Skip to content
Vulnerability intelligence

CVE-2026-1293 — WordPress Vulnerability

The most popular WordPress backup plugin gave unauthenticated attackers full admin access. Wordfence blocked 8,172 exploit attempts in 24 hours. The plugin supply chain strikes again.

CVSS 9.8 WordPress 2026