Tech News
← Home  ·  All topics

Wordpress

21 GoKawiil briefs on this topic

Attackers exploit WordPress CVE-2026-87902 within hours of patch release

Security firm Patchstack says threat actors began exploiting a critical WordPress path traversal flaw, CVE-2026-87902, to write files that execute shell commands, after initial reconnaissance traffic surged tenfold. The bug, discovered by researcher Robert Ressl and rated 9.2/10 in severity, allows unauthenticated attackers to trick get_page_template() into loading arbitrary local PHP files under certain theme and server configurations. WordPress patched the issue in version 7.1.2 and backported fixes to branches as old as 4.7.

GreyNoise ties Red Heron-linked group to WordPress, ZyXEL exploits hitting 996 devices

GreyNoise's Global Observation Grid detected a Chinese-speaking threat actor exploiting flaws in ZyXEL GS1900 switches and WordPress's wp2shell vulnerabilities to compromise 996 devices and steal over 18,500 records. The group, linked to the Red Heron actor previously tied to a Gitea flaw, breached at least 49 organizations across 29 countries since early June 2026, including an unnamed Western government agency.

Critical WordPress Flaw Rated 9.2/10 Has Persisted Since 2016

Security researchers have identified a high-severity vulnerability in WordPress that carries a CVSS score of 9.2 out of 10, indicating it can be exploited with relatively low complexity and minimal attacker privileges. The flaw has reportedly existed in every version of the platform released since 2016, meaning it has gone undetected or unpatched for nearly a decade.

WordPress patches 'Click2Shell' CSRF flaw enabling remote code execution

Researcher Paulos Yibelo of pwn.ai disclosed a WordPress Core vulnerability, called Click2Shell, that chains a cross-site request forgery bug with the theme Customizer preview to achieve remote PHP execution. The flaw lets an attacker trick a logged-in administrator into visiting a malicious link, silently installing a theme from the WordPress.org catalog and running arbitrary PHP through the Customizer preview even before activation. WordPress fixed the issue in version 7.1.1 after it was reported in late August.

Automattic taps Jeremy Klaperman as interim CFO after leadership shakeup

Automattic has appointed Jeremy Klaperman, CFO of its WordPress VIP Enterprise unit, as interim Chief Financial Officer following the departure of former CFO Mark Davies. The move comes after a failed attempt to remove CEO Matt Mullenweg last week, which led to the exit of several board members and executives, including Davies and Chief Legal Officer Andy Missan. Mullenweg also said a new Chief Legal Officer candidate has verbally accepted the role, while the board still must formally evaluate CFO candidates.

Developer deprecates decade-old PHP polyfill package with 20 million installs

A developer who wrote a 174-line PHP polyfill in 2014 as a temporary fix for AOL's content management system has now marked the package as deprecated. The code, originally meant to replace a deprecated function from the pecl_http extension, was shared on Packagist and has since been installed nearly 20 million times, with over 400,000 installs still occurring monthly. It also spread indirectly through WPML, idna-convert, SPIP, and Linux distributions like Debian and Ubuntu.

Admin Menu Editor Pro update server hacked, plugin backdoored on 1,500 WordPress sites

A threat actor breached the website of Admin Menu Editor Pro maintainer Janis Elsts and pushed a malicious version 2.35 update that installed a web shell and created a hidden admin account on customer sites. Even after Elsts released a clean version 2.36, the attacker retained access and compromised that release too, affecting an estimated 230 customers and at least 1,500 sites.

WooCommerce Wholesale Lead Capture flaw exploited to plant PHP backdoors

Hackers are exploiting an unauthenticated file-upload vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture plugin for WordPress, versions 2.0.3.1 and earlier, to install PHP webshells. Wordfence says its firewall has blocked over 100,000 attack attempts, with spikes in June, July and August, and the shells allow attackers to gather site information and upload further malicious files.

Automattic's entire board departs days after failed bid to oust CEO Mullenweg

Sources tell TechCrunch that Automattic's board has been dissolved following a failed attempt last week to place CEO Matt Mullenweg on paid leave. Founding CEO Toni Schneider reportedly resigned his board seat, while Mullenweg removed remaining members Sue Decker and Gen. Ann Dunwoody. Automattic has not confirmed specifics but acknowledged in a statement that people have left the company.

Matt Mullenweg reclaims Automattic CEO role after board's failed ouster attempt

Automattic confirmed that Matt Mullenweg has resumed his position as CEO and chairman with the board's backing, days after the board had voted to place him on leave and install CFO Mark Davies as interim CEO. Mullenweg had resisted the removal, taking control of the company's Slack, ejecting other admins, and publicly disputing the board's authority before the company's statement settled the matter in his favor.

Mullenweg claims reinstatement as Automattic CEO days after board ouster

Matt Mullenweg told Automattic staff on Slack that he is back in control as CEO, just days after the board had voted to place him on leave and install CFO Mark Davies as interim chief. Davies' Slack account has reportedly been deactivated, but Automattic has not confirmed Mullenweg's claim, and Mullenweg says a formal blog post explaining the situation is coming.

Automattic board sidelines CEO Matt Mullenweg, CFO Mark Davies named interim chief

Automattic's board voted to place founder and CEO Matt Mullenweg on paid leave against his wishes, installing CFO Mark Davies as interim CEO. Mullenweg publicly objected in a company Slack channel, saying the board acted without giving him time to consult legal counsel. The exact reason for the ouster hasn't been disclosed, though it comes after years of legal disputes, layoffs and staff departures tied to his leadership.