100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in Pods WordPress Plugin

On August 10th, 2026, we received a submission for an Unauthenticated Privilege Escalation vulnerability in Pods, a WordPress plugin with more than 100,000 active installations. This vulnerability allows unauthenticated attackers to escalate their privileges to administrator and perform various administrator actions, such as overwriting the password of any user account, including the site owner’s, resulting … Read more

Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)

Last week, there were 259 vulnerabilities disclosed in 199 WordPress Plugins and 5 WordPress Themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 142 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with … Read more

Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin

On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and … Read more

AI Creates Opportunity While Artists Ship at WordCamp US 2026

WordCamp US (WCUS) 2026 just wrapped up after 4 days at the Phoenix Convention Center in Phoenix, Arizona. Over 1,100 people from around the world registered to attend, and thousands more watched online through livestreams. Contributor Day and Showcase Day opened the week before two main conference days, featuring over 50 speaker-led sessions across 4 tracks, … Read more