Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
3 clusters · 13 sources · 10 days · First seen · Last updated
Cybersecurity vulnerabilities in WordPress and Joomla
Overview
Cybersecurity experts and agencies, including CISA, have reported an increase in attacks targeting WordPress and Joomla websites. Vulnerabilities in the WordPress ecosystem have risen significantly, with data from Patchstack indicating approximately 11,334 new vulnerabilities discovered in 2025, a 42 percent increase from the prior year. Most of these flaws reside in plugins and themes rather than the core software.
Specific threats have been identified in the Astroid template framework and the JCE content editor, with risk scores reaching 10.0. A high-severity second-order SQL injection vulnerability, CVE-2026-19949, has been identified in the All-in-One WP Migration and Backup plugin, affecting versions 7.109 and earlier. Discovered by researcher Jack Taylor and reported via Wordfence, the flaw allows unauthenticated attackers to execute remote code by planting malicious data through WordPress trackbacks. While the developer, ServMask, released a patch in version 7.110, as of early September 2026, it was estimated that approximately 3.25 million out of more than five million active installations were still running vulnerable versions.
Further complicating the landscape, a critical-severity vulnerability (CVE-2026-32475) has been identified in the Elementor Pro plugin, carrying a CVSS score of 9.8. Security firm Defiant reported that the flaw involves an arbitrary file upload issue within the plugin’s form submission function. By submitting an array containing an empty slot followed by a PHP payload, unauthenticated attackers can bypass security checks to execute code on the server. Although a patch was released in version 4.2.2 on August 19, Defiant noted that threat actors began exploiting the defect immediately following the release, blocking over 190,000 exploit attempts to date.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] CVE-2026-19949 is a second-order SQL injection vulnerability affecting All-in-One WP Migration and Backup versions through 7.109. cybernoz.com · www.it-daily.net · www.esecurityplanet.com · dev.to
- [● 3 SOURCES] Unauthenticated attackers can plant malicious data via WordPress trackbacks to trigger the exploit during an administrator's archive restoration. cybernoz.com · www.it-daily.net · dev.to
- [● 3 SOURCES] The SQL injection can expose the plugin’s secret import key, allowing attackers to import malicious archives and execute remote code. cybernoz.com · www.esecurityplanet.com · dev.to
- [● 2 SOURCES] Security researcher Jack Taylor discovered the vulnerability and reported it through Wordfence. cybernoz.com · www.esecurityplanet.com
- [● 2 SOURCES] Approximately 3.25 million sites were still running vulnerable versions of the plugin as of early September. cybernoz.com · www.esecurityplanet.com
- [● 2 SOURCES] The developer, ServMask, released a patch in version 7.110 to address the vulnerability. www.esecurityplanet.com · dev.to
- [● 2 SOURCES] The All-in-One WP Migration and Backup plugin has over five million active installations. cybernoz.com · dev.to
Timeline
-
6 days ago
[TECHNOLOGY] 3 sourcesElementor Pro WordPress plugin vulnerability exploited by hackersA critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload malicious PHP payloads and compromise websites.
-
9 days ago
[TECHNOLOGY] 5 sourcesWordPress plugin flaw exposes millions of sites to takeoverA critical SQL injection vulnerability in the All-in-One WP Migration and Backup plugin leaves millions of WordPress sites at risk of remote code execution and complete takeover.
-
15 days ago
[TECHNOLOGY] 6 sourcesWordPress and Joomla websites face increased cyberattacksCybercriminals are targeting WordPress and Joomla sites, exploiting critical vulnerabilities in plugins and themes. Patchstack reports a 42% increase in WordPress vulnerabilities in 2025.
Sources
b2k-media.de · cinemagia.wordpress.com · cybernoz.com · dev.to · esecurityplanet.com · infoguerra.com.br · it-daily.net · news.mynavi.jp · newsonline24.net · presse-board.de · pressnetwork.de · reporterbox.de · schlaunews.de
This summary has been updated 2 times: see revision history