10,000 WordPress Sites Protected Against Site Reset and Privilege Escalation Vulnerability in Demo Importer Plus WordPress Plugin

We urge users to update their sites with the latest patched version of Demo Importer Plus, version 2.0.9 at the time of this publication, as soon as possible.

https://www.wordfence.com/blog/2026/01/10000-wordpress-sites-protected-against-site-reset-and-privilege-escalation-vulnerability-in-demo-importer-plus-wordpress-plugin/

#wordpress #wordpresssecurity #wordpresssecuritynews

Attackers Actively Exploiting Critical Vulnerability in King Addons for Elementor Plugin

https://www.wordfence.com/blog/2025/12/attackers-actively-exploiting-critical-vulnerability-in-king-addons-for-elementor-plugin/

We urge users to ensure their sites are updated with the latest patched version, version 51.1.35, ASAP

#wordpress #wordpresssecurity #wordpresssecuritynews

100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in AI Engine WordPress Plugin

https://www.wordfence.com/blog/2025/11/100000-wordpress-sites-affected-by-privilege-escalation-vulnerability-in-ai-engine-wordpress-plugin/

We urge users to update their sites with the latest patched version of AI Engine, (3.1.4) and change the token in the settings page, as soon as possible.

#wordpress #wordpressecurity #wordpresssecuritynews #cybersecurity #cybersecuritynews #wordfence #bugbounty

Attackers Actively Exploiting Critical Vulnerability in WP Freeio Plugin

https://www.wordfence.com/blog/2025/10/attackers-actively-exploiting-critical-vulnerability-in-wp-freeio-plugin/

Considering this vulnerability is under active attack, we urge users to ensure their sites are updated with the latest patched version of WP Freeio, version 1.2.22 at the time of this writing, as soon as possible.

#wordpress #wordpresssecurity #wordpresssecuritynews

100,000 WordPress Sites Affected by Vulnerability in Anti-Malware Security and Brute-Force Firewall Plugin

Please update to latest version (4.23.83) as soon as possible.

#wordpress #wordpresssecurity #wordpresssecuritynews