A new report sheds light on the most targeted WordPress plugin vulnerabilities hackers used in the first quarter of 2025 to compromise sites. All four flaws are vulnerabilities discovered and fixed in 2024 but remain unpatched in many cases, giving hackers the opportunity to execute arbitrary code or exfiltrate sensitive data. Among the four flaws, which are all critical severity, are two that are reported as actively exploited for the first time. According to a new Patchstack report, the four flaws that received the most exploitation attempts are: It is important to note that exploitation attempts don't always lead to successful compromises, as many of these probes are blocked before they do any harm or the exploits are ineffective in achieving the desired outcome. However, given that not all websites are protected by Patchstack or other effective website security products, the chances of hackers finding more suitable conditions for exploitation across the WordPress landscape are significant. Website administrators and owners should apply the latest available security updates on all WordPress add-ons and themes and deactivate those they don't necessarily need. Also, make sure that dormant accounts are deleted and strong passwords and multi-factor authentication protect administrator accounts. Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them. WordPress security plugin WP Ghost vuln...
The 4 WordPress flaws hackers targeted the most in Q1 2025
BleepingComputer
·Bill Toulas
·Published Mar 27, 2025
·Updated
Affected Software
3 affected components
WP Ghost
Apache Tomcat
WordPress plugin
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the WordPress vulnerabilities that were most targeted by hackers in the first quarter of 2025.
2
What security implications are discussed?
The article highlights the risk of unpatched vulnerabilities in WordPress plugins that hackers are exploiting to compromise websites.
3
What products or software are affected?
The article specifically mentions WordPress plugins as the main software affected by the targeted vulnerabilities.
4
When were the vulnerabilities discovered and fixed?
The vulnerabilities were discovered and patched in 2024 but remain unpatched on many sites.
5
Why is it important for WordPress site owners to address these vulnerabilities?
It is crucial for WordPress site owners to address these vulnerabilities to prevent potential hacking and protect their sites from compromise.