Skip to content
The Nexus
DossierENTITY

Wordfence

Coverage of Wordfence in the Nexus archive.

Earliest in view: Jun 22 · 18:00 UTCMost recent: Aug 11 · 05:48 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 11 · 05:48 UTCTHE HACKER NEWS
    BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

    A supply chain compromise impacted WordPress plugin vendor BdThemes, leading the CMS platform's plugins team to temporarily disable their downloads. Cybersecurity researchers issued warnings regarding this issue. However, they noted that zero source code files were modified within the official WordPress.org repository.

  • SECURITYJul 21 · 14:57 UTCMALWAREBYTES LABS
    What happens if you visit a WordPress site hacked through wp2shell?

    WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.

  • SECURITYJun 22 · 18:00 UTCTHE HACKER NEWS
    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

    Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after threat actors injected backdoor code into Pro plugin releases through official licensed update channels. Wordfence analyzed the incident, confirming the vendor's build and distribution pipeline was compromised.

Wordfence · Dossier · The Nexus