WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Security researchers have uncovered a sophisticated WordPress backdoor called “SC” that persistently rebuilds itself after cleanup by spreading its payload across files, the database, and shared memory. This self-healing malware uses multiple redundant loaders, including coded plugins and theme files, and communicates with a command-and-control server via the Ethereum blockchain to maintain control, evade removal, create hidden admin accounts, and deploy further malicious code. The complexity and multi-layered persistence mechanisms make it extremely difficult to fully eradicate from an infected WordPress site.

https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Attackers have begun exploiting the critical WordPress vulnerability CVE-2026-87902 within hours of its public disclosure, enabling unauthenticated remote code execution under specific conditions involving theme directory naming and readable local PHP files. Security firms Previdian and Patchstack have observed active exploitation attempts resulting in arbitrary file writes and web shell deployments, prompting urgent recommendations for WordPress site administrators to update to version 7.1.2 or later and monitor for malicious activity.

https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has patched a critical vulnerability in all supported versions from 4.7 to 7.1.1 that allowed unauthenticated attackers to load PHP files from outside theme folders, potentially enabling code execution on some servers. The issue, fixed in release 7.1.2 and backported to earlier branches, stems from improper validation of template file names, and site owners are urged to update immediately as no workaround exists. The exploit depends on specific server and theme conditions, with no known active attacks reported as of the patch release.

https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

A critical pre-authentication reflected XSS vulnerability (CVE-2026-64638) affecting all WordPress versions has been patched in WordPress 7.0.3 and backported to the 4.7 branch. Discovered by pwn.ai, the flaw allows attacker-controlled JavaScript execution on the login error page without authentication, which can escalate to PHP code execution on servers when an administrator interacts with a malicious page, enabling plugin uploads or API credential creation. WordPress site operators are urged to update immediately to mitigate risks including remote code execution, credential exposure, and persistent site compromise.

https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html

Introducing the WordPress Browser Extension

The official WordPress Browser Extension is now available for Chrome, Chromium-based browsers, and Safari, offering logged-in users the ability to hide the admin bar while retaining key shortcuts in the browser toolbar. It provides quick access to WordPress sites, tools for developers and content creators like block boundaries and cache busting, and stores data locally without tracking or sending user information externally. Developed as an open-source project with community contributions, the extension enhances site management and testing workflows directly from the browser.

https://wordpress.org/news/2026/08/browser-extension/

XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)

Security researchers at pwn.ai disclosed a critical pre-authentication vulnerability in WordPress Core (CVE-2026-64638) that allowed attackers to execute cross-site scripting (XSS) on the login page, leading to remote code execution (RCE) on the server. The exploit abused differences in how WordPress sanitizes HTML, enabling injection of malicious DOM elements that triggered admin-only REST API calls to approve application passwords, publish attacker-controlled scripts, and upload PHP plugins without user interaction. WordPress patched the flaw in version 7.0.3 and backported fixes to all maintained versions; site owners are strongly urged to update immediately.

https://pwn.ai/blog/xss2shell

WordPress Core “Wp2shell” RCE Flaws Get Public Exploits, Patch Now

Critical remote code execution vulnerabilities named “wp2shell” affecting WordPress Core versions 6.9.x and 7.0.x have public exploits released, enabling unauthenticated attackers to fully compromise default installations. The flaws stem from a REST API batch-route confusion bug and an SQL injection in WP_Query, which can be chained for pre-authentication RCE; WordPress has issued emergency updates (6.9.5 and 7.0.2) with forced auto-updates enabled, and administrators are urged to patch immediately or apply temporary mitigations such as blocking REST API access. Cloudflare has also deployed WAF rules to reduce exposure, but these do not replace the need for timely updates as in-the-wild exploitation has already been observed.

https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/

What’s New in WordPress 7.0: Impact on Your ACF Workflows

WordPress 7.0 introduces native AI infrastructure, a modernized admin experience, advanced block registration, and enhanced APIs that significantly impact ACF PRO workflows. These updates enable AI-assisted field workflows, stronger admin interfaces, dynamic block development, and deeper core data integration, while maintaining full compatibility with ACF PRO and paving the way for more scalable, AI-powered content architectures.

