WordPress · Security · Small Business
LMAO! WordPress Got Hacked Again. Is Your Site One of Them?
A plugin shipped with a backdoor in it last week. Backdoor is Wordfence's word, not mine. Two more went out with no fix at all and hand a stranger your admin login. 246 new holes in seven days.

Three versions of a WordPress plugin went out with a backdoor built into them last week. Backdoor is Wordfence's word for it, not mine. It's the classification sitting on the entry.
That isn't a hole somebody left open by accident. Somebody built a way into your site, put it in an update, and shipped it to everybody who installed it.
Two more went out with no fix at all. Both rated 9.8 out of 10. Both hand a stranger an administrator account on your site with no password, no login and nothing typed in. There's still nothing to update to.
So yeah. LMAO. 246 new holes in seven days and one of them was a door somebody installed on purpose.
Your site might be fine. It might not be. Two minutes tells you which.
One of last week's 246 wasn't a mistake. It was a door, and it shipped in an update.
TL;DR
Wordfence logged 246 new WordPress vulnerabilities between August 24 and August 30, 2026, across 174 plugins and 5 themes. One of them, Newspapers X 1.0.46 through 1.0.48, is classified as a backdoor: a way in that shipped inside the update. Two more are rated 9.8 and still have no fix, and both let a stranger become an administrator with no password. 18 were critical in total, 73 more were high, and 12 of the 246 are still open today. Go read your plugin list.
3 Things to Remember
You Clicked Update. That Was the Attack.

You saw the update badge and you clicked it, because that's the responsible thing to do. On this one, clicking it is what put the attacker inside.
Newspapers X, versions 1.0.46 through 1.0.48. Rated 9.8. The entry doesn't say vulnerability. It says backdoor.
Not a mistake in the code. Not a corner somebody missed. Somebody put a way in and shipped it to whoever installed the update.
You'd never see it either. It looks like a plugin. It updates like a plugin. It sits in the same list as your contact form and your cache tool, and the list doesn't tell you which one is which.
This isn't new. Somebody bought 30 WordPress plugins last month and did the same thing on purpose. Buy the plugin, get the install base, ship one bad update.
That's the thing about the plugin list. Every row on it is a company you've never met holding a key to your site, and they can sell those keys tomorrow.
Mistake: you think updating is the safe move and skipping is the risky one.
Fix: go read who publishes each plugin on your site, not just what it does.
Payoff: you find out how many strangers you hand a key to every month.
Two of Them Are Still Open Right Now.

Two plugins from last week are still wide open today, and there's nothing you can do about either one except take them off the site.
One is a custom post type plugin, anything up to 2.0.63. One is a login plugin, anything up to 1.0.2. Both rated 9.8. Both hand a stranger an administrator account without a password. 234 of the 246 got patched. These two did not.
There's no update to run. No button. Being on top of your updates does nothing here, because there's nothing to install.
Your only move is to know they're on your site and pull them out. Which means reading a list you have probably never opened.
Updating your plugins is good advice and it's also not enough, which is a thing I've written about before.
They Didn't Need Your Password. They Got Admin.

Read the 18 critical entries and one word keeps coming back. Unauthenticated. The attacker never logs in. No password, no account, no click from you, and on several of them what they get at the end is your administrator account.
Administrator is not a technical detail. It's your pages, your customer list, your payment settings and the login you use. There's no part of the site an admin can't reach.
Critical means 9.1 or higher out of 10. Last week had 18 of those, plus 73 more rated high. Five of the 18 go straight to running their own code on your server.
So your strong password did nothing, because nobody went near the login. That door wasn't the one being used.
Look at where the critical ones landed. A site management tool on more than a million sites. A page builder tool on 500,000. A translation plugin on 400,000. A donation plugin churches and nonprofits run on 100,000. An upload add on for the most common contact form on WordPress.
Add up just the plugins that carry a public install count and had a critical hole last week and you're over 2.3 million sites. In seven days. That's install counts published by the WordPress plugin directory, 2026, for the ones that publish them at all. Plenty don't.
I wrote about what one bad plugin does to your whole site over here.
I Checked the Security Plugin. It Was the Hole.

