A Chinese-speaking threat actor exploited vulnerabilities in ZyXEL GS1900 switches and WordPress to steal over 18,500 records from backend databases.
WordPress has issued updates to fix the ‘Click2Shell’ vulnerability, a flaw that allows unauthenticated attackers to potentially execute remote code.
Attackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP webshells and execute remote code on WordPress sites.
WordPress has introduced automated security reviews for plugin releases to identify malicious code and vulnerabilities before they reach users through the update API.
WordPress is launching automated security reviews for every plugin release to identify high-risk updates and malicious code before they are distributed.