Wordfence Intelligence Weekly WordPress Vulnerability Report (June 2, 2025 to June 8, 2025)

Calling all Vulnerability Researchers and Bug Bounty Hunters!   Spring into Summer with Wordfence! Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Bounties up to $31,200 per vulnerability. Submit bold. Earn big! Last week, there were … Read more

33,000 WordPress Sites Affected by Privilege Escalation Vulnerability in RealHomes WordPress Theme

🌞 Spring Into Summer Challenge: Critical Threats = Critical Rewards. 🌞 🔥 Now through August 4, 2025, earn 2X bounty rewards for all in-scope submissions from our ‘High Threat’ list in software with fewer than 5 million active installs. Submit bold. Earn big!🔥 On May 4th, 2025, we received a submission for a Privilege Escalation … Read more

Wordfence Intelligence Weekly WordPress Vulnerability Report (May 26, 2025 to June 1, 2025)

In case you missed it, Wordfence just published its annual WordPress security report for 2024. Read it now to learn more about the evolving risk landscape of WordPress so you can keep your sites protected in 2025 and beyond.   Last week, there were 64 vulnerabilities disclosed in 59 WordPress Plugins and 3 WordPress Themes that … Read more

9,000 WordPress Sites Affected by Arbitrary File Upload and Deletion Vulnerabilities in WP User Frontend Pro WordPress Plugin

📢 In case you missed it, Wordfence just published its annual WordPress security report for 2024. Read it now to learn more about the evolving risk landscape of WordPress so you can keep your sites protected in 2025 and beyond.   On March 24th, 2025, we received a submission for an Arbitrary File Upload and an … Read more

Malware Masquerades as Legitimate, Hidden WordPress Plugin with Remote Code Execution Capabilities

📢 In case you missed it, Wordfence just published its annual WordPress security report for 2024. Read it now to learn more about the evolving risk landscape of WordPress so you can keep your sites protected in 2025 and beyond.   The Wordfence Threat Intelligence team recently discovered an interesting malware variant that appears in the … Read more