Sign in

Wordfence

@wordfenceofficial.bsky.social
16 followers 0 following 220 posts

Wordfence is the most popular WordPress security plugin, protecting over 5 million websites worldwide. Visit wordfence.com #WordPress #WordPressSecurtiy #Cybersecurity

PostsRepliesMedia
Wordfence @wordfenceofficial.bsky.social · 30/09/2026
Highlights from the Wordfence Quarterly WordPress Threat Intelligence Report for Q2 2026 Read Full Report: www.wordfence.com/blog/2026/09...
000
Wordfence @wordfenceofficial.bsky.social · 30/09/2026
The Wordfence Q2 2026 WordPress Threat Intelligence Report: • 2,073 Total Vulnerabilities (-24.3%) • 357 Common & Dangerous Vulnerabilities (+80.3%) • 10.4B WAF Attacks Blocked (+14.3%) • 18.2B Brute Force Attacks Blocked (+13.8%) • 573K Sites Infected (+21.0%) www.wordfence.com/blog/2026/09...
wordfence.com
Quarterly WordPress Threat Intelligence Report – Q2 2026
Wordfence's Q2 2026 threat intelligence report covers 2,073 published WordPress vulnerabilities, 182 high threat vulnerabilities, 10.4 billion blocked WAF attacks, 18.2 billion blocked brute force att...
010
Wordfence @wordfenceofficial.bsky.social · 29/09/2026
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)
000
Wordfence @wordfenceofficial.bsky.social · 24/09/2026
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026) 358 vulnerabilities (311 patched, 47 unpatched) across 243 plugins and 4 themes. www.wordfence.com/blog/2026/09...
wordfence.com
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 14, 2026 to September 20, 2026)
Last week, there were 358 vulnerabilities disclosed in 243 WordPress Plugins and 4 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 184 Vulner...
000
Wordfence @wordfenceofficial.bsky.social · 23/09/2026
PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core Update to WordPress 7.1.2 or to the fixed release listed for your current branch asap. www.wordfence.com/blog/2026/09...
wordfence.com
PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core
WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on affected server and theme configurations, remote c...
010
Wordfence @wordfenceofficial.bsky.social · 22/09/2026
Inside a Malicious, Stealthy WordPress Must Use Plugin www.wordfence.com/blog/2026/09...
wordfence.com
Inside a Malicious, Stealthy WordPress Must Use Plugin
The Wordfence Threat Intelligence Team identified an interesting malware sample in mid June during a site clean. The malware was installed as a must-use plugin with several self-healing mechanisms in ...
000
Wordfence @wordfenceofficial.bsky.social · 18/09/2026
Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server www.wordfence.com/blog/2026/09...
wordfence.com
Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file disclosure and code execution on one exact WordPre...
000
Wordfence @wordfenceofficial.bsky.social · 17/09/2026
100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS Update to 4.0.8 as soon as possible. www.wordfence.com/blog/2026/09...
wordfence.com
100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
Wordfence Argus discovered a PHP Object Injection vulnerability in Tutor LMS, affecting more than 100,000 WordPress sites. Subscriber-level attackers could achieve remote code execution. Update to ver...
000
Wordfence @wordfenceofficial.bsky.social · 15/09/2026
Boost Engagement with Free Passkeys by Wordfence Wordfence 9 introduces passkeys: Enabling passwordless login, reducing user friction, and increasing security against phishing attacks. www.wordfence.com/blog/2026/09...
wordfence.com
Boost Engagement with Free Passkeys by Wordfence
Wordfence 9 introduces passkeys, and passkeys provide a huge friction reduction because your user no longer has to remember their password or retrieve it from a password manager and copy/paste.
000
Wordfence @wordfenceofficial.bsky.social · 14/09/2026
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin Update to 2.0.3.2 as soon as possible. www.wordfence.com/blog/2026/09...
wordfence.com
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 ...
000
Wordfence @wordfenceofficial.bsky.social · 14/09/2026
Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin Update The Events Calendar to patched version 6.17.4.1 as soon as possible. www.wordfence.com/blog/2026/09...
wordfence.com
Wordfence Argus Identifies Two Critical Unauthenticated Vulnerability Chains Leading to Remote Code Execution in The Events Calendar Plugin
On August 21 and August 22, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, identified two independent critical vulnerability chains in The Events Calendar, a WordPress plugi...
