Suggestions:

Malware Masquerades as Legitimate, Hidden WordPress Plugin with Remote Code Execution Capabilities

June 2, 2025

The Wordfence Threat Intelligence team recently discovered an interesting malware variant that appears in the file system as a normal WordPress plugin containing a comment header, a handful of functions as well as a simple admin interface. Just like previous examples we have seen, this piece of malware contains code that ensures it remains hidden in the administrator dashboard. It has a password extraction feature, which requires configuration through its own admin interface, an AJAX-based remote code execution mechanism and unfinished code suggesting it is still in development.

Episode 107: Two Plugin Vulnerabilities Target File Upload Capabilities

March 5, 2021

The Wordfence Threat intelligence team finds vulnerabilities in two plugins, the User Profile Picture plugin and the WooCommerce Upload Files plugin. WordPress 5.7 is set to release on Tuesday, March 9 with numerous enhancements for the block editor, a new robots.txt API, and a stay of execution on jQuery-migrate. A zero day affecting Microsoft Exchange …
Read More

PSA: Supply Chain Compromise Targets ShapedPlugin, Backdoored Pro Plugins Distributed via Official Channels

June 16, 2026

The Wordfence Threat Intelligence Team was notified on June 11th, 2026 of a potential supply chain compromise affecting ShapedPlugin, a WordPress plugin vendor with over 400,000 active free plugin installations. Fortunately, Wordfence customers have already had malware signature detection for the particular backdoor used in this attack.

Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin

May 5, 2026

On April 22nd, 2026, we publicly disclosed a critical Arbitrary File Upload vulnerability in Breeze Cache, a WordPress plugin with an estimated 400,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on April 21st, 2026. Our records indicate that attackers started exploiting the issue the same day the vulnerability was disclosed in the Wordfence Intelligence vulnerability database – April 22nd, 2026. The Wordfence Firewall has already blocked over 30,000 exploit attempts targeting this vulnerability.

The Role of Firewalls in WordPress

February 6, 2026

TL;DR: WordPress firewalls filter incoming traffic and stop malicious requests before they reach your site. WordPress-native firewalls like Wordfence use specialized threat intelligence to block attacks that generic security solutions miss. In 2024, Wordfence blocked over 54 billion malicious requests targeting WordPress sites. Attackers used SQL injection to access databases, cross-site scripting to compromise user…

Which Wordfence Product Is Right for You?

February 4, 2026

TL;DR: Wordfence has become the WordPress security standard with over 5 million installations and the most comprehensive vulnerability database in the market. The choice comes down to selecting the right Wordfence tier — Free, Premium, Care, or Response — based on your website’s business role and your security management preferences. Wordfence became the most popular…

20,000 WordPress Sites Affected by Backdoor Vulnerability in LA-Studio Element Kit for Elementor WordPress Plugin

January 21, 2026

On January 12th, 2026, we received a submission for a Backdoor vulnerability in the LA-Studio Element Kit for Elementor, a WordPress plugin with more than 20,000+ active installations. This vulnerability makes it possible for an unauthenticated attacker to create malicious administrator users.

Attackers Actively Exploiting Critical Vulnerability in Sneeit Framework Plugin

December 3, 2025

On June 10th, 2025, we received a submission for a Remote Code Execution vulnerability in Sneeit Framework, a WordPress plugin with an estimated 1,700 active installations. The plugin is bundled in multiple premium themes. This vulnerability can be leveraged to execute code remotely.

Rogue WordPress Plugin Conceals Multi-Tiered Credit Card Skimmers in Fake PNG Files

October 29, 2025

The Wordfence Threat Intelligence Team recently discovered a sophisticated malware campaign targeting WordPress e-commerce sites, specifically those using the WooCommerce plugin. This malware exhibits advanced features including custom encryption methods, fake images used to conceal malicious payloads, a robust persistence layer that allows attackers to deploy additional code on demand, all packaged as a rogue WordPress plugin.

Mass Exploit Campaign Targeting Arbitrary Plugin Installation Vulnerabilities

October 23, 2025

On September 25th, 2024, and on October 3rd, 2024, we received submissions through our Bug Bounty Program for Arbitrary Plugin Installation vulnerabilities in the GutenKit and Hunk Companion WordPress plugins, which have over 40,000 and 8,000 active installations, respectively.