Skip to content
BaeWP

WordPress News & Coverage

Monday, June 15, 2026
  • Home
  • Reviews
  • Security
  • Core
  • Hosting
  • Industry
  • Community
Latest How to Get Green Core Web Vitals on WordPress With One Plugin

Report Tag: wordpress security

Security

Authenticated Arbitrary File Upload Vulnerability Patched in Slider Revolution 7 WordPress Plugin

An authenticated arbitrary file upload vulnerability affecting Slider Revolution 7.0.0 to 7.0.10 has been patched in version 7.0.11. This flaw allowed subscriber-level users to achieve remote code execution.

May 7, 2026 · 5 min read
slider revolution vulnerability
Industry

WordPress.org Closes 31 Plugins After Backdoor Planted Across Flippa Portfolio

WordPress.org has closed 31 plugins due to a backdoor planted post-acquisition on Flippa. The malicious code remained dormant for eight months before activation.

Apr 18, 2026 · 5 min read
wordpress plugin backdoor
Security

Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)

154 vulnerabilities were disclosed last week across 118 plugins and 23 themes. Wordfence tools help users monitor and patch risks effectively.

Apr 17, 2026 · 5 min read
wordpress vulnerabilities report
Security

Attackers Actively Exploiting Critical Vulnerability in Ninja Forms – File Upload Plugin

A critical vulnerability in Ninja Forms – File Upload plugin is actively exploited, affecting 50,000 WordPress sites. Update to version 3.3.27 immediately.

Apr 17, 2026 · 5 min read
ninja forms vulnerability
Security

Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin

Critical RCE vulnerability in Kali Forms plugin actively exploited since March 20, 2026. Over 312,200 attacks blocked by Wordfence. Update to version 2.4.10 immediately.

Apr 14, 2026 · 5 min read
kali forms vulnerability
Security

Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026)

Wordfence's latest report reveals 54 vulnerabilities across 49 WordPress plugins, with 52 patched. XSS leads vulnerabilities, highlighting security risks.

Apr 10, 2026 · 5 min read
wordpress plugin vulnerabilities
Hosting

What ‘Enterprise-Ready’ Means for WordPress Hosting (And How Some Hosts Misuse It)

Many WordPress hosts misuse 'enterprise-ready,' focusing on traffic instead of governance and security. Here's what truly defines enterprise hosting.

Apr 8, 2026 · 5 min read
enterprise-ready wordpress hosting
Security

50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms Plugin

A critical vulnerability in Ninja Forms – File Upload plugin exposes 50,000 WordPress sites to remote code execution attacks. Update to version 3.3.27 immediately.

Apr 7, 2026 · 5 min read
ninja forms vulnerability
Security

Wordfence Intelligence Weekly WordPress Vulnerability Report (March 23, 2026 to March 29, 2026)

Wordfence Intelligence reports 106 vulnerabilities in WordPress plugins and themes last week, with high-threat bug bounty rewards available until April 6.

Apr 3, 2026 · 5 min read
wordpress vulnerability report
Security

200,000 WordPress Sites Affected by Arbitrary File Move Vulnerability in MW WP Form Plugin

A vulnerability in MW WP Form plugin affects 200,000 WordPress sites, risking file moves like wp-config.php. Update to version 5.1.1 immediately.

Apr 2, 2026 · 5 min read
MW WP Form vulnerability
1 2 3 →

Browse Coverage

  • Community 170
  • Hosting 246
  • Industry 115
  • Jobs 1
  • Security 30
  • WordPress Core 101

Recent Stories

  1. 1 How to Get Green Core Web Vitals on WordPress With One Plugin
  2. 2 Core AI Team at WordPress Undergoes Leadership Transition: What It Means for Developers and Site Owners
  3. 3 Critical Object Injection Vulnerability Fixed in SEOPress 7.9
  4. 4 What’s New in WordPress 7.0? Features and Screenshots for Professionals
  5. 5 #217 – Leonardo Losovic on Affordable and Accurate WordPress Translations Using AI

BaeWP

Covering WordPress core, security, hosting, and the ecosystem. Trusted by developers, agencies, and site owners worldwide.

Coverage

  • WordPress Core
  • Security
  • Hosting
  • Industry
  • Community
  • Jobs

Recent

  • How to Get Green Core Web Vitals on WordPress With One Plugin
  • Core AI Team at WordPress Undergoes Leadership Transition: What It Means for Developers and Site Owners
  • Critical Object Injection Vulnerability Fixed in SEOPress 7.9
  • What’s New in WordPress 7.0? Features and Screenshots for Professionals
  • #217 – Leonardo Losovic on Affordable and Accurate WordPress Translations Using AI

Info

  • Home
© 2026 BaeWP. All rights reserved. Affiliate Disclosure