More than 40,000 WordPress sites affected by malware flaw

A vulnerability in a popular WordPress quiz plugin has impacted over 40,000 sites, allowing potential SQL injection attacks. Security researchers have identified the flaw, urging site owners to check for exposure. The issue was reported on February 4, 2026.

The cybersecurity community has raised alarms over a newly discovered malware flaw targeting WordPress sites. According to reports, more than 40,000 installations are at risk due to a vulnerability in a widely used quiz plugin. This plugin, which enables interactive quizzes on websites, contains a weakness that can be exploited for SQL injection attacks.

SQL injection is a common hacking technique where attackers insert malicious code into a query, potentially stealing data or disrupting site functions. The flaw's discovery highlights ongoing challenges in securing content management systems like WordPress, which powers a significant portion of the web.

Site administrators are advised to review their plugins and apply any available updates or patches immediately. While specific details on the plugin's name were not disclosed in initial reports, the scale of the affected sites underscores the urgency of the situation. TechRadar published the findings on February 4, 2026, emphasizing the need for users to verify if their sites are compromised.

This incident serves as a reminder of the importance of regular security audits for WordPress users. No further details on exploitation or mitigation steps were provided in the initial alert, but experts recommend monitoring for unusual activity.

相关文章

Illustration depicting the Linux CopyFail vulnerability enabling root access exploits alongside Ubuntu's DDoS-induced outage.
AI 生成的图像

Linux CopyFail exploit threatens root access amid Ubuntu outage

由 AI 报道 AI 生成的图像

A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.

A security vulnerability in the WordPress plugin Ally has been identified as an SQL injection flaw. This issue could potentially affect up to 250,000 websites using the plugin. The flaw was reported in a TechRadar article published on March 12, 2026.

由 AI 报道

Adult entertainment website Frivol has disclosed a data leak that may impact around 479,000 users. The breach involved an open database containing user details. The revelation was reported on February 25, 2026.

A critical remote code execution vulnerability has been discovered in multiple BeyondTrust products. The flaw, rated 9.9 out of 10 in severity, allows hackers to run code on affected systems without needing to log in. The issue was reported on February 10, 2026.

由 AI 报道

Security specialists have raised alarms over the vulnerability of online accounts, stating that almost half of all passwords in use today can be broken within minutes.

Flare researchers have identified a new Linux botnet called SSHStalker that has compromised around 7,000 systems using outdated exploits and SSH scanning. The botnet employs IRC for command-and-control while maintaining dormant persistence without immediate malicious activities like DDoS or cryptomining. It targets legacy Linux kernels, highlighting risks in neglected infrastructure.

此网站使用 cookie

我们使用 cookie 进行分析以改进我们的网站。阅读我们的 隐私政策 以获取更多信息。
拒绝