← Back
VulnerabilityThe Hacker News·4 hours ago

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical vulnerabilities affecting popular WordPress plugins and themes—including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—have been disclosed by Wordfence and Patchstack researchers. These flaws enable attackers to bypass authentication, take over accounts, and achieve arbitrary code execution on affected WordPress installations. The most severe vulnerability has a CVSS score of 9.8, representing an immediate threat to site integrity and data security.

Read full article at The Hacker News

Related Articles

VulnerabilitySecurity Affairs·9 hours ago

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

A security researcher discovered multiple vulnerabilities in the Unitree G1 humanoid robot that allow remote root access without physical interaction, and demonstrated how a compromised unit could be weaponized to attack neighboring robots. By chaining two separate flaws together, the researcher established a concerning attack vector that reveals the propagation risks within networked robotic systems. The three-month investigation highlights significant security gaps in the robot's design that could have broad implications for deployments in shared or industrial environments.

VulnerabilityUnit 42·23 hours ago

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

VulnerabilityThe Hacker News·1 day ago

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs disclosed that a critical balance-handling vulnerability in its shared EVM module was actively exploited to drain funds from six blockchains over a five-day period in August 2026, despite the company's awareness that every blockchain using the module was vulnerable. The flaw, tracked as GHSA-7g4w-cg88-2cq2, was published without standard vulnerability identifiers or severity scoring, complicating threat assessment and response coordination across affected networks.

VulnerabilityThe Hacker News·1 day ago

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Attackers are chaining two vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution by compromising the application's trusted configuration. PaperCut has released an emergency patch with additional hardening measures to address the flaw. The vulnerability allows malicious actors to execute arbitrary Java code within the application without requiring authentication credentials.