{"id":76586,"date":"2025-10-15T01:00:00","date_gmt":"2025-10-15T08:00:00","guid":{"rendered":"https:\/\/dhblog.dream.press\/blog\/?p=76586"},"modified":"2026-08-25T20:55:05","modified_gmt":"2026-08-26T03:55:05","slug":"top-cves","status":"publish","type":"post","link":"https:\/\/www.dreamhost.com\/blog\/top-cves\/","title":{"rendered":"Scary Hosting Tales: 10 Security Risks Still Haunting Sites in 2026"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>TL;DR:<\/strong> The scariest website vulnerabilities of the past year didn\u2019t come from WordPress core. They came from plugins, themes, and unpatched server software like OpenSSH and PHP on Ubuntu. Patchstack\u2019s vulnerability database logged 10,230 plugin vulnerabilities and 1,009 theme vulnerabilities for 2025, against just 2 in WordPress core. Every one of those bugs is still dangerous in 2026 on a site that hasn\u2019t patched.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Below are <strong>10 notable vulnerabilities disclosed in 2025<\/strong>, including how each one worked and what site owners and developers should take away. The bottom line: consistent updates, careful role management, and attention to security advisories are what keep your hosting stories from turning into horror stories.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">It always starts the same way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A late-night ping. A panicked client. A WordPress site that was working fine yesterday, but is now coughing up error logs and redirecting visitors to a sketchy pharmacy domain. In your mind, all you can hear is the screeching violins from a horror soundtrack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most scary hosting tales aren\u2019t caused by the ghosts and monsters of spooky season fame. They come from vulnerabilities left unpatched just a little too long. The real danger lives in the <strong>plugins, themes, and server software that power your site<\/strong> \u2014 WordPress core itself recorded just two published vulnerabilities in all of 2025, per Patchstack\u2019s database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s why we\u2019re here, flashlight in hand, to walk you through 10 vulnerabilities that sent shivers down developers\u2019 spines. These aren\u2019t cautionary tales meant to scare you away from the web. They\u2019re field notes from the front lines: lessons you can use to keep your hosting stories from turning into <em>horror<\/em> stories.<\/p>\n\n\n\n<h2 id=\"h-what-does-the-2026-threat-landscape-look-like-for-wordpress-plugins-and-ubuntu-packages\" class=\"wp-block-heading\">What do the threats to WordPress plugins and Ubuntu packages look like in 2026?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/blog\/intro-to-wordpress-plugins\/\">Plugins<\/a> and <a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/blog\/how-to-find-wp-themes\/\">themes<\/a> accounted for almost all recorded WordPress vulnerabilities in Patchstack\u2019s 2025 statistics. For 2025, <a target=\"_blank\" href=\"https:\/\/patchstack.com\/database\/statistics\/wordpress\/2025\">Patchstack\u2019s WordPress vulnerability statistics<\/a> list 10,230 plugin vulnerabilities (91% of the year\u2019s total) and 1,009 theme vulnerabilities (9%), and exactly 2 in WordPress core (figures as published on Patchstack\u2019s statistics page, checked August 2026). Only one of those core vulnerabilities had been identified by mid-2025, when the chart below was drawn, per Patchstack\u2019s mid-year report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Volume is only half the story. Patchstack\u2019s <a target=\"_blank\" href=\"https:\/\/patchstack.com\/whitepaper\/2025-mid-year-vulnerability-report\/\">2025 mid-year vulnerability report<\/a> counted 6,700 new vulnerabilities across plugins, themes, and core in the first six months of 2025, classified 41% of them as exploitable in real-life attacks, and found that 57.6% could be exploited by a complete outsider with no login or stolen credentials at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The server layer needs the same attention. Canonical publishes <a target=\"_blank\" href=\"https:\/\/ubuntu.com\/security\/notices\">Ubuntu Security Notices (USNs)<\/a> continuously for <a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/blog\/check-ubuntu-version\/\">supported releases<\/a>, and many of them cover software your hosting stack depends on. In 2025 alone, those notices included an OpenSSH directive that failed to disable forwarding as documented and a PHP flaw that could crash the interpreter (both covered below).