<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — WordPress</title><description>Vulnerabilities across WordPress core and its plugin and theme ecosystem — the sprawling third-party attack surface that runs a large share of the public web, where a single popular plugin flaw can cascade into hundreds of thousands of compromised sites within days of disclosure. Combined article + CVE feed for the WordPress beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>All-in-One WP Migration Flaw Hits 3M WordPress Sites</title><link>https://0daynews.com/articles/2026-09-04-all-in-one-wp-migration-cve-2026-19949-sql-injection/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-09-04-all-in-one-wp-migration-cve-2026-19949-sql-injection/</guid><description>Unauthenticated SQL injection in All-in-One WP Migration and Backup plugin (versions through 7.109) enables data theft and conditional RCE. Update immediately.</description><pubDate>Fri, 04 Sep 2026 10:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>Elementor Pro Flaw Exploited to Backdoor WordPress Sites</title><link>https://0daynews.com/articles/2026-09-04-elementor-pro-cve-2026-32475-wordpress-webshell/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-09-04-elementor-pro-cve-2026-32475-wordpress-webshell/</guid><description>Attackers are exploiting CVE-2026-32475, a critical file upload flaw in Elementor Pro, to deliver webshells to WordPress sites running version 4.2.1 or earlier.</description><pubDate>Fri, 04 Sep 2026 06:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>CVE-2019-9978 — WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability</title><link>https://0daynews.com/cve/cve-2019-9978/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-9978/</guid><description>WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>medium</category><category>cve</category></item><item><title>CVE-2020-11738 — WordPress Snap Creek Duplicator Plugin File Download Vulnerability</title><link>https://0daynews.com/cve/cve-2020-11738/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-11738/</guid><description>WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>high</category><category>cve</category></item><item><title>CVE-2020-25213 — WordPress File Manager Plugin Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-25213/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-25213/</guid><description>WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-60137 — WordPress WP_Query author__not_in SQL injection (wp2shell companion)</title><link>https://0daynews.com/cve/cve-2026-60137/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-60137/</guid><description>A medium-severity SQL injection in WordPress WP_Query&apos;s author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-63030 — WordPress Core unauthenticated RCE (wp2shell)</title><link>https://0daynews.com/cve/cve-2026-63030/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-63030/</guid><description>A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>critical</category><category>cve</category></item><item><title>Profile Builder Plugin Flaw Allows Unauth File Upload</title><link>https://0daynews.com/articles/2026-08-31-profile-builder-unauth-file-upload-cve-2026-82607/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-31-profile-builder-unauth-file-upload-cve-2026-82607/</guid><description>Cozmoslabs Profile Builder for WordPress up to 3.16.1 lets unauthenticated attackers upload files via the avatar AJAX endpoint. Patch or mitigate now.</description><pubDate>Mon, 31 Aug 2026 06:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>Avada WordPress Theme Patches Critical Zero-Click RCE</title><link>https://0daynews.com/articles/2026-08-27-avada-wordpress-zero-click-rce-cve-2026-18431/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-27-avada-wordpress-zero-click-rce-cve-2026-18431/</guid><description>ThemeFusion patches a six-flaw chain in Avada and Fusion Builder that lets unauthenticated attackers execute arbitrary PHP code. CVSS 9.8 Critical.</description><pubDate>Thu, 27 Aug 2026 07:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>miniOrange SAML WordPress Flaws Under Active Exploit</title><link>https://0daynews.com/articles/2026-08-25-miniorange-saml-wordpress-auth-bypass-exploited/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-25-miniorange-saml-wordpress-auth-bypass-exploited/</guid><description>Two authentication bypass flaws in the miniOrange SAML 2.0 SSO plugin are being actively exploited for WordPress admin takeover. Update immediately.