There's been another turn in Automattic and WordPress co-founder Matt Mullenweg’s ongoing legal battle with WordPress provider WP Engine. In a counterclaim Automattic filed as part of WP Engine [...]
There's been another turn in WordPress creator Automattic's ongoing legal battle with WordPress provider WP Engine. In a counterclaim Automattic filed as part of WP Engine's lawsuit aga [...]
An attacker bought 30+ WordPress plugins (Essential Plugin portfolio) on Flippa for six figures, planted a PHP deserialization backdoor in August 2025, then activated it eight months later to serve cl [...]
A critical vulnerability in WP Maps Pro, a commercial WordPress plugin with more than 15,000 sales on the Envato Market, is being actively exploited by attackers to create malicious administrator acco [...]
Attackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin that exposes API keys, OAuth tokens, and detailed system configuration data to anyone who sends a single unauthen [...]