Follow the latest coverage, related explainers and connected technology stories.
A critical vulnerability in the Elementor Pro plugin is being exploited days after it was fixed, allowing malicious PHP files to be uploaded and remote commands to be executed on the site server. Wordfence says its firewall blocked more than 190,000 exploitation attempts between August 19 and 23.
An undocumented SQL injection vulnerability allows attackers to execute remote code and take control of sites using the All-in-One WP Migration and Backup plugin. ServMask issued the fix in version 7.110, but approximately 3.25 million sites are still running a vulnerable version, according to the figures cited in the report.