Tech News
← Home  ·  All topics

Wordpress

21 GoKawiil briefs on this topic

Automattic board sidelines CEO Matt Mullenweg, installs CFO as interim chief

Automattic's board voted to place founder and CEO Matt Mullenweg on paid leave, a move he says was orchestrated behind his back by CFO Mark Davies alongside board members Ann Dunwoody, Toni Schneider, and Sue Decker. Davies has been named interim CEO, though Mullenweg reportedly remains on the board. WordPress.org's executive director Mary Hubbard says the open-source project itself is unaffected and Mullenweg still leads it.

Automattic Board Ousts Matt Mullenweg as CEO, Installs Mark Davies as Interim Chief

Automattic's board voted to place founder Matt Mullenweg on paid leave and name CFO Mark Davies as interim CEO, a move Mullenweg says he opposed and learned of only shortly before the vote. Board member Toni Schneider confirmed the decision, saying Mullenweg was asked to step away while Davies takes over daily leadership, though Mullenweg retains a board seat.

Automattic Board Places CEO Matt Mullenweg on Paid Leave, Names CFO Interim Chief

Automattic's board has voted to put founder and CEO Matt Mullenweg on paid leave, installing CFO Mark Davies as interim CEO. Mullenweg says he opposed the move and accused Davies of conspiring with board members Ann Dunwoody, Toni Schneider, and Sue Decker to sideline him, though he will stay on the board.

5,400+ hacked WordPress and PrestaShop sites push ClickFix malware via BNB Smart Chain

Netskope researchers found over 5,400 compromised small-business websites, mostly running WordPress and PrestaShop, injected with scripts that fetch malicious payloads from smart contracts on the BNB Smart Chain Testnet. Visitors are shown a fake CAPTCHA that tricks them into pasting a PowerShell command via the Windows Run dialog, which downloads and runs the attacker's final payload. Later in the campaign, attackers swapped the ClickFix payload for a stealthier WebRTC data-channel stager that opens a covert encrypted connection without a genuine handshake.

Attackers exploit patched Elementor Pro flaw to plant webshells on WordPress sites

Hackers are actively exploiting CVE-2026-32475, a critical vulnerability in Elementor Pro affecting version 4.2.1 and earlier, by abusing a file-upload validation flaw in the plugin's form widget to upload malicious PHP files and run commands on compromised servers. Elementor patched the bug on August 19 with version 4.2.2, but Wordfence says exploitation began the same day and has already blocked nearly 200,000 attack attempts.

SQL injection bug in All-in-One WP Migration plugin leaves 3.25M sites vulnerable

Researcher Jack Taylor found a second-order SQL injection flaw, CVE-2026-19949, in the All-in-One WP Migration and Backup WordPress plugin, used on over five million sites. Attackers can plant malicious data via trackbacks that activates when an admin exports or imports a site, exposing a secret key that lets them upload a malicious archive containing executable code and seize control of the website.

Critical flaw in GiveWP WordPress plugin enables remote code execution

Security researchers disclosed CVE-2026-82222, a maximum-severity vulnerability in the GiveWP donation plugin affecting versions through 4.16.7.1. By chaining an unauthenticated registration bypass, an insecure PHP unserialize function, and a gadget chain in bundled libraries, attackers can create an account, plant a malicious object in the plugin's session data, and trigger arbitrary command execution on the server by simply loading a front-end page.

Avada WordPress theme flaw allows unauthenticated remote code execution

Wordfence researchers found a critical vulnerability chain, tracked as CVE-2026-18431 with a 9.8 severity score, in the Avada theme and its companion Fusion Builder plugin for WordPress. By chaining six separate weaknesses in a specific sequence, an attacker with no login credentials could execute arbitrary PHP code on a vulnerable server, fully compromising the site.

Attackers actively exploit auth-bypass flaws in miniOrange SSO plugin for WordPress

Security researchers say hackers are exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and log into WordPress sites as administrators. The plugin, made by Xecurify, lets sites authenticate through identity providers like Microsoft Entra ID, Okta, Google Workspace or OneLogin, and comes in a free version plus six paid editions used by roughly 30,000 customers.