Pinned
- The WordPress security landscape has fundamentally changed. Here's how we're innovating to stay ahead of threat actors and help secure the web:
- wp2shell is one of the most significant WordPress security events in recent years. Here's what happened, what you should know and what you should do:
- On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase
- Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP WordPress Plugin The Wordfence Firewall has blocked over 17 million exploit attempts targeting CVE-2026-4020 (CVSS 5.3) in Gravity SMTP, a plugin with an estimated 100,000 active


