Follow the latest coverage, related explainers and connected technology stories.
Attackers are exploiting stored XSS vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce plugins to plant backdoors and create hidden administrator accounts. Users are advised to update to Ninja Forms version 3.15.4 or later and WPC Product Bundles version 8.6.7 or later, while scanning sites that may have already been compromised.
Attackers have begun exploiting CVE-2026-87902 in WordPress to write PHP files to disk and run shell commands when those files are accessed, just hours after the patch was released. Site administrators are advised to update to version 7.1.2 and review logs immediately.
Researchers disclosed details of a CSRF vulnerability in the WordPress core that, without requiring an attacker account, allows a site to be forced to install a theme and execute PHP code, provided that a logged-in administrator visits a specially crafted link. WordPress addressed the issue in version 7.1.1, while the proof-of-concept exploit has become publicly available.