComputer · source ↗ #wordpress#webshell#cisa-kev
  • Engineer — Act: Both CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation deploying persistent webshells and rogue plugins. Patch WordPress Core immediately, then audit web root directories for unexpected PHP files and review installed plugins for unauthorized additions.
  • SOC/IR — Act: Active webshell deployment creates a concrete detection surface — sweep web server access logs for unusual POST requests to new PHP files in WordPress directories since public PoC release, hunt for unexpected process spawning from web server processes, and add rules for plugin installation events outside change-window hours.
  • Leader — Plan: WordPress is pervasive; CISA KEV listing on both CVEs signals confirmed active exploitation at scale. Confirm this week that engineering has inventoried all WordPress instances and is treating these as priority patches — a successful webshell compromise could trigger breach notification obligations if customer data is exposed.
  • Signals: CVE-2026-60137 — CISA KEV: listed, EPSS 0.04, public PoC on GitHub, reported by 2 collected sources · CVE-2026-63030 — CISA KEV: listed, EPSS 0.09, public PoC on GitHub, reported by 3 collected sources
2026-07-21 · The Hacker News · source ↗ #wordpress#rce#active-exploitation
  • Engineer — Act: Both CVEs have public PoCs and exploitation is already underway with mass scanning — patch all WordPress instances to the fixed versions immediately and audit exposed sites for webshell artifacts, especially any unexpected PHP files or modified themes.
  • SOC/IR — Act: Active exploitation confirmed since early Saturday UTC; hunt for webshell uploads and anomalous POST requests targeting WordPress endpoints across your estate, and sweep for post-compromise persistence on any internet-facing WordPress hosts.
  • Leader — Plan: Active exploitation with mass scanning is in progress but hasn’t reached Log4Shell-scale board attention yet; confirm whether WordPress appears in your web portfolio and ensure it’s on your engineering team’s immediate patching queue this week.
  • Signals: CVE-2026-60137 — CISA KEV: not listed, EPSS 0.04, public PoC on GitHub · CVE-2026-63030 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources
2026-07-21 · SANS ISC · source ↗ #wordpress#rce#sql-injection
  • Engineer — Act: Unauthenticated RCE in WordPress Core (not a plugin) is being actively exploited with a public PoC on GitHub — patch all WordPress Core installations to the latest fixed release immediately and audit web server and DB logs for SQLi patterns.
  • SOC/IR — Act: Active exploitation is confirmed; sweep any WordPress-hosting infrastructure for webshells, unexpected file writes, and anomalous database query patterns tied to wp2shell activity since last week’s disclosure.
  • Leader — Plan: Confirm whether WordPress is present in the company’s web estate and verify engineering has prioritized patching this week; not yet at board-briefing scale but unauthenticated RCE with active exploitation warrants prompt follow-up with the engineering team.
  • Signals: CVE-2026-63030 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources
2026-07-19 · BleepingComputer · source ↗ #rce#wordpress#public-exploit
  • Engineer — Act: Public exploits for critical WordPress Core RCE make this urgent regardless of absent KEV/EPSS data — update WordPress Core to the latest patched release immediately and verify any managed hosting environments are also updated.
  • SOC/IR — Plan: No IOCs or TTPs are provided to hunt on now, but given public exploits exist for a widely-deployed web platform, build or tune detections for WordPress exploit traffic (e.g., anomalous POST patterns, webshell indicators in web access logs) before active campaigns arrive.
  • Leader — Plan: This is an engineering-track issue, not board-level — confirm your team has inventoried WordPress instances across the estate and that patching is tracked to completion this week.
2026-07-18 · The Hacker News · source ↗ #wordpress#rce#unauthenticated
  • Engineer — Act: Public PoC is available for an unauthenticated RCE in WordPress core affecting 6.9 and 7.0 with no plugins required — patch every WordPress instance to the fixed version immediately and audit web server file systems for newly dropped shells or unexpected PHP files.
  • SOC/IR — Act: A public PoC for unauthenticated RCE in WordPress core means active exploitation is likely underway; sweep web access logs for anomalous POST patterns against wp-admin and wp-includes endpoints, and hunt for new or modified PHP files and unexpected child processes spawned by the web server process since the disclosure date.
  • Leader — Act: Unauthenticated RCE in WordPress core with a working public exploit is a systemic exposure for any org running WordPress-powered properties; confirm inventory of WordPress versions across customer-facing and internal sites, verify engineering has prioritized emergency patching, and assess whether key SaaS or media vendors in your supply chain are exposed.
2026-07-11 · The Hacker News · source ↗ #wordpress#web-skimming#threat-intel
  • Engineer — Act: If you host WordPress sites, audit them now for backdoors and unknown admin accounts; review your web server logs for indicators matching this campaign’s mass-exploitation pattern.
  • SOC/IR — Act: Review logs for WordPress admin-panel anomalies and unexpected file writes since the campaign has been active; hunt for web shells or unusual PHP execution tied to mass-compromise tooling.
  • Leader — Learn: Provides useful context on the scale of opportunistic WordPress compromise operations, but no immediate board-level action is required without confirmed organizational exposure.