• News/
  • https://www.bleepingcomputer.com/news/security/the-four-wordpress-flaws-hackers-targeted-the-most-in-q1-2025/

The 4 WordPress flaws hackers targeted the most in Q1 2025

BleepingComputer
·
Bill Toulas
·
Published Mar 27, 2025
·
Updated

A new report sheds light on the most targeted WordPress plugin vulnerabilities hackers used in the first quarter of 2025 to compromise sites. All four flaws are vulnerabilities discovered and fixed in 2024 but remain unpatched in many cases, giving hackers the opportunity to execute arbitrary code or exfiltrate sensitive data. Among the four flaws, which are all critical severity, are two that are reported as actively exploited for the first time. According to a new Patchstack report, the four flaws that received the most exploitation attempts are: It is important to note that exploitation attempts don't always lead to successful compromises, as many of these probes are blocked before they do any harm or the exploits are ineffective in achieving the desired outcome. However, given that not all websites are protected by Patchstack or other effective website security products, the chances of hackers finding more suitable conditions for exploitation across the WordPress landscape are significant. Website administrators and owners should apply the latest available security updates on all WordPress add-ons and themes and deactivate those they don't necessarily need. Also, make sure that dormant accounts are deleted and strong passwords and multi-factor authentication protect administrator accounts. Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them. WordPress security plugin WP Ghost vuln...

Read full article

Affected Software

3 affected components
WP Ghost
Apache Tomcat
WordPress plugin

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the WordPress vulnerabilities that were most targeted by hackers in the first quarter of 2025.

2

What security implications are discussed?

The article highlights the risk of unpatched vulnerabilities in WordPress plugins that hackers are exploiting to compromise websites.

3

What products or software are affected?

The article specifically mentions WordPress plugins as the main software affected by the targeted vulnerabilities.

4

When were the vulnerabilities discovered and fixed?

The vulnerabilities were discovered and patched in 2024 but remain unpatched on many sites.

5

Why is it important for WordPress site owners to address these vulnerabilities?

It is crucial for WordPress site owners to address these vulnerabilities to prevent potential hacking and protect their sites from compromise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203