Skip to content
BaeWP

WordPress News & Coverage

Monday, June 15, 2026
  • Home
  • Reviews
  • Security
  • Core
  • Hosting
  • Industry
  • Community
Latest How to Get Green Core Web Vitals on WordPress With One Plugin
Category

Security

Security

Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin

Critical RCE vulnerability in Kali Forms plugin actively exploited since March 20, 2026. Over 312,200 attacks blocked by Wordfence. Update to version 2.4.10 immediately.

Apr 14, 2026 · 5 min read
kali forms vulnerability
Security

AI Now Powers 66% of WordPress Vulnerability Research: Impacts & Insights

AI-assisted vulnerability research now drives 66% of WordPress submissions, transforming security workflows while raising stakes for defenders.

Apr 11, 2026 · 5 min read
AI vulnerability research
Security

Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026)

Wordfence's latest report reveals 54 vulnerabilities across 49 WordPress plugins, with 52 patched. XSS leads vulnerabilities, highlighting security risks.

Apr 10, 2026 · 5 min read
wordpress plugin vulnerabilities
Security

50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms Plugin

A critical vulnerability in Ninja Forms – File Upload plugin exposes 50,000 WordPress sites to remote code execution attacks. Update to version 3.3.27 immediately.

Apr 7, 2026 · 5 min read
ninja forms vulnerability
Security

Wordfence Intelligence Weekly WordPress Vulnerability Report (March 23, 2026 to March 29, 2026)

Wordfence Intelligence reports 106 vulnerabilities in WordPress plugins and themes last week, with high-threat bug bounty rewards available until April 6.

Apr 3, 2026 · 5 min read
wordpress vulnerability report
Security

200,000 WordPress Sites Affected by Arbitrary File Move Vulnerability in MW WP Form Plugin

A vulnerability in MW WP Form plugin affects 200,000 WordPress sites, risking file moves like wp-config.php. Update to version 5.1.1 immediately.

Apr 2, 2026 · 5 min read
MW WP Form vulnerability
Security

Wordfence Intelligence Weekly WordPress Vulnerability Report (March 16, 2026 to March 22, 2026)

Wordfence Intelligence disclosed 258 vulnerabilities in WordPress plugins and themes last week, with 138 patched and 120 unpatched. Critical bugs highlight ongoing risks.

Mar 29, 2026 · 5 min read
wordpress vulnerability report
Security

Wordfence Intelligence: 116 WordPress Vulnerabilities Disclosed Last Week

116 WordPress vulnerabilities were disclosed last week, including 6 critical ones. Wordfence highlights risks and urges operators to act now.

Mar 20, 2026 · 4 min read
wordpress vulnerability report
Security

WordPress Vulnerabilities Surge in March 2026 Report

WordPress security faces a surge with 201 new vulnerabilities reported last week, highlighting the need for urgent updates and vigilance.

Mar 13, 2026 · 4 min read
WordPress vulnerabilities
Security

400,000 Sites Threatened: SQL Injection in Ally Plugin

A critical SQL Injection vulnerability in the Ally plugin puts 400,000 WordPress sites at risk. Swift patching is essential to protect sensitive data.

Mar 11, 2026 · 4 min read
SQL Injection vulnerability
← 1 2 3 →

Browse Coverage

  • Community 170
  • Hosting 246
  • Industry 115
  • Jobs 1
  • Security 30
  • WordPress Core 101

Recent Stories

  1. 1 How to Get Green Core Web Vitals on WordPress With One Plugin
  2. 2 Core AI Team at WordPress Undergoes Leadership Transition: What It Means for Developers and Site Owners
  3. 3 Critical Object Injection Vulnerability Fixed in SEOPress 7.9
  4. 4 What’s New in WordPress 7.0? Features and Screenshots for Professionals
  5. 5 #217 – Leonardo Losovic on Affordable and Accurate WordPress Translations Using AI

BaeWP

Covering WordPress core, security, hosting, and the ecosystem. Trusted by developers, agencies, and site owners worldwide.

Coverage

  • WordPress Core
  • Security
  • Hosting
  • Industry
  • Community
  • Jobs

Recent

  • How to Get Green Core Web Vitals on WordPress With One Plugin
  • Core AI Team at WordPress Undergoes Leadership Transition: What It Means for Developers and Site Owners
  • Critical Object Injection Vulnerability Fixed in SEOPress 7.9
  • What’s New in WordPress 7.0? Features and Screenshots for Professionals
  • #217 – Leonardo Losovic on Affordable and Accurate WordPress Translations Using AI

Info

  • Home
© 2026 BaeWP. All rights reserved. Affiliate Disclosure