Skip to content
BaeWP

WordPress News & Coverage

Thursday, July 30, 2026
  • Home
  • Reviews
  • Security
  • Core
  • Hosting
  • Industry
  • Community
Latest WordPress 7.0.1 Release Schedule: What Agencies and Developers Need to Know

Report Tag: plugin vulnerability

Security

200,000 WordPress Sites at Risk from Critical Authentication Bypass Vulnerability in Burst Statistics Plugin

Wordfence researchers uncovered a critical authentication bypass in the Burst Statistics plugin impacting over 200,000 WordPress sites. Immediate updates to version 3.4.2 are essential to prevent administrator impersonation.

May 14, 2026 · 5 min read
authentication bypass vulnerability
Security

Attackers Actively Exploiting Critical Vulnerability in Breeze Cache Plugin

A critical Arbitrary File Upload vulnerability in Breeze Cache plugin is actively exploited, risking remote code execution on 400,000 WordPress sites. Immediate update to version 2.4.5 is vital.

May 6, 2026 · 5 min read
Breeze Cache vulnerability
Security

50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms Plugin

A critical vulnerability in Ninja Forms – File Upload plugin exposes 50,000 WordPress sites to remote code execution attacks. Update to version 3.3.27 immediately.

Apr 7, 2026 · 5 min read
ninja forms vulnerability
Security

200,000 WordPress Sites Affected by Arbitrary File Move Vulnerability in MW WP Form Plugin

A vulnerability in MW WP Form plugin affects 200,000 WordPress sites, risking file moves like wp-config.php. Update to version 5.1.1 immediately.

Apr 2, 2026 · 5 min read
MW WP Form vulnerability
Security

Tutor LMS Pro Authentication Bypass Exposes 30,000 WordPress Sites

A critical authentication bypass in Tutor LMS Pro affects 30,000 WordPress sites. Update to version 3.9.6 now to secure your site.

Mar 10, 2026 · 4 min read
Tutor LMS Pro authentication bypass

Browse Coverage

  • Community 170
  • Hosting 246
  • Industry 115
  • Jobs 1
  • Security 30
  • WordPress Core 101

Recent Stories

  1. 1 WordPress 7.0.1 Release Schedule: What Agencies and Developers Need to Know
  2. 2 Looking Ahead to WordCamp Europe 2026: What WordPress Professionals Should Expect
  3. 3 WordPress 7.1 Hides Classic Block from Inserter to Accelerate Block Editor Adoption
  4. 4 WordPress 7.1 Hides the Classic Block from Inserter by Default
  5. 5 Roadmap to WordPress 7.1: Collaboration, Responsive Styling, and Editorial Guidelines Take Center Stage

BaeWP

Covering WordPress core, security, hosting, and the ecosystem. Trusted by developers, agencies, and site owners worldwide.

Coverage

  • WordPress Core
  • Security
  • Hosting
  • Industry
  • Community
  • Jobs

Recent

  • WordPress 7.0.1 Release Schedule: What Agencies and Developers Need to Know
  • Looking Ahead to WordCamp Europe 2026: What WordPress Professionals Should Expect
  • WordPress 7.1 Hides Classic Block from Inserter to Accelerate Block Editor Adoption
  • WordPress 7.1 Hides the Classic Block from Inserter by Default
  • Roadmap to WordPress 7.1: Collaboration, Responsive Styling, and Editorial Guidelines Take Center Stage

Info

  • Home
© 2026 BaeWP. All rights reserved. Affiliate Disclosure