</description><pubDate>Tue, 25 Aug 2026 16:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>Forminator WordPress Plugin RCE Flaw Hits 600K Sites</title><link>https://0daynews.com/articles/2026-08-18-forminator-wordpress-cve-2026-15748-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-18-forminator-wordpress-cve-2026-15748-rce/</guid><description>CVE-2026-15748 (CVSS 9.8) in Forminator Forms lets unauthenticated attackers upload PHP files and achieve remote code execution. Update immediately.</description><pubDate>Tue, 18 Aug 2026 08:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>Critical Flaws in Pods, Link Library Hit WordPress Sites</title><link>https://0daynews.com/articles/2026-08-16-wordpress-pods-link-library-critical-vulns/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-wordpress-pods-link-library-critical-vulns/</guid><description>Pods (CVSS 9.8) and Link Library (CVSS 9.1) expose WordPress sites to unauthenticated privilege escalation and arbitrary file deletion with RCE potential.</description><pubDate>Sun, 16 Aug 2026 22:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>MaxUpload for WordPress: Unauthenticated File Upload</title><link>https://0daynews.com/articles/2026-08-15-maxupload-cve-2026-15965-file-upload/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-maxupload-cve-2026-15965-file-upload/</guid><description>CVE-2026-15965: MaxUpload (≤1.4.0) lets unauthenticated attackers upload arbitrary files via a filename validation mismatch between chunk and final assembly. CVSS 8.8, no patch confirmed.</description><pubDate>Sat, 15 Aug 2026 22:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>Patch Now: Critical Auth Bypass Hits WordPress Plugins</title><link>https://0daynews.com/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98/</guid><description>Two WordPress plugins patched this week carry CVSS 9.8 authentication bypass flaws. A third allows unauthenticated file deletion that hands attackers RCE.</description><pubDate>Sat, 15 Aug 2026 20:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>WordPress 7.0.4 Patches High-Severity RCE Flaw</title><link>https://0daynews.com/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript/</guid><description>WordPress 7.0.4 fixes a high-severity RCE allowing Author-level accounts to execute code via malicious PostScript files. Update now.</description><pubDate>Fri, 14 Aug 2026 10:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>Three CVEs Chain to Admin Takeover in WordPress Login Plugin</title><link>https://0daynews.com/articles/2026-08-10-wp-login-register-cve-2026-18468-18469-18470/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-10-wp-login-register-cve-2026-18468-18469-18470/</guid><description>Three CVEs in the Login &amp; Register Forms WordPress plugin before 4.0.2 enable unauthenticated account takeover, including site admins. Update now.</description><pubDate>Mon, 10 Aug 2026 04:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>Both wp2shell CVEs land on CISA KEV — federal clock runs</title><link>https://0daynews.com/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock/</guid><description>CISA added both wp2shell CVEs — CVE-2026-63030 RCE and CVE-2026-60137 SQLi — to KEV on July 21. BOD 26-04 clock runs; SQLi is now framed as chainable.</description><pubDate>Wed, 22 Jul 2026 03:00:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>wp2shell mass scanning confirmed — patch triage tonight</title><link>https://0daynews.com/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage/</guid><description>Four vendors — KEVIntel, watchTowr, Wiz, Cloudflare — now confirm mass scanning of the wp2shell RCE. CMSmap webshells and backdoor admin accounts observed.</description><pubDate>Tue, 21 Jul 2026 15:15:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>wp2shell: first signs of exploitation; CVE-2026-60137 lands</title><link>https://0daynews.com/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched/</guid><description>watchTowr reports first signs of in-the-wild exploitation of the WordPress Core wp2shell RCE. The pending companion CVE-2026-60137 SQLi has landed, and exact patched versions are 6.9.5 and 7.0.2.</description><pubDate>Mon, 20 Jul 2026 01:15:00 GMT</pubDate><category>WordPress</category><category>article</category></item><item><title>WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public</title><link>https://0daynews.com/articles/2026-07-18-wordpress-core-cve-2026-63030-wp2shell-rce-poc-public/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-wordpress-core-cve-2026-63030-wp2shell-rce-poc-public/</guid><description>A critical unauthenticated remote code execution flaw in WordPress Core got a CVE, a GitHub advisory, and a working public PoC on July 17, 2026.</description><pubDate>Sat, 18 Jul 2026 13:05:00 GMT</pubDate><category>WordPress</category><category>article</category></item></channel></rss>