Updated 21 July 2026.

The Hacker News and mySites.guru frequently publish articles warning Wordpress CMS users of security concerns.

Most recent news postings are listed at the top of each accordion below.

The Wordpress CMS offers a big juicy target for hackers because it is used by so many websites worldwide.

This news is published here to remind owners of Joomla! CMS websites to remain vigilant.

Heads Up

The Hacker News today (21 July 2026) report that attackers have begun to exploit the critical vulnerabilities which resulted in Wordpress rushing out v7.0.2.

The Hacker News: Wordpress exploitation grows

 

Recent mySites.guru articles

17 July 2026.

"If you have any WordPress sites then drop you what you are doing right now, get out of bed, stop what you are doing and go and upgrade every single one of your WordPress sites immediately. Do not wait for auto updates to kick in. Go and do it manually. Now. Right now. You have been warned!"

Your response should be: update your Wordpress site to v7.0.2 without delay.

10 April 2026.

"Smart Slider 3 Pro version 3.5.1.35 was a malicious release".

"Not a vulnerability, not a coding mistake, not a missed capability check. An unauthorized party pushed a backdoored build through Nextend’s own update infrastructure".

mySites.guru Blog: Smart Slider 3 Pro version 3.5.1.35 was a malicious release

26 March 2026.

"A vulnerability disclosed this week lets any registered user on your site - even a basic subscriber - download your wp-config.php and every other file the web server can read. Over 800,000 WordPress sites are affected, and the same vulnerable code ships in the Joomla version too. If you run Smart Slider 3, update to version 3.5.1.34 now."

Read more: Smart Slider 3 Hack Allows Any File to Be Downloaded

Recent Hacker News articles

17 July 2026.

An anonymous HTTP request can run code on a WordPress site. The bug (a persistent-object-cache condition) is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday (17 July 2026), when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.

Read more: WordPress Core Flaw Lets Unauthenticated Attackers Run Code

15 June 2026.

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. Any site that was hit should be treated as compromised.

Read more: Popular WordPress plugin scripts plant hidden backdoors on sites

5 June 2026.

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.

Read more: Hackers exploit critical Everest Forms Pro WordPress plugin flaw

10 April 2026.

Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress ... to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35.

Read more: Backdoored Smart Slider 3 Pro Update distributed via compromised Nextend servers

15 January 2026.

A maximum-severity security flaw in a WordPress plugin called Modular DS has come under active exploitation in the wild, according to Patchstack.

Read more: Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access

8 December 2025.

A critical security flaw in the Sneeit Framework plugin for WordPress is being actively exploited in the wild, per data from Wordfence.

Read more: Critical security flaw in the Sneeit Framework plugin for WordPress

9 October 2025.

Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites.

Read more: Hackers exploit WordPress sites to power next-gen ClickFix Phishing attacks

What can you you do to protect your Joomla! CMS?

Frequently check that you are using the latest available version and release of CMS and Third Party Extensions.

Password protect your website's Administrator directory

This can be achieved via the Hosting Control Panel included with your Hosting Account.

Example: cPanel users can enable Directory Privacy via the Files panel of the cPanel Dashboard.

Read more: cPanel Dashboard.

Add a Web Application Firewall (WAF)

Akeeba Admin Tools PRO is one example of a WAF extension.

It supports password protection and the use of a secret URL to cloak your website's Administrator directory URL.

It also includes a host of other security enhancements.

Read more: Web Application Firewall.

Use Multi-factor Authentication (MFA)

Use of MFA with Administrator user accounts is made possible by a range of CMS plugins.

Read more: Multi-factor Authentication.

Keep yourself informed

Keep up to speed with the latest security threats affecting your Website.

About the mySites.guru Blog

mySites.guru publishes tips, tutorials and updates about managing WordPress and Joomla! websites in its excellent blog.

mySites.guru also publishes a really useful Email Newsletter which you can subscribe to at the link below.

Subscribe: mySites.guru Newsletter

Read more: mySites.guru Blog

About The Hacker News

"The Hacker News (THN) stands as a top and reliable source for the latest updates in cybersecurity. As an independent outlet, we offer balanced and thorough insights into the cybersecurity sector, trusted by professionals and enthusiasts alike."

Subscribe to The Hacker News newsletter when you visit the following link.

And keep up to speed with the latest security threats affecting your Operating System, Web Browser and Website.

Read more: About 'The Hacker News' Media

Make Joomla! CMS Security your #1 Priority

We help and support managers responsible for Joomla! CMS websites in UK business and third sector organisations across Cheshire, Greater Manchester, Merseyside and North West England.

Read more: WYNCHCO Joomla! CMS Help & Support.

Updated 21 July 2026.

The Hacker News and mySites.guru frequently publish articles warning Wordpress CMS users of security concerns.

