PROTOTYPE Feeds read 28.09.2026. WordPress counts use versions from the 08–09.09 scan. PrestaShop and Magento stay [n] until version matching runs.
HackedIndex Check your site
Vulnerability radar · feeds read 28.09.2026

The holes attackers use on WordPress and PrestaShop, and how many sites still have them

Every hour we pull new vulnerabilities from public feeds and match them to what each site in the index shows publicly. You see counts. Each owner sees only their own site.

EXPLOITED NOW CVE-2026-87902 · WordPress Core

A file inclusion hole in WordPress itself lets attackers run code. No login needed.

CISA confirmed attacks in the wild and added it to its catalogue of exploited vulnerabilities. Mass exploitation of holes like this is what fills the index.

ADDED TO CISA KEV25.09.2026
US AGENCIES MUST PATCH BY28.09.2026
FIXED IN7.1.2older lines patched back to 4.7.37
INDEX SITES ON AFFECTED VERSIONS576 of 581WordPress versions seen 08–09.09, before the fix
Exploited now · CMS software

Confirmed attacks in the wild

From the CISA catalogue of exploited vulnerabilities, filtered to shop and site software, since July 2026.
Added Software Vulnerability What an attacker gets Index sites
25.09.2026 WordPress Core CVE-2026-87902 Runs code through file inclusion, no login 576
24.09.2026 Adobe Commerce / Magento CVE-2026-71362 Elevated access to sensitive data, no user action [n]
08.09.2026 Adobe Commerce / Magento CVE-2026-75650 Runs code through template injection [n]
21.07.2026 WordPress Core
CVE-2026-60137+ CVE-2026-63030
SQL injection chain that runs code on default installs 32
Index sites: infected sites whose public WordPress version in the 08–09.09.2026 scan fell in the affected range. 581 of the 923 show a version. 32 were still below the July fix seven weeks after it came out.

PrestaShop core

Official PrestaShop security advisories
OPEN FEED
5 advisories in one release18.08.2026
HIGH 8.2Server-side requests through image URLs in CSV import
HIGH 8.0Formula injection in CSV exports
HIGH 7.3Client IP spoofed through a request header
MED 6.5SQL injection through back-office list filters
MED 4.3Notifications endpoint exposes customer data
Fixed in 8.2.8 and 9.1.5 · index sites below: [n]
Stored XSS in the customer service viewCVE-2026-44212 · 04.05.2026 · fixed in 8.2.6 / 9.1.1
9.3
Stored XSS through template variablesCVE-2026-33673 · 23.03.2026 · fixed in 8.2.5 / 9.1.0
7.6

PrestaShop modules

Friends of Presta security advisories
OPEN FEED
UPS shipping module: logs readable by anyoneCVE-2026-39079 · upsshipping · 21.05.2026
[n] sites
Advanced Popup Creator: SQL injectionCVE-2025-69633 · advancedpopupcreator · 16.02.2026
[n] sites
PrestaShop Checkout: customer account takeover by emailCVE-2025-61922 · ps_checkout · 23.10.2025
[n] sites
AP Page Builder: reads files outside the shopCVE-2024-6648 · below 4.0.0 · 22.05.2025
[n] sites
Monetico payment module: SQL injectionCVE-2023-45256 · MoneticoPaiement · 10.06.2025
[n] sites
212 of the 230 advisories in this feed are about modules. Only 13 are about the PrestaShop core.

WordPress plugins and themes

The biggest source of WordPress break-ins. Plugin feeds plus what our own scan ties to infected sites.
WPMU DEV Dashboard: single sign-on bypass to the admin panelCVE-2026-76581 · CVSS 9.8 · fixed in 5.0.2 · active outbreak in our scan
Planned: the plugin and theme feed (Wordfence Intelligence), connected with an API key from [month]. Until then this list shows only what our own scan ties to infected sites.
How matching works

From a new hole to a warning in hours

01 · Fingerprint

What the site shows anyone

CMS version from the generator tag and asset links. Plugins and modules from their public paths. Their versions from readme files and asset links. Plain GET requests, nothing more.

02 · Match

Against every feed, every hour

A version inside an affected range makes a site likely affected, never proven: hosts sometimes patch without changing the number. Exploited-now holes jump the queue.

03 · Warn

The owner, then the counts

Monitored sites get an alert the same day. Every reachable site that is likely affected gets one free notice when a hole is exploited now. The public page only moves a number.

We never publish which sites are vulnerable.
A named list of unpatched sites is a shopping list for attackers. The public sees counts per vulnerability. Each owner sees only their own site, after verifying it.
Sources we match against

Four feeds connected today, three more planned

CISA KEVHoles confirmed exploited in the wildOPEN NVDEvery published CVE, with severityOPEN PrestaShop advisoriesPrestaShop core, with fixed versionsOPEN Friends of PrestaPrestaShop modules and themesOPEN Wordfence IntelligenceWordPress core, plugins and themesPLANNED · API KEY WPScanWordPress, second opinion on versionsPLANNED · LICENCE PatchstackWordPress, early disclosuresPLANNED · API HackedIndex scanWhich holes actually fill the indexOUR DATA