Topic

WordPress

🇷🇺Sep 13

Hashcat Password Cracking: Why Complex Passwords Like Summer2026! Often Fail First

Password cracking tools such as hashcat and John the Ripper exploit predictable human patterns when generating candidates, allowing structured passwords to be recovered faster than truly random strings. The process relies on comparing computed hashes against stored values without needing to reverse the one-way function. Modern password storage uses salted, computationally expensive algorithms including bcrypt, Argon2id, sha512crypt and yescrypt to increase the cost of each guess. Different formats require specific hashcat modes, and parameters such as cost factors or memory settings directly affect cracking speed. WordPress 6.8 introduced bcrypt with SHA-384 preprocessing while older phpass records remain supported. Audits must preserve full hash records, verify modes on test data, and combine dictionaries, rules, masks and statistical models to measure real risk. After testing, organizations should migrate to properly tuned Argon2id and enforce long unique passphrases managed by password managers.

Securitylab•Other
🇷🇺Aug 21

Critical Unauthenticated File Upload Flaw in Elementor Pro Allows Remote Code Execution on WordPress Sites

A critical vulnerability tracked as CVE-2026-32475 has been discovered in the Elementor Pro plugin for WordPress, enabling unauthenticated attackers to upload and execute arbitrary PHP code. The flaw resides in the file upload module where validation and saving processes handle empty filenames inconsistently across multipart requests. Attackers can bypass checks by sending one part with an empty filename and another containing a PHP backdoor, which gets stored in the publicly accessible wp-content/uploads/elementor/forms/ directory. Exploitation requires a published Elementor Pro form with the multiple-file upload option enabled, a setting that is disabled by default. The free version of Elementor remains unaffected, while the issue was resolved in Elementor Pro 4.2.2. Administrators are urged to update immediately and scan upload directories for unauthorized PHP files, as no active exploitation has been observed yet but public disclosure increases the risk.

AntiMalware•Vulnerabilities & Exploits
🇵🇹Aug 19

Critical Vulnerability in Forminator Forms WordPress Plugin Enables Unauthenticated Remote Code Execution

A critical vulnerability tracked as CVE-2026-15748 with a CVSS score of 9.8 has been identified in the Forminator Forms plugin for WordPress. The flaw allows unauthenticated attackers to upload malicious PHP files by manipulating the Select field alongside a File Upload field on published forms. This bypasses extension blocking and file type validation, potentially leading to full server compromise including web shell installation and database access. The plugin, which has more than 600,000 active installations, is affected in all versions up to and including 1.56.1. The issue was resolved in version 1.56.2 released at the end of July, with later updates including 1.57.0 now available.

BoletimSec•Vulnerabilities & Exploits
🇯🇵Aug 17

Top Cybersecurity Stories of the Week: WordPress XSS Flaw, Microsoft Patch Tuesday, Cisco Zero-Day and More

Security NEXT has published its weekly ranking of the most viewed articles between August 9 and August 15 2026. The list is dominated by critical vulnerabilities affecting widely deployed platforms including WordPress, Microsoft products, Cisco networking gear and Fortinet FortiOS. A cross-site scripting issue in the WordPress login screen and a remote code execution flaw in WordPress 7.0.4 both received immediate patches. Microsoft released updates addressing more than 400 vulnerabilities, while Cisco disclosed a zero-day denial-of-service flaw in its SSL VPN implementation. Additional high-impact issues were reported in FortiOS, Google Chrome, Zoom and Jenkins, prompting urgent remediation guidance from vendors.

Security NEXT•Vulnerabilities & Exploits
🇯🇵Aug 13

WordPress 7.0.4 Released to Patch High-Severity RCE Vulnerability CVE-2026-65640

The WordPress development team has issued version 7.0.4 to address a remote code execution vulnerability tracked as CVE-2026-65640. The flaw affects installations that use the Imagick and Ghostscript image-processing components and grants code execution to users with Author privileges or higher. An attacker can upload a specially crafted PostScript file to trigger arbitrary code execution on the server. The vulnerability received a CVSS v3.0 base score of 8.8 and is rated High severity. Administrators are urged to update immediately, either manually through the dashboard or via automatic background updates. Backported fixes for the 4.7 branch are also in preparation and will be released soon.