https://www.advancedcustomfields.com/blog/wordpress-7-0-acf-pro/

Building Custom WP-CLI Commands for Massive Data Migrations

The article explains how to build custom WP-CLI commands to perform massive data migrations in WordPress, avoiding browser timeouts and memory exhaustion by processing data in batches using PHP generators. It emphasizes managing the object cache carefully, employing SQL transactions for data safety, and using progress bars and dry-run options to maintain transparency and control during large updates.

https://deliciousbrains.com/building-custom-wp-cli-commands-for-massive-data-migrations/

WordPress Debuts my.WordPress.net Browser AI Sandbox

WordPress has launched my.WordPress.net, a browser-based sandbox that runs a full WordPress instance client-side using WebAssembly, allowing users to create and manage isolated sites without hosting or server setup. This environment includes an integrated AI Assistant and app catalog, enabling content generation experiments with models like ChatGPT, and is designed to facilitate rapid prototyping and plugin testing with data stored locally in the browser.

https://letsdatascience.com/news/wordpress-debuts-mywordpressnet-browser-ai-sandbox-c73edab1

This Free WordPress Tool Could Save Businesses Billions Every Year by Slashing the AI Tokens Needed to Read the Web — Saving Enough Electricity to Power the Entire USA for 24 Hours

The Chancery Lane Project has released an open-source WordPress plugin called Markdown for Agents that serves simplified Markdown versions of webpages to AI agents, stripping out unnecessary scripts and layout code. This approach significantly reduces data transfer—by about 80% per page—and token usage for AI processing, potentially saving billions of gigabytes and cutting energy consumption equivalent to powering the entire USA for 24 hours annually if widely adopted across WordPress sites.

https://www.techradar.com/pro/this-free-wordpress-tool-could-save-businesses-billions-every-year-by-slashing-the-ai-tokens-needed-to-read-the-web-saving-enough-electricity-to-power-the-entire-usa-for-24-hours

Why Your WordPress Site Lost Traffic (& How to Get It Back)

The WPBeginner article explains common reasons why a WordPress site may experience a sudden drop in traffic, such as tracking errors, Google manual penalties, algorithm updates, or technical issues caused by recent site changes. It provides a step-by-step troubleshooting guide to identify the cause—including verifying analytics tracking, checking Google Search Console for penalties, auditing site settings, and scanning for malware—and offers actionable advice on how to recover and maintain healthy website traffic.

https://www.wpbeginner.com/wp-tutorials/why-your-wordpress-site-lost-traffic-and-how-to-get-it-back/

Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

A newly acquired portfolio of over 30 popular WordPress plugins was found to contain a sophisticated backdoor planted by the buyer eight months before activation, enabling unauthorized access, SEO spam injection, and evasion of traditional domain takedowns by resolving command-and-control domains via Ethereum smart contracts. After discovery, WordPress.org immediately removed all affected plugins, and patched versions with the malicious module removed have been released to mitigate the widespread threat from hundreds of thousands of compromised sites. This incident highlights significant trust and security vulnerabilities in the WordPress plugin marketplace, particularly the lack of oversight around plugin ownership changes.

https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/

Moving From WordPress to Jekyll (and Static Site Generators in General)

DemandSphere completed a migration from WordPress to the static site generator Jekyll to improve site speed, flexibility, and development efficiency, leveraging AI tools like Claude Code to assist with the process. The migration involved transferring 288 blog posts, implementing advanced SEO architecture including JSON-LD schema and environment-aware configurations, building custom development tools for site auditing, and enabling client-side search without external dependencies, resulting in a faster, more manageable site better suited for rapid content updates.

https://www.demandsphere.com/blog/rebuilding-demandsphere-with-jekyll-and-claude-code/

Cloudflare Targets WordPress With New AI-Powered EmDash CMS

Cloudflare has launched EmDash CMS, an AI-powered content management system designed to address WordPress's significant security issues by sandboxing plugins and eliminating password use via passkey authentication. Developed rapidly with AI coding agents and built on modern frameworks, EmDash aims to provide a more secure, scalable, and AI-ready platform, though it faces criticism from WordPress co-founder Matt Mullenweg who favors greater openness and flexibility.

https://hackread.com/cloudflare-wordpress-ai-powered-emdash-cms/

Scroll to Top