Most recent news postings are listed at the top of each accordion below.

The Wordpress CMS offers a big juicy target for hackers because it is used by so many websites worldwide.

This news is published here to remind owners of Joomla! CMS websites to remain vigilant.

Heads Up

The Hacker News today (21 July 2026) report that attackers have begun to exploit the critical vulnerabilities which resulted in Wordpress rushing out v7.0.2.

The Hacker News: Wordpress exploitation grows

 

Recent mySites.guru articles

17 July 2026.

"If you have any WordPress sites then drop you what you are doing right now, get out of bed, stop what you are doing and go and upgrade every single one of your WordPress sites immediately. Do not wait for auto updates to kick in. Go and do it manually. Now. Right now. You have been warned!"

Your response should be: update your Wordpress site to v7.0.2 without delay.

10 April 2026.

"Smart Slider 3 Pro version 3.5.1.35 was a malicious release".

"Not a vulnerability, not a coding mistake, not a missed capability check. An unauthorized party pushed a backdoored build through Nextend’s own update infrastructure".

mySites.guru Blog: Smart Slider 3 Pro version 3.5.1.35 was a malicious release

26 March 2026.

"A vulnerability disclosed this week lets any registered user on your site - even a basic subscriber - download your wp-config.php and every other file the web server can read. Over 800,000 WordPress sites are affected, and the same vulnerable code ships in the Joomla version too. If you run Smart Slider 3, update to version 3.5.1.34 now."

Read more: Smart Slider 3 Hack Allows Any File to Be Downloaded

Recent Hacker News articles

17 July 2026.

An anonymous HTTP request can run code on a WordPress site. The bug (a persistent-object-cache condition) is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday (17 July 2026), when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.

Read more: WordPress Core Flaw Lets Unauthenticated Attackers Run Code

15 June 2026.

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. Any site that was hit should be treated as compromised.

Read more: Popular WordPress plugin scripts plant hidden backdoors on sites

5 June 2026.

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.

Read more: Hackers exploit critical Everest Forms Pro WordPress plugin flaw

10 April 2026.

Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress ... to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35.

Read more: Backdoored Smart Slider 3 Pro Update distributed via compromised Nextend servers

15 January 2026.

A maximum-severity security flaw in a WordPress plugin called Modular DS has come under active exploitation in the wild, according to Patchstack.

Read more: Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin Access

8 December 2025.

A critical security flaw in the Sneeit Framework plugin for WordPress is being actively exploited in the wild, per data from Wordfence.

Read more: Critical security flaw in the Sneeit Framework plugin for WordPress

9 October 2025.

Cybersecurity researchers are calling attention to a nefarious campaign targeting WordPress sites to make malicious JavaScript injections that are designed to redirect users to sketchy sites.

Read more: Hackers exploit WordPress sites to power next-gen ClickFix Phishing attacks

What can you you do to protect your Joomla! CMS?

Frequently check that you are using the latest available version and release of CMS and Third Party Extensions.

Password protect your website's Administrator directory

This can be achieved via the Hosting Control Panel included with your Hosting Account.

Example: cPanel users can enable Directory Privacy via the Files panel of the cPanel Dashboard.

Read more: cPanel Dashboard.

Add a Web Application Firewall (WAF)

Akeeba Admin Tools PRO is one example of a WAF extension.

It supports password protection and the use of a secret URL to cloak your website's Administrator directory URL.

It also includes a host of other security enhancements.

Read more: Web Application Firewall.

Use Multi-factor Authentication (MFA)

Use of MFA with Administrator user accounts is made possible by a range of CMS plugins.

Read more: Multi-factor Authentication.

Keep yourself informed

Keep up to speed with the latest security threats affecting your Website.

About the mySites.guru Blog

mySites.guru publishes tips, tutorials and updates about managing WordPress and Joomla! websites in its excellent blog.

mySites.guru also publishes a really useful Email Newsletter which you can subscribe to at the link below.

Subscribe: mySites.guru Newsletter

Read more: mySites.guru Blog

About The Hacker News

"The Hacker News (THN) stands as a top and reliable source for the latest updates in cybersecurity. As an independent outlet, we offer balanced and thorough insights into the cybersecurity sector, trusted by professionals and enthusiasts alike."

Subscribe to The Hacker News newsletter when you visit the following link.

And keep up to speed with the latest security threats affecting your Operating System, Web Browser and Website.

Read more: About 'The Hacker News' Media

Make Joomla! CMS Security your #1 Priority

We help and support managers responsible for Joomla! CMS websites in UK business and third sector organisations across Cheshire, Greater Manchester, Merseyside and North West England.

Read more: WYNCHCO Joomla! CMS Help & Support.

By browsing our website you agree to its use of cookies. Cookie Policy.