Разработчики WordPress исправили серьезную отраженную XSS-уязвимость на странице авторизации, которая затрагивает все версии ...
IT之家 8 月 16 日消息,WordPress 近日发布 7.0.3 安全更新,修复了一项存在于核心登录页面中的高风险跨站脚本漏洞“XSS2Shell”,该漏洞编号为 CVE-2026-64638,目前已遭黑客大规模利用,遍布全球 67 个国家地区超 1.1 万个网站受影响。 IT之家参考通报获悉,“XSS2Shell”漏洞存在于 WordPress 登录流程。当用户使用不存在的账号名称尝试登 ...
IT之家 8 月 16 日消息,WordPress 近日发布 7.0.3 安全更新,修复了一项存在于核心登录页面中的高风险跨站脚本漏洞“XSS2Shell”,该漏洞编号为 CVE-2026-64638,目前已遭黑客大规模利用,遍布全球 67 ...
A malware-as-a-service (MaaS) campaign has combined ClickFix social engineering with the ErrTraffic delivery service and ...
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create ...
In einem ausführlichen Blogbeitrag führt ein Sicherheitsforscher von pwn.ai Details zur XSS2Shell-Lücke aus. Der Fehler ...
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
Ein Angreifer kompromittierte die Infrastruktur des Plugin-Anbieters BdThemes und legte darüber unbemerkt Admin-Konten auf über 350.000 WordPress-Seiten an.
The WordPress developers have closed a malicious code security vulnerability known as XSS2Shell. In a detailed blog post, a security researcher from pwn.ai explains details about the XSS2Shell ...
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
TTSWP uses ElevenLabs voices to give WordPress sites audio in 70+ languages, with a WCAG 2.1 AA player, as the EU ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results