#cve — Web Hosting News

All web hosting articles tagged #cve — 29 results.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Articles tagged #cve
1–20 of 29
Security
The WordPress 7.1.2 Flaw Was Exploited in Hours. Theme and Host Decide the Damage.
by Natalia Nowak · 30 Sep 2026 · 9 min read
Attackers were writing PHP files through pearcmd.php by the evening of the day WordPress 7.1.2 shipped, and whether a site is reachable at all depends on its theme layout and on register_argc_argv, which is on by default under cPanel below PHP 8.5.
Security
WordPress 7.1.1 Fixes a Comment-Form XSS. The Payload Passes the Sanitizer.
by Natalia Nowak · 22 Sep 2026 · 10 min read
WordPress 7.1.1 fixes CVE-2026-93485, a stored XSS delivered through the ordinary comment form by an anonymous visitor and missed by wp_kses. Two of the other ten fixes came from Anthropic, and three in ten sites run a version 6 branch reached only by a backport.
Security
Ten IP Addresses Sent at Least 94,000 Attempts to Exploit a WooCommerce Plugin.
by Natalia Nowak · 15 Sep 2026 · 5 min read
A critical file-upload flaw in a paid WooCommerce extension was disclosed in February, and Wordfence has since blocked more than 100,000 attempts to exploit it. The largest published spike came on August 30, and ten source addresses account for at least 94,490 of the blocked requests.
Security
A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.
by Natalia Nowak · 9 Sep 2026 · 4 min read
cPanel has patched CVE-2026-67401. An authenticated account with mail-related privileges could create files through EmailTrack and reach code execution as root. All supported versions were affected, and the CVE record scores the flaw 9.9 out of 10, critical.
Security
WHMCS Has an Unauthenticated RCE. The Fix Exists Only for 9.0.8 and 8.13.7.
by Natalia Nowak · 4 Sep 2026 · 5 min read
Two WHMCS advisories on September 3: an unauthenticated remote code execution flaw affecting every build since 8.0, and a 2CheckOut gateway flaw exposing client data in versions from 4.5. Both are fixed in 9.0.8 and 8.13.7, and nothing older gets a patch.
Security
Attacks on the Elementor Pro Flaw Began the Day It Was Disclosed
by Natalia Nowak · 3 Sep 2026 · 6 min read
A critical Elementor Pro flaw was disclosed on August 19 and attacked the same day, with one firewall vendor blocking more than 190,000 attempts. The fix had already shipped, only sites with a published upload form were reachable, and the check for compromise takes one look at a single directory.
Security
A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
by Natalia Nowak · 2 Sep 2026 · 7 min read
Two unauthenticated flaws in plugins on millions of WordPress sites were patched the same day, days before the CVE records went public. The changelogs gave no severity signal, and for anyone running a fleet, that gap is the real story.
Security
cPanel Patches a Root-Level Flaw in Domain Parking: One Customer Account With Domain Permissions Was Enough
by Natalia Nowak · 28 Aug 2026 · 3 min read
cPanel patched CVE-2026-65643: an account holder able to add parked or addon domains could create arbitrary files and reach root, taking every site on the server. All supported versions were affected. No CVE record, no CVSS and no exploitation status published so far.
Security
Plesk Patches Three Flaws That Start From an Ordinary Customer Account
by Natalia Nowak · 26 Aug 2026 · 5 min read
Plesk's August 25 advisories cover three flaws reachable from an ordinary customer account: arbitrary file reads, cross-tenant database access, and root through two extensions. The extension fixes ship separately, and administrators report the Migrator update is not arriving.
Security
Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days
by Natalia Nowak · 20 Aug 2026 · 7 min read
Forminator's file upload flaw scores 9.8 and needs no authentication, but it takes a form with both an upload and a select field, and the default .htaccess meant to stop execution does nothing on NGINX. The changelog records twelve security releases in nineteen days.
Security
The Hypervisor Escape Comes to VMware: CVE-2026-47876 May Let a Guest VM Run Code on the ESX Host
by Natalia Nowak · 14 Aug 2026 · 8 min read
CVE-2026-47876, rated 9.3, may let a guest VM with a VMXNET3 adapter escape to the VMware ESX host. Two vCenter flaws rated 9.8 shipped in the same advisory, and one is already being exploited in the wild.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
by Natalia Nowak · 13 Aug 2026 · 6 min read
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Security
Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.
by Natalia Nowak · 12 Aug 2026 · 5 min read
Metabase's cloud service was breached through a zero-day, and the vendor patched every hosted instance before most customers heard. Self-hosted operators had to find out, patch by hand and hunt for evidence. Five customers came forward in four days, and about 2,500 instances remain visible online.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
by Natalia Nowak · 7 Aug 2026 · 8 min read
WordPress shipped its second security release in three weeks. Around the first one, both ends of the vulnerability lifecycle collapsed: an AI model found the critical chain in 10 hours for about $25, and exploitation began 90 minutes after the patch shipped. Hosting companies own the gap in between.
Security
N-able’s First Patch Left the Door Open, and Attackers Walked Back Through It
by Natalia Nowak · 3 Aug 2026 · 4 min read
A second CVE in N-able N-central exists because the first patch was incomplete, and it is being exploited to take over MSP consoles and reach every machine they manage. The August 2 hotfix closes the way in, but no vendor statement says it removes the attackers' persistence.
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
by Natalia Nowak · 29 Jul 2026 · 4 min read
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
by Natalia Nowak · 24 Jul 2026 · 6 min read
Three months after cPanel's emergency patch, attackers have turned GitHub Actions into a distributed fleet that scans the internet for servers still exposed to CVE-2026-41940 and harvests their cloud keys, tokens and database logins. How it works, and what to check.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
Security
A 16-Year-Old KVM Escape, and OVHcloud’s Week-Long Patch Across a Million VMs
by Natalia Nowak · 21 Jul 2026 · 6 min read
A 16-year-old flaw in KVM let a customer with admin access escape their virtual server and seize the host on both Intel and AMD. OVHcloud built a fix and rebooted around a million VMs in a week to deploy it, and the campaign shows the quiet choice every host makes between your consent and your safety.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 2