I went down the 18 looking for the one that would land hardest on a small shop. It was the security plugin.
A security and backup plugin carried a 9.8 last week. The entry calls it unauthenticated site takeover. Takeover means the whole site, and unauthenticated means they didn't need anything from you to do it.
That family covers a malware scanner and firewall on 200,000 sites, a backup and staging tool on 80,000, and a remote management tool on 30,000. Same code underneath. Same hole.
It's fixed now. The makers shipped it and I'm not going to beat them up over one bug, because I've read enough of these to know how the sausage gets made.
But sit with the shape of it for a second. You added that plugin because you were worried about exactly this. It's outside code. So it's another door. Being a security plugin doesn't make it not a door.
That's the trap. You can't patch your way out of a pile by adding to the pile.
Mistake: you install a security plugin and cross security off the list.
Fix: count it as one more piece of code you didn't write and can't read.
Payoff: you start counting doors instead of counting features. That number is usually about 15.
Here Are the Eighteen Names.
I put the whole critical eighteen below, with what the report says about each one. It's the list, not a summary of the list.
Names, ratings, which ones are fixed, which are still open, and how many sites run each. Open your own plugin screen next to it and tick what you see.
plugins carried a critical hole in seven days, and 2.3 million sites run the ones with a published install count. Every name is below. (Wordfence Intelligence, August 24 to August 30, 2026, and the WordPress plugin directory, 2026)
I Read This List Every Week. That's Why I Left.
I've read this report every week for years, and I used to read it as a to do list. Which of mine is on here. What do I have to go patch tonight.
That's what finally did it. Not one bad week. The reading. So I moved 1,387 of my own posts off WordPress and rebuilt clean.
25 years. 10k+ sites built. 281 of them JSX AI interactive. The page you're reading has no plugin list, so last week's backdoor shipped to nobody here. That's not me being sharper than you. There's just nothing here for it to land in.
Here's how that move actually went, rankings and all.
When None of This Is Your Problem.
I'll give you the other side, because you've been sold to enough.
234 of the 246 got patched, most inside a few days. The people who write these plugins mostly move fast and mostly do good work, and Wordfence pays researchers real money to turn this stuff up. That's a working system and I won't pretend it isn't.
The backdoor is one plugin out of 174 that week. If you don't run it, that part isn't your story. Run three plugins from three real companies, update inside a week, and most of that list is noise to you. Go run your business.
Same if somebody real watches your site. A person who reads the alerts and patches on a Tuesday. That person is worth every dollar you pay them.
And none of this was a freak week. Wordfence publishes a list like it every Wednesday, and six weeks ago I walked through one that came in at 270. If that's the argument you want, that post is the one to read. This one is about the four entries on last week's list that could take the whole site.
Here's who the careful person isn't. Most shops have a plugin list nobody has opened in two years and a guy who answers sometimes. Next Wednesday there'll be another list and the same plugins will be sitting there.
There's No Plugin List on This Page.
There's no plugin list on this page. No update screen, no version numbers, nothing for last week's backdoor to have shipped into.
I'm not telling you your site is on fire. I'm telling you a backdoor shipped in an update last week, two takeovers are still open, and you heard it from me instead of from anybody who was supposed to tell you.
That's the part I'd fix. Not the plugin. The setup where a stranger's release notes decide how your week goes, and the bill you pay for the privilege.
If you want to see your own site with no plugin list at all, take a test drive. I'll put your site on my code and you look at it before you spend a dime.
Want a human first? Email me at seo@smallbusiness-seo.com and send me your plugin list. I'll tell you which ones I'd cut. No cost, no pitch.
FAQ
Yes. A plugin called Newspapers X shipped three versions with a backdoor built in, and Wordfence classifies it exactly that way. Two more plugins are rated 9.8 and still unfixed, and both hand a stranger an administrator account with no password.
Open your plugin list and read the version numbers. If you ran Newspapers X 1.0.46 through 1.0.48, a backdoor shipped to you in an update and you want somebody to look at the site. For the other 17 critical ones, an old version means the door is open.
Newspapers X, versions 1.0.46 through 1.0.48, rated 9.8. Backdoor is the classification on the Wordfence entry. It wasn't a coding mistake. Somebody built a way in and shipped it inside a normal plugin update to everybody who installed it.
12 of last week's 246, and two of those are rated 9.8. ACPT Premium up to 2.0.63 and SmilePass Selfie Login up to 1.0.2. Both let a stranger become an administrator with no login. There's nothing to update to, so take them off the site.
246, between August 24 and August 30, 2026. They landed in 174 plugins and 5 themes, and 121 researchers filed them. 18 were rated critical and another 73 were rated high. Wordfence publishes a count like this every week.
Partly, and they're also part of the pile. One of last week's critical holes was an unauthenticated site takeover inside a security and backup plugin family running on more than 300,000 sites. A security plugin is still outside code you didn't write.
Log into WordPress and click Plugins. That list is every company holding a key to your site. Read the version number next to each one, then check it against the 18 critical ones above. Start with anything that has no fix.
Yes, by not having a plugin layer. When the features are built into the site there's no plugin list, so a backdoor in somebody else's update has nothing on your site to ship into.
Read These In This Order
- 270 WordPress Vulnerabilities Last Week
- WordPress Just Screwed 5 Million People. Are You One of Them?
- Someone Bought 30 WordPress Plugins and Hacked Every Site Running Them.
- Hundreds of Holes With No Fix Coming
- Stop Being Held Hostage by Your Plugins
- The WordPress Bill Nobody Adds Up
- Leave WordPress
Check Out My Last 3 Builds
Real sites, built with this exact system. Tap any one and poke around.