The Wordfence Threat Intelligence team recently discovered an interesting malware variant that appears in the file system as a normal WordPress plugin containing a comment header, a handful of functions as well as a simple admin interface. Just like previous examples we have seen, this piece of malware contains code that ensures it remains hidden in the administrator dashboard. It has a password extraction feature, which requires configuration through its own admin interface, an AJAX-based remote code execution mechanism and unfinished code suggesting it is still in development.
The Wordfence Threat intelligence team finds vulnerabilities in two plugins, the User Profile Picture plugin and the WooCommerce Upload Files plugin. WordPress 5.7 is set to release on Tuesday, March 9 with numerous enhancements for the block editor, a new robots.txt API, and a stay of execution on jQuery-migrate. A zero day affecting Microsoft Exchange … Read More
The Wordfence Threat Intelligence Team was notified on June 11th, 2026 of a potential supply chain compromise affecting ShapedPlugin, a WordPress plugin vendor with over 400,000 active free plugin installations. Fortunately, Wordfence customers have already had malware signature detection for the particular backdoor used in this attack.
On April 22nd, 2026, we publicly disclosed a critical Arbitrary File Upload vulnerability in Breeze Cache, a WordPress plugin with an estimated 400,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on April 21st, 2026. Our records indicate that attackers started exploiting the issue the same day the vulnerability was disclosed in the Wordfence Intelligence vulnerability database – April 22nd, 2026. The Wordfence Firewall has already blocked over 30,000 exploit attempts targeting this vulnerability.
TL;DR: WordPress firewalls filter incoming traffic and stop malicious requests before they reach your site. WordPress-native firewalls like Wordfence use specialized threat intelligence to block attacks that generic security solutions miss. In 2024, Wordfence blocked over 54 billion malicious requests targeting WordPress sites. Attackers used SQL injection to access databases, cross-site scripting to compromise user…
TL;DR: Wordfence has become the WordPress security standard with over 5 million installations and the most comprehensive vulnerability database in the market. The choice comes down to selecting the right Wordfence tier — Free, Premium, Care, or Response — based on your website’s business role and your security management preferences. Wordfence became the most popular…
On January 12th, 2026, we received a submission for a Backdoor vulnerability in the LA-Studio Element Kit for Elementor, a WordPress plugin with more than 20,000+ active installations. This vulnerability makes it possible for an unauthenticated attacker to create malicious administrator users.
On June 10th, 2025, we received a submission for a Remote Code Execution vulnerability in Sneeit Framework, a WordPress plugin with an estimated 1,700 active installations. The plugin is bundled in multiple premium themes. This vulnerability can be leveraged to execute code remotely.
The Wordfence Threat Intelligence Team recently discovered a sophisticated malware campaign targeting WordPress e-commerce sites, specifically those using the WooCommerce plugin. This malware exhibits advanced features including custom encryption methods, fake images used to conceal malicious payloads, a robust persistence layer that allows attackers to deploy additional code on demand, all packaged as a rogue WordPress plugin.
On September 25th, 2024, and on October 3rd, 2024, we received submissions through our Bug Bounty Program for Arbitrary Plugin Installation vulnerabilities in the GutenKit and Hunk Companion WordPress plugins, which have over 40,000 and 8,000 active installations, respectively.
Breaking WordPress Security Research in your inbox as it happens.
This website uses cookies, pixels, and similar technologies (collectively “Cookies”) to improve your browsing experience. By clicking “Accept All”, you agree to the storing of Cookies on your device and that we may share, track, store, and analyze your interactions with the website to enhance site navigation, analyze site usage, and assist in our marketing efforts. For more information on our use of cookies please review our Cookie Policy.
Cookie Options
For additional information on how this site uses cookies, please review our Privacy Policy. The cookies used by this site are classified into the following categories and can be configured below.
Strictly Necessary
Always active
The “Strictly Necessary” cookies are necessary for the Sites and Services to work properly, and cannot be disabled. They include any essential authentication and authorization cookies for the Services. If you select the “Reject All” button, or choose to do nothing, only the strictly necessary cookies are active by default.
Functional
Disabled via "Do Not Sell or Share My Information" request. This category cannot be enabled.
Your browser is sending a Global Privacy Control signal which automatically disables this category. You may change your browser settings to enable it.
These cookies allow us to remember choices you make, such as your username, language, or region. This helps provide a more personalized and consistent experience by tailoring the Services to your preferences. For example, we can remember your preferred settings or login details, so you don't have to re-enter them each time you visit.
Performance/Analytical
Disabled via "Do Not Sell or Share My Information" request. This category cannot be enabled.
Your browser is sending a Global Privacy Control signal which automatically disables this category. You may change your browser settings to enable it.
These Cookies allow us to collect certain information about how you navigate the Sites or utilize the Services running on your device. They help us understand which areas you use and what we can do to improve them.
Targeting
Disabled via "Do Not Sell or Share My Information" request. This category cannot be enabled.
Your browser is sending a Global Privacy Control signal which automatically disables this category. You may change your browser settings to enable it.
These Cookies are used to deliver relevant information related to the Services to an identified machine or other device (not a named or otherwise identifiable person) which has previously been used to visit our Sites. Some of these types of Cookies on our Sites are operated by third parties with our permission and are used to identify advertising sources that are effectively driving customers to our Sites.
Do Not Sell or Share My Personal Information
This form enables you to request that we stop selling or sharing your personal information with third parties. "Selling" includes exchanging your information for money or other benefits, while "sharing" refers to providing your data to third parties for targeted advertising purposes. For more information on how we process personal information, please review our Privacy Notice.
When you submit this form, we will:
Immediately disable retargeting and remarketing cookies on your current browser/device
Browser/Device Specific: This opt-out applies to the specific browser from which you submit the request. To opt out on additional devices or browsers, you will need to submit separate requests.
Cookie Management: You may also manage cookies directly through your browser settings, or on our Cookie Control form.
Your request has been received. We will no longer share or sell your personal information on this browser.
An error occurred while attempting to submit your request. Please try again or contact support.