Wordfence Research and News

Blog icon
Newest

PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response

The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress plugins directory. Currently, all the affected plugins are temporarily closed pending a full inspection and ongoing investigation by the WordPress Plugins team. Our investigation revealed …
Read More

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)

Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week.

Wordfence Bug Bounty Program Monthly Report – April 2026

In April 2026, the Wordfence Bug Bounty Program received 1288 vulnerability submissions from our growing community of security researchers working to improve the overall security posture of the WordPress ecosystem.

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 20, 2026 to July 26, 2026)

Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week.
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data

WP2Shell WordPress Exploit Technical Analysis and Real Attack Data

On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers to create an administrator account and then execute code through normal administrator capabilities, such as uploading a plugin.

Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced

On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after the malicious code was introduced.

Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)

Last week, there were disclosed in WordPress Core, and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Security last week.
A New Threat Landscape Meets A New Kind of Defender

A New Threat Landscape Meets A New Kind of Defender

PRISM, our autonomous AI researcher, is now our #1 vulnerability researcher.
wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade

wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade

wp2shell is a critical unauthenticated RCE chain in WordPress Core, patched July 17, 2026.

PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain

On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities.