Small Business SEO904-664-6144Take a Test Drive
100K AI WebsiteSEOLeave WordPressGuidesBlogReviewsFAQsAboutContact904-664-6144Take a Test Drive

WordPress · Security · Small Business

LMAO! WordPress Got Hacked Again. Is Your Site One of Them?

A plugin shipped with a backdoor in it last week. Backdoor is Wordfence's word, not mine. Two more went out with no fix at all and hand a stranger your admin login. 246 new holes in seven days.

A man lifting a steel door stencilled WORDPRESS that has been torn off its hinges while its padlock is still locked through the hasp, in a wet alley beside an open doorway full of server gear

Three versions of a WordPress plugin went out with a backdoor built into them last week. Backdoor is Wordfence's word for it, not mine. It's the classification sitting on the entry.

That isn't a hole somebody left open by accident. Somebody built a way into your site, put it in an update, and shipped it to everybody who installed it.

Two more went out with no fix at all. Both rated 9.8 out of 10. Both hand a stranger an administrator account on your site with no password, no login and nothing typed in. There's still nothing to update to.

So yeah. LMAO. 246 new holes in seven days and one of them was a door somebody installed on purpose.

Your site might be fine. It might not be. Two minutes tells you which.

One of last week's 246 wasn't a mistake. It was a door, and it shipped in an update.

The receipt

0

WordPress vulnerabilities disclosed in one week. Across 174 plugins and 5 themes. 121 researchers found them.

Wordfence Intelligence Weekly WordPress Vulnerability Report, August 24 to August 30, 2026. See the live threat intel →
0

rated critical, meaning 9.1 or higher out of 10. Another 73 rated high.

0

still sitting there with no fix at all. The other 234 got patched.

Wordfence figures are theirs, linked to the source. Read that week's full report.

TL;DR

Wordfence logged 246 new WordPress vulnerabilities between August 24 and August 30, 2026, across 174 plugins and 5 themes. One of them, Newspapers X 1.0.46 through 1.0.48, is classified as a backdoor: a way in that shipped inside the update. Two more are rated 9.8 and still have no fix, and both let a stranger become an administrator with no password. 18 were critical in total, 73 more were high, and 12 of the 246 are still open today. Go read your plugin list.

3 Things to Remember

1
A plugin shipped a backdoor. If you took that update, somebody else's door went on your site.
2
Two 9.8s are still open with no fix. Both hand out admin with no password.
3
246 in seven days across 174 plugins. That's a normal week, not a bad one.
A new list every Wednesday. This was one week of it.

You Clicked Update. That Was the Attack.

A man crouched on a wet loading bay beside a crate stencilled UPDATE 1.0.47 whose side panel door, marked BACKDOOR, stands open with red light behind it

You saw the update badge and you clicked it, because that's the responsible thing to do. On this one, clicking it is what put the attacker inside.

Newspapers X, versions 1.0.46 through 1.0.48. Rated 9.8. The entry doesn't say vulnerability. It says backdoor.

Not a mistake in the code. Not a corner somebody missed. Somebody put a way in and shipped it to whoever installed the update.

You'd never see it either. It looks like a plugin. It updates like a plugin. It sits in the same list as your contact form and your cache tool, and the list doesn't tell you which one is which.

This isn't new. Somebody bought 30 WordPress plugins last month and did the same thing on purpose. Buy the plugin, get the install base, ship one bad update.

That's the thing about the plugin list. Every row on it is a company you've never met holding a key to your site, and they can sell those keys tomorrow.

Mistake: you think updating is the safe move and skipping is the risky one.

Fix: go read who publishes each plugin on your site, not just what it does.

Payoff: you find out how many strangers you hand a key to every month.

Two of Them Are Still Open Right Now.

A man holding one of two empty drawers stencilled FIX pulled from a parts cabinet stencilled 2, beside a card reading NO UPDATE TO RUN

Two plugins from last week are still wide open today, and there's nothing you can do about either one except take them off the site.

One is a custom post type plugin, anything up to 2.0.63. One is a login plugin, anything up to 1.0.2. Both rated 9.8. Both hand a stranger an administrator account without a password. 234 of the 246 got patched. These two did not.

There's no update to run. No button. Being on top of your updates does nothing here, because there's nothing to install.

Your only move is to know they're on your site and pull them out. Which means reading a list you have probably never opened.

Updating your plugins is good advice and it's also not enough, which is a thing I've written about before.

They Didn't Need Your Password. They Got Admin.

A heavy steel vault door standing in its own free standing frame bolted to a concrete slab in a warehouse, stencilled PASSWORD with the numeral 18 above it, yellow tape across the face reading NOT IN USE, a small green keypad beside the wheel handle, a man and a hen standing on the wet floor to the left.

Read the 18 critical entries and one word keeps coming back. Unauthenticated. The attacker never logs in. No password, no account, no click from you, and on several of them what they get at the end is your administrator account.

Administrator is not a technical detail. It's your pages, your customer list, your payment settings and the login you use. There's no part of the site an admin can't reach.

Critical means 9.1 or higher out of 10. Last week had 18 of those, plus 73 more rated high. Five of the 18 go straight to running their own code on your server.

So your strong password did nothing, because nobody went near the login. That door wasn't the one being used.

Look at where the critical ones landed. A site management tool on more than a million sites. A page builder tool on 500,000. A translation plugin on 400,000. A donation plugin churches and nonprofits run on 100,000. An upload add on for the most common contact form on WordPress.

Add up just the plugins that carry a public install count and had a critical hole last week and you're over 2.3 million sites. In seven days. That's install counts published by the WordPress plugin directory, 2026, for the ones that publish them at all. Plenty don't.

I wrote about what one bad plugin does to your whole site over here.

Twelve of them are still lying there. There's nothing to install.

I Checked the Security Plugin. It Was the Hole.

A steel cabinet stencilled SECURITY PLUGIN hanging open on one hinge while its padlock stays locked around nothing

I went down the 18 looking for the one that would land hardest on a small shop. It was the security plugin.

A security and backup plugin carried a 9.8 last week. The entry calls it unauthenticated site takeover. Takeover means the whole site, and unauthenticated means they didn't need anything from you to do it.

That family covers a malware scanner and firewall on 200,000 sites, a backup and staging tool on 80,000, and a remote management tool on 30,000. Same code underneath. Same hole.

It's fixed now. The makers shipped it and I'm not going to beat them up over one bug, because I've read enough of these to know how the sausage gets made.

But sit with the shape of it for a second. You added that plugin because you were worried about exactly this. It's outside code. So it's another door. Being a security plugin doesn't make it not a door.

That's the trap. You can't patch your way out of a pile by adding to the pile.

Mistake: you install a security plugin and cross security off the list.

Fix: count it as one more piece of code you didn't write and can't read.

Payoff: you start counting doors instead of counting features. That number is usually about 15.

Eighteen names. One of them might be on your screen.

Here Are the Eighteen Names.

I put the whole critical eighteen below, with what the report says about each one. It's the list, not a summary of the list.

Names, ratings, which ones are fixed, which are still open, and how many sites run each. Open your own plugin screen next to it and tick what you see.

0

plugins carried a critical hole in seven days, and 2.3 million sites run the ones with a published install count. Every name is below. (Wordfence Intelligence, August 24 to August 30, 2026, and the WordPress plugin directory, 2026)

Last week's list

The Critical Eighteen

These are the 18 plugins that carried a critical hole between August 24 and August 30. Open your own plugin list and tick the ones you see. Nothing gets scanned and nothing gets sent anywhere.

Do it yourself

Hand your plugin list to AI and ask what last week did to it

Copy your plugin list out of your WordPress dashboard and paste it in. Takes about 30 seconds.

Try it · Check my plugins against last week
I run a [TYPE OF BUSINESS] in [YOUR CITY] and my website is on
WordPress.

Here is every plugin on my site, one per line, with the version number
next to it where I have it:
[PASTE YOUR PLUGIN LIST]

Do five things.

1. Sort these into groups: backup, security, forms, uploads, page
   builder, booking, payments, and everything else. Tell me which
   groups touch the most on my site.
2. For each plugin, tell me if you know of a security advisory against
   it in the last month. If you do not know, say you do not know. Do
   not guess and do not invent a CVE number.
3. Tell me which ones look abandoned, meaning no update in over a year.
4. Tell me which ones a custom built site would not need at all.
5. Give me the one plugin to deal with first, and one sentence on why.

Rules: write at a 5th grade reading level. Short sentences. No hype.
If you are not sure about something, say you are not sure.

Fill the [brackets] in the chat box before you send.

You get: a ranked list of which plugins on your own site are the ones to look at first, and which ones you never needed.

I Read This List Every Week. That's Why I Left.

I've read this report every week for years, and I used to read it as a to do list. Which of mine is on here. What do I have to go patch tonight.

That's what finally did it. Not one bad week. The reading. So I moved 1,387 of my own posts off WordPress and rebuilt clean.

25 years. 10k+ sites built. 281 of them JSX AI interactive. The page you're reading has no plugin list, so last week's backdoor shipped to nobody here. That's not me being sharper than you. There's just nothing here for it to land in.

