Malicious PhishWP Plugin Targets WordPress E-commerce Payment Data Through Fake Checkouts
• 1 min read
A sophisticated WordPress plugin called PhishWP has emerged on Russian cybercrime forums, creating deceptive payment gateways to steal customer payment data through fake checkout pages. The malware includes advanced features like OTP functionality and real-time data transmission via Telegram, highlighting growing e-commerce security threats.
Critical Security Flaw in Popular WordPress Backup Plugin Threatens Millions of Sites
• 1 min read
A severe vulnerability discovered in UpdraftPlus WordPress plugin puts over 3 million websites at risk of code execution attacks. The high-severity flaw affects all versions up to 1.24.11 and requires immediate updating to the patched version.