Visualização normal

Antes de ontemGBHackers on Security | #1 Globally Trusted Cyber Security News Platform

WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover

A high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely used All-in-One WP Migration and Backup plugin developed by ServMask. Wordfence has rated the vulnerability 8.8 out of […]

The post WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). This vulnerability, tracked as CVE-2026-76581, has a CVSS score of 9.8 and affects WPMU DEV Dashboard versions 5.0.1 and earlier. The plugin […]

The post Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts

Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8. Research conducted by DigitalOcean’s security team and later […]

The post Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete control of affected websites by escalating privileges to the administrator level. This vulnerability, tracked as CVE-2026-19598, carries a CVSS score of 9.8 and affects Pods – Custom Content Types and Fields versions up to […]

The post Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

WordPress Supply Chain Attack Exploits BdThemes Plugins to Create Rogue Admin Accounts and Install Webshells

A supply chain compromise affecting multiple BdThemes WordPress plugins has allowed attackers to hijack administrator sessions, create unauthorized admin accounts, and deploy persistent web shells, without modifying the plugin source code or requiring a plugin update. Wordfence Threat Intelligence reported being notified of the incident on August 7, 2026. The affected plugins, distributed through the […]

The post WordPress Supply Chain Attack Exploits BdThemes Plugins to Create Rogue Admin Accounts and Install Webshells appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