Here's how that move actually went, rankings and all.

When None of This Is Your Problem.

I'll give you the other side, because you've been sold to enough.

234 of the 246 got patched, most inside a few days. The people who write these plugins mostly move fast and mostly do good work, and Wordfence pays researchers real money to turn this stuff up. That's a working system and I won't pretend it isn't.

The backdoor is one plugin out of 174 that week. If you don't run it, that part isn't your story. Run three plugins from three real companies, update inside a week, and most of that list is noise to you. Go run your business.

Same if somebody real watches your site. A person who reads the alerts and patches on a Tuesday. That person is worth every dollar you pay them.

And none of this was a freak week. Wordfence publishes a list like it every Wednesday, and six weeks ago I walked through one that came in at 270. If that's the argument you want, that post is the one to read. This one is about the four entries on last week's list that could take the whole site.

Here's who the careful person isn't. Most shops have a plugin list nobody has opened in two years and a guy who answers sometimes. Next Wednesday there'll be another list and the same plugins will be sitting there.

There's No Plugin List on This Page.

There's no plugin list on this page. No update screen, no version numbers, nothing for last week's backdoor to have shipped into.

I'm not telling you your site is on fire. I'm telling you a backdoor shipped in an update last week, two takeovers are still open, and you heard it from me instead of from anybody who was supposed to tell you.

That's the part I'd fix. Not the plugin. The setup where a stranger's release notes decide how your week goes, and the bill you pay for the privilege.

If you want to see your own site with no plugin list at all, take a test drive. I'll put your site on my code and you look at it before you spend a dime.

Take a Test Drive →

Want a human first? Email me at seo@smallbusiness-seo.com and send me your plugin list. I'll tell you which ones I'd cut. No cost, no pitch.

FAQ

Did WordPress get hacked again?

Yes. A plugin called Newspapers X shipped three versions with a backdoor built in, and Wordfence classifies it exactly that way. Two more plugins are rated 9.8 and still unfixed, and both hand a stranger an administrator account with no password.

Is my WordPress site one of them?

Open your plugin list and read the version numbers. If you ran Newspapers X 1.0.46 through 1.0.48, a backdoor shipped to you in an update and you want somebody to look at the site. For the other 17 critical ones, an old version means the door is open.

What was the WordPress plugin backdoor last week?

Newspapers X, versions 1.0.46 through 1.0.48, rated 9.8. Backdoor is the classification on the Wordfence entry. It wasn't a coding mistake. Somebody built a way in and shipped it inside a normal plugin update to everybody who installed it.

Which WordPress plugins still have no fix?

12 of last week's 246, and two of those are rated 9.8. ACPT Premium up to 2.0.63 and SmilePass Selfie Login up to 1.0.2. Both let a stranger become an administrator with no login. There's nothing to update to, so take them off the site.

How many WordPress vulnerabilities were reported last week?

246, between August 24 and August 30, 2026. They landed in 174 plugins and 5 themes, and 121 researchers filed them. 18 were rated critical and another 73 were rated high. Wordfence publishes a count like this every week.

Do security plugins protect me from this?

Partly, and they're also part of the pile. One of last week's critical holes was an unauthenticated site takeover inside a security and backup plugin family running on more than 300,000 sites. A security plugin is still outside code you didn't write.

How do I check my own plugin list in two minutes?

Log into WordPress and click Plugins. That list is every company holding a key to your site. Read the version number next to each one, then check it against the 18 critical ones above. Start with anything that has no fix.

Is there a way off the weekly vulnerability list?

Yes, by not having a plugin layer. When the features are built into the site there's no plugin list, so a backdoor in somebody else's update has nothing on your site to ship into.

Read These In This Order

  1. 270 WordPress Vulnerabilities Last Week
  2. WordPress Just Screwed 5 Million People. Are You One of Them?
  3. Someone Bought 30 WordPress Plugins and Hacked Every Site Running Them.
  4. Hundreds of Holes With No Fix Coming
  5. Stop Being Held Hostage by Your Plugins
  6. The WordPress Bill Nobody Adds Up
  7. Leave WordPress

Check Out My Last 3 Builds

Real sites, built with this exact system. Tap any one and poke around.

Two Men and a Truck
Moving company
See it live →
Learn Euphoria
Education & courses
See it live →
SoFresh
Fast-casual food
See it live →
Small Business SEO · Jacksonville, FL · Go Balls Out.

Get 2 Must-Read Resources Every Week

No spam. No pitch. Just 2 Must Read Resources a Week.

By downloading, you agree to our Privacy Policy. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.