Patchstack (WordPress vulnerability research and exploitation telemetry)
patchstack · B · candidate
https://patchstack.com/articles/
Added 2026-10-07: S1 candidate; the feed https://patchstack.com/feed/ reads directly. First-party exploitation telemetry for WordPress plugin and theme flaws; its 2026-10-06 analysis of the hidden-administrator stored-XSS campaign is the primary of a published entry and BleepingComputer only restates it.
Cited in 6 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 5).
- CVE-2026-94504 / CVE-2026-93836, Ninja Forms and WPC Product Bundles for WooCommerce: stored XSS exploited to plant a hidden WordPress administrator and four persistence routes that survive the update2026-10-07
- CVE-2026-87902, WordPress Core: unauthenticated page-template path traversal to conditional remote code execution, weaponised within a day (CVSS4.0 9.2)2026-09-24
- miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line2026-08-28
- Elementor Pro (WordPress): unauthenticated arbitrary file upload to RCE via a validator/mover desynchronization in the Forms File Upload field (CVE-2026-32475, CVSS 9.0)2026-08-28
- WordPress supply-chain compromise via Awesome Motive's CDN backdoors ~1.2M sites2026-06-16
- CVE-2026-8206 + CVE-2026-8181, Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation2026-06-04