000
Wordfence @wordfenceofficial.bsky.social · 10/09/2026
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026) www.wordfence.com/blog/2026/09...
wordfence.com
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 31, 2026 to September 6, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week. Review those vulnerab...
000
Wordfence @wordfenceofficial.bsky.social · 03/09/2026
Weekly WordPress Vulnerability Report: August 24-30, 2026 246 vulnerabilities (234 patched, 12 unpatched) across 174 plugins and 5 themes. www.wordfence.com/blog/2026/09...
wordfence.com
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)
Last week, there were 246 vulnerabilities disclosed in 174 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 121 Vulner...
000
Wordfence @wordfenceofficial.bsky.social · 03/09/2026
Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin Update to 6.3.314 as soon as possible. www.wordfence.com/blog/2026/09...
wordfence.com
Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerabi...
000
Wordfence @wordfenceofficial.bsky.social · 02/09/2026
Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin Update to 4.2.2 as soon as possible. www.wordfence.com/blog/2026/09...
wordfence.com
Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin
On August 19th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with more than 6,000,000 active installations. This vuln...
000
Wordfence @wordfenceofficial.bsky.social · 01/09/2026
Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms Update to Gravity Forms 3.0.3 or newer as soon as possible. www.wordfence.com/blog/2026/09...
wordfence.com
Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more t...
000
Wordfence @wordfenceofficial.bsky.social · 01/09/2026
5,000,000 WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin www.wordfence.com/blog/2026/09...
wordfence.com
5,000,000 WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active...
000
Wordfence @wordfenceofficial.bsky.social · 27/08/2026
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026) www.wordfence.com/blog/2026/08...
wordfence.com
Wordfence Intelligence Weekly WordPress Vulnerability Report (August 17, 2026 to August 23, 2026)
Last week, there were 240 vulnerabilities disclosed in 184 WordPress Plugins and 17 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 105 Vulne...
000
Wordfence @wordfenceofficial.bsky.social · 27/08/2026
Wordfence Argus: Moving Beyond Human Research Capability When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something... www.wordfence.com/blog/2026/08... #wordpress
wordfence.com
Wordfence Argus: Moving Beyond Human Research Capability
When you create an AI agent that makes a breakthrough that is so difficult to understand that you need to ask it to write a blog post to explain it to you, you know you’re on to something.
000
Wordfence @wordfenceofficial.bsky.social · 27/08/2026
Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin www.wordfence.com/blog/2026/08...
wordfence.com
Wordfence Argus Finds Critical Authentication Bypass in WPMU DEV Dashboard Plugin
On August 19th, 2026, during internal research, I discovered an Authentication Bypass vulnerability in WPMU DEV Dashboard, a WordPress plugin with an estimated 350,000 active installations. This vulne...
000
Wordfence @wordfenceofficial.bsky.social · 26/08/2026
400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin www.wordfence.com/blog/2026/08...
wordfence.com
400,000 WordPress Sites Affected by Account Takeover Vulnerability in TranslatePress WordPress Plugin
On August 11th, 2026, we received a submission for an Unauthenticated Account Takeover vulnerability in TranslatePress, a WordPress plugin with more than 400,000 active installations. This vulnerabili...
000
Wordfence @wordfenceofficial.bsky.social · 25/08/2026
Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales www.wordfence.com/blog/2026/08...
wordfence.com
Wordfence Argus Finds Complex 6 Step Critical RCE in Avada Theme with 1 Million Sales
Using an agentic framework we developed, code named Argus, we found and reproduced a critical, unauthenticated remote code execution vulnerability chain in Avada, one of the best-selling WordPress the...
000
Wordfence @wordfenceofficial.bsky.social · 21/08/2026
100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin Update to the latest patched version (3.3.9.1) as soon as possible. Read The Full Advisory: www.wordfence.com/blog/2026/08...
wordfence.com
100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin
On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability all...
000
Wordfence @wordfenceofficial.bsky.social · 20/08/2026
Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin Update to patched version (4.2.2) ASAP Full advisory: www.wordfence.com/blog/2026/08...
wordfence.com
Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vuln...
001
Wordfence @wordfenceofficial.bsky.social · 17/08/2026
600,000 WordPress Sites affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin www.wordfence.com/blog/2026/08...
wordfence.com
600,000 WordPress Sites affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms, a WordPress plugin with more than 600,000 active installations.
