{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Wordfence Security News","title":"WordPress Plugin Supply Chain Attacks, Ivanti CVSS 10 & phpBB Hijacks | Wordfence Security News #12","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/8d38efd5\"></iframe>","width":"100%","height":180,"duration":931,"description":"WordPress Supply Chain Attacks, Ivanti Root Flaw, and phpBB Account Takeovers\nThis week in Wordfence Security News (Week of June 15, 2026):ShapedPlugin's paid pro plugins were backdoored via the vendor's update system, stealing passwords and 2FA secretsOptinMonster, TrustPulse, and PushEngage served a tampered CDN script that targeted logged-in adminsOracle PeopleSoft zero-day exploited by ShinyHunters hit 300+ systems, 68% in higher educationIvanti Sentry CVSS 10 OS command injection flaw gives attackers root, added to CISA KEVLangflow AI app builder path traversal flaw now actively exploited against unpatched instancesphpBB authentication bypass lets attackers hijack any account with just a username and one requestTimestamps:\n0:00 Introduction0:42 ShapedPlugin Multiple Plugins Supply Chain Compromised5:11 OptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDN7:48 Oracle PeopleSoft Zero-Day Exploited by ShinyHunters10:17 Ivanti Sentry CVSS 10 RCE Added to KEV11:53 Langflow RCE Actively Exploited Against Exposed AI App Builders13:46 phpBB Authentication Bypass Lets Attackers Hijack Accounts\nStory Links:ShapedPlugin Multiple Plugins Supply Chain CompromisedOptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDNOracle PeopleSoft Zero-Day Exploited by ShinyHuntersIvanti Sentry CVSS 10 RCE Added to KEVLangflow RCE Actively Exploited Against Exposed AI App BuildersphpBB Authentication Bypass Lets Attackers Hijack AccountsStay informed and secure: get the latest Wordfence Security News on the Wordfence blog or subscribe to the WordPress Security Newsletter.","thumbnail_url":"https://img.transistorcdn.com/tNZ1BCLBa7hdisGHRggcQKe1fS0BRjNwLU5euMPMXfE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjZm/M2NiNzczNWQ4MDdh/OTYyMTg5MDQ5ODk3/ODI5ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}