Výsledky hledání

výrobce: WordPress× v celém archivu zrušit filtry

24 karet z 33 položek CZ · EN/orig

1

3

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

WordPress Admin Menu Editor US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec

· BleepingComputer · Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Rilevate vulnerabilità nel tema WordPress “Design Scuole Italia”

Rilevate quattro vulnerabilità, di cui due con gravità “alta”, in Design Scuole Italia, noto tema WordPress destinato alla realizzazione dei siti istituzionali delle scuole italiane. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di leggere file arbitrari sul filesystem, eludere i meccanismi di autenticazione ed accedere a informazioni sensibili sui sistemi interessati

EPSS 0.00 CVE-2026-87791 CVE-2026-87792 CVE-2026-87793 CVE-2026-89307 WordPress Design Scuole Italia školství IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Rilevate vulnerabilità nel tema WordPress “Design Scuole Italia”

1

1

1

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…

EPSS 0.03 CVSS 10.0 CVE-2026-18431 CVE-2026-19598 CVE-2026-19632 CVE-2026-76581 CVE-2026-82222 WordPress WPMU DEV Avada TranslatePress FI

tg: zneužíváno tg: zranitelnost tp: dodavatelský řetězec

· NCSC-FI · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

1

1

1

SPOJENO PŘES CVE Hackers target WordPress sites in miniOrange auth bypass attacks

Classification: Severe, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8, CVEs: CVE-2026-61979, CVE-2026-15981, Summary: The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select…

EPSS 0.01 CVSS 9.8 CVE-2026-15981 CVE-2026-61979 WordPress miniOrange FI US

tg: varování tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-FI · Hackers target WordPress sites in miniOrange auth bypass attacks · BleepingComputer · Hackers target WordPress sites in miniOrange auth bypass attacks

1

SPOJENO PŘES CVE WordPress: rilevato sfruttamento di vulnerabilità nel plugin Pods

Rilasciati aggiornamenti di sicurezza che sanano una vulnerabilità, con gravità “critica”, presente nel plugin Pods per WordPress. Tale vulnerabilità, qualora sfruttata, potrebbe permettere a un utente non autenticato di ottenere privilegi elevati sul sistema interessato, compreso l'accesso amministrativo e la modifica delle password degli utenti.

EPSS 0.03 CVE-2026-19598 WordPress IT

· CSIRT Itálie (ACN) · WordPress: rilevato sfruttamento di vulnerabilità nel plugin Pods

1

Kritické zranitelnosti ohrožují stovky tisíc webů využívajících redakční systém WordPress

Bezpečnostní výzkumníci upozornili na dvě kritické zranitelnosti v populárních pluginech pro WordPress. CVE-2026-15748 (CVSS 9,8) se týká pluginu Forminator Forms s více než 600 tisíci aktivními instalacemi. Neautentizovaný útočník může na zranitelný web nahrát škodlivý PHP soubor a za určitých podmínek dosáhnout vzdáleného spuštění kódu a úplného převzetí webu. Podmínkou zneužití je formulář obsahující současně pole File Upload a Select. Zranitelné jsou verze do 1.56.1 včetně, oprava je…

EPSS 0.05 CVSS 9.8 CVE-2026-15748 CVE-2026-15826 WordPress CZ

· CSIRT.CZ (CZ.NIC) · Kritické zranitelnosti ohrožují stovky tisíc webů využívajících redakční systém WordPress

1

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) Key points StopAndProtect is a newly identified operation that combines file encryption with data theft. The criminals abuse thousands of hacked WordPress websites as their infrastructure – using them to spread the malware, control infected machines, and store stolen documents, screenshots, and activity logs (records created by malware to track its actions, progress, or status during execution). Operational security (OPSEC) failures by the…

WordPress IL

tg: varování tg: rozbor tp: malware tp: phishing tp: ransomware tp: únik dat

· Check Point Research · Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

3

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads …

KEV ✓ · ransomware EPSS 0.97 CVE-2025-49132 CVE-2026-15409 CVE-2026-27760 CVE-2026-29053 CVE-2026-3891 CVE-2026-46300 CVE-2026-48907 CVE-2026-60137 CVE-2026-63030 WordPress Ghost CMS SonicWall Linux US

tg: novinka v produktu tg: přehled

· Rapid7 · Metasploit Wrap Up: Lot of summer shells and fit http profiles

SPOJENO PŘES CVE Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress

Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.

KEV ✓ EPSS 0.97 CVSS 9.0 CVE-2026-60137 CVE-2026-63030 WordPress CZ US AT FR

tg: zneužíváno tg: rozbor tg: návod tg: přehled tp: malware tp: ransomware

· NÚKIB · Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress · Cisco Talos · Don’t swing at everything · Elastic Security · wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution · CERT.at · Kritische Sicherheitslücken in WordPress - Updates verfügbar · CERT-FR – alerty · Multiples vulnérabilités dans WordPress (20 juillet 2026)

1

SPOJENO PŘES CVE WordPress security advisory (AV26-792)

Serial Number: AV26-792Date: August 10, 2026 As of August 7, 2026, WordPress is affected by a vulnerability in the following product: WordPress prior to 7.0.3 Open-source reporting indicates that CVE-2026-64638 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. WordPress 7.0.3 release – WordPress News

EPSS 0.31 CVE-2026-64638 WordPress CA RO

· Cyber Centre Kanada · WordPress security advisory (AV26-792) · DNSC Rumunsko · ALERTĂ: Vulnerabilitate critică la nivelul WordPress (XSS2Shell)

1

2

1

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ · ransomware EPSS 0.97 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

· Check Point Research · 20th July – Threat Intelligence Report

1

1

Postřehy z bezpečnosti: armáda botů řízená přes herní fóra Steam

Dnešní vydání našich Postřehů z bezpečnosti přináší informace o tom, jak malware řídil armádu WordPressů přes platformu Steam nebo jak se nechal omámit asistent Google Gemini. Dále si na Root.cz můžete přečíst o balíčcích Red Hatu kradoucí přístupové údaje a o českém projektu Phishguard Sentinel chránící internetové uživatele.

WordPress Red Hat Google Steam CZ

· CSIRT.CZ (CZ.NIC) · Postřehy z bezpečnosti: armáda botů řízená přes herní fóra Steam

1