011
Wordfence @wordfenceofficial.bsky.social · 29/07/2026
Wordfence PRISM Detected a Supply Chain Backdoor in a WordPress Plugin with 20,000 Active Installations Within Two Hours of it Being Introduced www.wordfence.com/blog/2026/07...
wordfence.com
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin ...
000
Wordfence @wordfenceofficial.bsky.social · 23/07/2026
The WordPress security landscape has fundamentally changed. Here's how we're innovating to stay ahead of threat actors and help secure the web: www.wordfence.com/blog/2026/07...
wordfence.com
A New Threat Landscape Meets A New Kind of Defender
PRISM, our autonomous AI researcher, is now our #1 vulnerability researcher. A look at AI's new threat landscape — and the new kind of defender it demands.
010
Wordfence @wordfenceofficial.bsky.social · 20/07/2026
WordPress fixed a serious security flaw in WordPress itself on July 17. If you run a WordPress site, make sure it updated to 6.8.6, 6.9.5, or 7.0.2 — most sites auto-update, so log in and confirm — and check your admin users for anyone you don't recognize. www.wordfence.com/blog/2026/07...
wordfence.com
wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
wp2shell is a critical unauthenticated RCE chain in WordPress Core, patched July 17, 2026. See who's affected, the exploitation timeline, and what to do now.
011
Wordfence @wordfenceofficial.bsky.social · 18/07/2026
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain www.wordfence.com/blog/2026/07...
wordfence.com
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-...
020
Wordfence @wordfenceofficial.bsky.social · 23/06/2026
The latest Wordfence Security News covers these top stories: • Kirki Password Reset Flaw Allows Unauthenticated Account Takeover • UpdraftPlus Remote Management Bug Leads to Code Execution • Check Point VPN Zero-Day Exploited One Month Before Disclosure Watch now: youtu.be/rMbOlAsj14A
The latest Wordfence Security News (Episode #11) is out - Here are the top stories we covered:
000
Wordfence @wordfenceofficial.bsky.social · 18/06/2026
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin www.wordfence.com/blog/2026/06...
wordfence.com
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
On May 13th, 2026, we received a submission for a critical Unauthenticated Arbitrary File Deletion vulnerability in Avada Builder, a premium WordPress plugin with an estimated 1,000,000 active install...
000
Wordfence @wordfenceofficial.bsky.social · 17/06/2026
Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin www.wordfence.com/blog/2026/06...
wordfence.com
Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP Plugin
On March 30th, 2026, we publicly disclosed a Sensitive Information Exposure vulnerability in Gravity SMTP, a WordPress plugin with an estimated 100,000 active installations.
000
Wordfence @wordfenceofficial.bsky.social · 16/06/2026
PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels www.wordfence.com/blog/2026/06...
wordfence.com
PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels
The Wordfence Threat Intelligence Team was notified on June 11th, 2026 of a potential supply chain compromise affecting ShapedPlugin, a WordPress plugin vendor with over 400,000 active free plugin ins...
000
Wordfence @wordfenceofficial.bsky.social · 16/06/2026
UpdraftPlus Authentication Bypass Exploited Wordfence Security News Clip | June 8, 2026 A failed decryption silently falls back to an all-zeros key, giving attackers admin access to UpdraftPlus sites. www.youtube.com/watch?v=LTv6...
UpdraftPlus Authentication Bypass Exploited
012
Wordfence @wordfenceofficial.bsky.social · 16/06/2026
Cisco SD-WAN Manager Zero-Day Exploited Wordfence Security News Clip | June 8, 2026 A Cisco SD-WAN zero-day gives attackers root over every branch router in the fabric. www.youtube.com/watch?v=5Vag...
000
Wordfence @wordfenceofficial.bsky.social · 16/06/2026
Chrome 149 Patches Record-Breaking 429 Vulnerabilities Wordfence Security News Clip | June 8, 2026 Chrome 149 patches 429 vulnerabilities - nearly tripling the previous record of 151 set by Chrome 148. youtube.com/shorts/-3NHt...
Chrome 149 Patches Record-Breaking 429 Vulnerabilities
000
Wordfence @wordfenceofficial.bsky.social · 16/06/2026
Chrome 149 Patches Record-Breaking 429 Vulnerabilities Wordfence Security News Clip | June 8, 2026 Chrome 149 patches 429 vulnerabilities - nearly triple the previous record set by Chrome 148. www.youtube.com/watch?v=rPZt...