Security NEXT•Vulnerabilities & Exploits
🇵🇹Aug 10

WordPress Patches High-Severity XSS2Shell Flaw Enabling Remote Code Execution (CVE-2026-64638)

WordPress has released a fix for a high-severity vulnerability in its core that can turn a malicious login attempt into remote PHP code execution on the server. The flaw, tracked as CVE-2026-64638 and rated 8.9 on CVSS, is named XSS2Shell and begins as a reflected cross-site scripting issue on the authentication screen. An unauthenticated attacker can submit a specially crafted username that bypasses sanitization mechanisms due to differences in how PHP and WordPress interpret certain characters, allowing controlled HTML elements to be injected into the login page. This leads to JavaScript execution in the site domain, and when an authenticated administrator visits a prepared page, the attacker can abuse the existing session to authorize application credentials and upload arbitrary PHP code. The patch is included in WordPress 7.0.3 released on August 6, with backports available for branches as old as 4.7. No public exploitation has been confirmed yet, but the technical details make immediate updating a priority for site administrators.

BoletimSec•Vulnerabilities & Exploits
🇯🇵Aug 10

Top 10 Security Stories: WordPress XSS Flaw, PHP Vulnerabilities, and VMware ESX Issues Lead Weekly Roundup

Security NEXT has published its weekly ranking of the most viewed articles for the period from August 2 to August 8, 2026. The list highlights critical vulnerabilities affecting widely used platforms including WordPress, PHP, pgAdmin 4, VMware ESX, and Chrome. Several entries focus on newly released security updates and ongoing exploitation warnings issued by US authorities. The ranking also includes real-world incidents such as credit card skimming by employees and data leaks caused by phishing attacks. This weekly overview reflects the topics that drew the highest attention from the Japanese cybersecurity community during the specified week.

Security NEXT•Vulnerabilities & Exploits
🇯🇵Aug 7

WordPress 7.0.3 Addresses 12 Vulnerabilities Including Reflected XSS Leading to PHP Execution

WordPress has released version 7.0.3 to fix multiple security issues discovered in the content management system. The update, announced on August 6, 2026, resolves 12 vulnerabilities covering cross-site scripting, privilege escalation, information disclosure, and server-side request forgery. One issue tracked as CVE-2026-64638 is a reflected XSS flaw on the login page that can be exploited without authentication. Under specific conditions the vulnerability allows an attacker to execute PHP code on the affected site. The flaw received a CVSS v4.0 base score of 8.9 and is rated High severity. Administrators are urged to apply the update immediately.

Security NEXT•Vulnerabilities & Exploits
🇷🇺Aug 2

Distributed Crawler Poses as Human Visitor to Evade Analytics and Ad Filters

A detailed investigation revealed a sophisticated distributed crawler that successfully mimicked legitimate human browsing behavior across multiple unrelated websites. The crawler generated realistic events in Google Analytics while avoiding ad script loading and resource chains that would confirm genuine user sessions. Server logs showed consistent patterns of fake search engine referrers, internal navigation with fabricated Referer headers, and selective requests limited mostly to images returning 404 errors. Analysts built a graph-based detection system that correlated events across sites to expose the coordinated activity despite individual requests appearing benign. The campaign rotated browser signatures and IP addresses frequently, making single-site rate limiting ineffective. The case demonstrates how modern crawlers can exploit Measurement Protocol and incomplete bot detection to consume server resources without contributing to revenue.

Habr•Malware & Botnets
🇯🇵Jul 21

WordPress Releases Security Update Fixing Two Vulnerabilities That Chain to Remote Code Execution

The WordPress development team has issued version 7.0.2 along with other security releases on July 17, 2026, addressing two critical vulnerabilities identified as CVE-2026-63030 and CVE-2026-60137. When combined, these flaws enable remote attackers to execute arbitrary code on affected installations. CVE-2026-60137 stems from insufficient input validation in certain functions, potentially allowing SQL injection when processing untrusted data from plugins or themes. CVE-2026-63030 involves route interpretation confusion in the REST API batch endpoint, which can be leveraged alongside the SQL injection issue to achieve code execution. The vulnerabilities impact WordPress 6.8 and later branches, although chained attacks are not possible on the 6.8 series. Administrators are urged to apply the updates immediately to mitigate the risks.

Security NEXT•Vulnerabilities & Exploits