Automattic's board voted to place founder and CEO Matt Mullenweg on paid leave, a move he says was orchestrated behind his back by CFO Mark Davies alongside board members Ann Dunwoody, Toni Schneider, and Sue Decker. Davies has been named interim CEO, though Mullenweg reportedly remains on the board. WordPress.org's executive director Mary Hubbard says the open-source project itself is unaffected and Mullenweg still leads it.
techcrunch.com
· 2026-09-09
Automattic's board voted to place founder Matt Mullenweg on paid leave and name CFO Mark Davies as interim CEO, a move Mullenweg says he opposed and learned of only shortly before the vote. Board member Toni Schneider confirmed the decision, saying Mullenweg was asked to step away while Davies takes over daily leadership, though Mullenweg retains a board seat.
404media.co
· 2026-09-09
Automattic's board has voted to put founder and CEO Matt Mullenweg on paid leave, installing CFO Mark Davies as interim CEO. Mullenweg says he opposed the move and accused Davies of conspiring with board members Ann Dunwoody, Toni Schneider, and Sue Decker to sideline him, though he will stay on the board.
theverge.com
· 2026-09-09
Netskope researchers found over 5,400 compromised small-business websites, mostly running WordPress and PrestaShop, injected with scripts that fetch malicious payloads from smart contracts on the BNB Smart Chain Testnet. Visitors are shown a fake CAPTCHA that tricks them into pasting a PowerShell command via the Windows Run dialog, which downloads and runs the attacker's final payload. Later in the campaign, attackers swapped the ClickFix payload for a stealthier WebRTC data-channel stager that opens a covert encrypted connection without a genuine handshake.
bleepingcomputer.com
· 2026-09-05
Hackers are actively exploiting CVE-2026-32475, a critical vulnerability in Elementor Pro affecting version 4.2.1 and earlier, by abusing a file-upload validation flaw in the plugin's form widget to upload malicious PHP files and run commands on compromised servers. Elementor patched the bug on August 19 with version 4.2.2, but Wordfence says exploitation began the same day and has already blocked nearly 200,000 attack attempts.
bleepingcomputer.com
· 2026-09-03
Researcher Jack Taylor found a second-order SQL injection flaw, CVE-2026-19949, in the All-in-One WP Migration and Backup WordPress plugin, used on over five million sites. Attackers can plant malicious data via trackbacks that activates when an admin exports or imports a site, exposing a secret key that lets them upload a malicious archive containing executable code and seize control of the website.
bleepingcomputer.com
· 2026-09-02
Security researchers disclosed CVE-2026-82222, a maximum-severity vulnerability in the GiveWP donation plugin affecting versions through 4.16.7.1. By chaining an unauthenticated registration bypass, an insecure PHP unserialize function, and a gadget chain in bundled libraries, attackers can create an account, plant a malicious object in the plugin's session data, and trigger arbitrary command execution on the server by simply loading a front-end page.
bleepingcomputer.com
· 2026-08-28
Wordfence researchers found a critical vulnerability chain, tracked as CVE-2026-18431 with a 9.8 severity score, in the Avada theme and its companion Fusion Builder plugin for WordPress. By chaining six separate weaknesses in a specific sequence, an attacker with no login credentials could execute arbitrary PHP code on a vulnerable server, fully compromising the site.
bleepingcomputer.com
· 2026-08-26
Security researchers say hackers are exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and log into WordPress sites as administrators. The plugin, made by Xecurify, lets sites authenticate through identity providers like Microsoft Entra ID, Okta, Google Workspace or OneLogin, and comes in a free version plus six paid editions used by roughly 30,000 customers.
bleepingcomputer.com
· 2026-08-24