< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 13 sources · 10 days · First seen · Last updated

Cybersecurity vulnerabilities in WordPress and Joomla

Overview

Cybersecurity experts and agencies, including CISA, have reported an increase in attacks targeting WordPress and Joomla websites. Vulnerabilities in the WordPress ecosystem have risen significantly, with data from Patchstack indicating approximately 11,334 new vulnerabilities discovered in 2025, a 42 percent increase from the prior year. Most of these flaws reside in plugins and themes rather than the core software.

Specific threats have been identified in the Astroid template framework and the JCE content editor, with risk scores reaching 10.0. A high-severity second-order SQL injection vulnerability, CVE-2026-19949, has been identified in the All-in-One WP Migration and Backup plugin, affecting versions 7.109 and earlier. Discovered by researcher Jack Taylor and reported via Wordfence, the flaw allows unauthenticated attackers to execute remote code by planting malicious data through WordPress trackbacks. While the developer, ServMask, released a patch in version 7.110, as of early September 2026, it was estimated that approximately 3.25 million out of more than five million active installations were still running vulnerable versions.

Further complicating the landscape, a critical-severity vulnerability (CVE-2026-32475) has been identified in the Elementor Pro plugin, carrying a CVSS score of 9.8. Security firm Defiant reported that the flaw involves an arbitrary file upload issue within the plugin’s form submission function. By submitting an array containing an empty slot followed by a PHP payload, unauthenticated attackers can bypass security checks to execute code on the server. Although a patch was released in version 4.2.2 on August 19, Defiant noted that threat actors began exploiting the defect immediately following the release, blocking over 190,000 exploit attempts to date.

Entities

WordPress · Wordfence · Sansec · Elementor · CISA

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 6 days ago

    [TECHNOLOGY] 3 sources
    Elementor Pro WordPress plugin vulnerability exploited by hackers

    A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload malicious PHP payloads and compromise websites.

  2. 9 days ago

    [TECHNOLOGY] 5 sources
    WordPress plugin flaw exposes millions of sites to takeover

    A critical SQL injection vulnerability in the All-in-One WP Migration and Backup plugin leaves millions of WordPress sites at risk of remote code execution and complete takeover.

  3. 15 days ago

    [TECHNOLOGY] 6 sources
    WordPress and Joomla websites face increased cyberattacks

    Cybercriminals are targeting WordPress and Joomla sites, exploiting critical vulnerabilities in plugins and themes. Patchstack reports a 42% increase in WordPress vulnerabilities in 2025.

Sources

b2k-media.de · cinemagia.wordpress.com · cybernoz.com · dev.to · esecurityplanet.com · infoguerra.com.br · it-daily.net · news.mynavi.jp · newsonline24.net · presse-board.de · pressnetwork.de · reporterbox.de · schlaunews.de

This summary has been updated 2 times: see revision history