Chrome 149 Patches Record-Breaking 429 Vulnerabilities
000
Wordfence @wordfenceofficial.bsky.social · 16/06/2026
Cisco SD-WAN Manager Zero-Day Exploited Wordfence Security News Clip | June 8, 2026 A command injection zero-day in Cisco Catalyst SD-WAN Manager hands attackers root over every branch router in the fabric. www.youtube.com/shorts/-3NHt...
Cisco SD-WAN Manager Zero-Day Exploited
000
Wordfence @wordfenceofficial.bsky.social · 12/06/2026
Kirki Password Reset Exploit Wordfence Security News Clip | June 8, 2026 youtube.com/shorts/Z4Ep7...
Kirki Password Reset Exploit Goes Live
000
Wordfence @wordfenceofficial.bsky.social · 12/06/2026
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026) 159 vulnerabilities across 140 plugins and 2 themes. youtube.com/shorts/t1zDu... www.wordfence.com/blog/2026/06...
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)
000
Wordfence @wordfenceofficial.bsky.social · 12/06/2026
Checkpoint VPN Auth Bypass Exploited as Zero-Day Wordfence Security News Clip | June 8, 2026 A Checkpoint VPN flaw let attackers bypass credentials entirely - and a ransomware gang was already inside. youtube.com/shorts/nFV96...
Checkpoint VPN Auth Bypass Exploited as Zero-Day
000
Wordfence @wordfenceofficial.bsky.social · 12/06/2026
Checkpoint VPN Auth Bypass Exploited as Zero-Day Wordfence Security News Clip | June 8, 2026 A Checkpoint VPN flaw let attackers skip credentials entirely - and a ransomware gang got there first. www.youtube.com/watch?v=MWds...
Checkpoint VPN Auth Bypass Exploited as Zero-Day
010
Wordfence @wordfenceofficial.bsky.social · 11/06/2026
The latest Wordfence Security News is live! This week's top stories: • WPMaps Pro Exploited Before Public Disclosure • Palo Alto VPN Auth Bypass Under Active Attack • AI Agent Drove Live Intrusion via Marimo Flaw • Flowise Takeover Flaw Hits Self-Hosted Installs youtu.be/__yMIMJ-pPM
youtube.com
Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion
YouTube video by Wordfence
020
Wordfence @wordfenceofficial.bsky.social · 05/06/2026
LLM Agent Drove Post-Compromise Attack Wordfence Security News Clip | June 1, 2026 www.youtube.com/watch?v=Mrux...
LLM Agent Drove Post-Compromise Attack
000
Wordfence @wordfenceofficial.bsky.social · 05/06/2026
AI-Driven Post-Compromise Attack on Marimo Wordfence Security News Clip | June 1, 2026 www.youtube.com/shorts/WtaFV...
AI-Driven Post-Compromise Attack on Marimo
000
Wordfence @wordfenceofficial.bsky.social · 05/06/2026
Critical RCE in Flowise AI Platform Wordfence Security News Clip | June 1, 2026 www.youtube.com/watch?v=aURb...
Critical RCE in Flowise AI Platform
000
Wordfence @wordfenceofficial.bsky.social · 05/06/2026
Flowise Flaw Gives Attackers Root Access Wordfence Security News Clip | June 1, 2026 www.youtube.com/shorts/1P806...
Flowise Flaw Gives Attackers Root Access
000
Wordfence @wordfenceofficial.bsky.social · 05/06/2026
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 25, 2026 to May 31, 2026) 277 vulnerabilities across 184 plugins and 70 themes. 131 patched, 146 unpatched. 94 researchers contributed. www.wordfence.com/blog/2026/06...
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 25, 2026 to May 31, 2026)
000
Wordfence @wordfenceofficial.bsky.social · 05/06/2026
Attackers Abuse FortiClient EMS to Push Malware Wordfence Security News Clip | June 1, 2026 youtu.be/BZubo-mYFxg
Attackers Abuse FortiClient EMS to Push Malware
000
Wordfence @wordfenceofficial.bsky.social · 05/06/2026
FortiClient EMS Used To Push Malware Wordfence Security News Clip | June 1, 2026 youtube.com/shorts/9Z7Pm...
FortiClient EMS Used To Push Malware
000