<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"1659\" height=\"948\" data-src=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531.webp\" alt=\"Bar chart of 2025 WordPress vulnerabilities per Patchstack: 10,230 in plugins, 1,009 in themes, and just 2 in WordPress core\" class=\"wp-image-87220 lazyload\" data-srcset=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531.webp 1659w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-300x171.webp 300w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-1024x585.webp 1024w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-768x439.webp 768w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-1536x878.webp 1536w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-600x343.webp 600w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-1200x686.webp 1200w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-730x417.webp 730w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-1460x834.webp 1460w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-784x448.webp 784w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-1568x896.webp 1568w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2026\/08\/wordpress-2025-vulnerabilities-plugins-themes-core-dreamops-2d0fe6cb40db6e12390fc531-877x501.webp 877w\" data-sizes=\"(max-width: 1659px) 100vw, 1659px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1659px; --smush-placeholder-aspect-ratio: 1659\/948;\" \/><figcaption class=\"wp-element-caption\">Where 2025 WordPress vulnerabilities lived: plugins (10,230), themes (1,009), and WordPress core (2). Source: Patchstack WordPress vulnerability statistics, checked August 2026.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">So what should site owners take away from those numbers? Three things:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>You can\u2019t rely on core for protection \u2013 <\/strong>Nearly all of the recorded 2025 WordPress vulnerabilities were in third-party code. Keeping WordPress itself updated is table stakes, not a security strategy.<\/li>\n\n\n\n<li><strong>Exploitability is high \u2013 <\/strong>Patchstack classified 41% of the vulnerabilities found in the first half of 2025 as exploitable in real-life attacks, and most required no authentication at all.<\/li>\n\n\n\n<li><strong>OS vulnerabilities compound the risk \u2013 <\/strong>Even if every plugin is patched, outdated Ubuntu packages widen the attack surface underneath your site.<\/li>\n<\/ol>\n\n\n\n<h2 id=\"h2_the-10-scary-tales-of-2025-what-went-wrong-and-what-can-we-learn-from-it\" class=\"wp-block-heading\">The 10 scary tales: what went wrong (and what can we learn from it)?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Below are real WordPress and Ubuntu vulnerabilities disclosed in 2025. They aren\u2019t ancient history: they can still expose sites that run affected versions and meet the relevant exploit conditions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Post SMTP<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>Versions 3.2.0 and earlier of the Post SMTP plugin contained an <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-24000\" target=\"_blank\">authentication bypass<\/a> (CVE-2025-24000). <a target=\"_blank\" href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/post-smtp\/vulnerability\/wordpress-post-smtp-3-2-0-privilege-escalation-vulnerability\">Patchstack scored it 8.8<\/a>, flagged it as high priority, and warned that flaws in this class let a malicious actor perform actions reserved for higher-privileged users \u2014 potentially all the way to admin access. The fix shipped in version 3.3.0.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Post SMTP\u2019s WordPress.org listing highlights detailed email logs as a feature. Combined with Patchstack\u2019s high-priority rating and the potential for higher-privileged actions, that makes strict authorization around the plugin essential.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Post SMTP is also popular: its WordPress.org listing counts over 400,000 website owners using it. Bugs in widely installed plugins attract attackers fast.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Being logged in is not the same as being authorized. Privilege checks must match the sensitivity of the endpoint they guard.<\/p>\n\n\n<div class=\"single__related-article\">\n\t<span>Related Article<\/span>\n\t<div class=\"single__related-article__wrap\">\n\t\t<div class=\"single__related-article__title\">\n\t\t\tKeep Your Comms Private: Your Best Secure Email Options in 2026\n\t\t<\/div>\n\t\t<a href=\"https:\/\/www.dreamhost.com\/blog\/secure-email\/\" class=\"btn btn--sm btn--brand\" target=\"_blank\" rel=\"noopener\">\n\t\t\tRead More\n\t\t<\/a>\n\t<\/div>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">2. Essential Addons for Elementor<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>Versions 6.0.14 and earlier of Essential Addons for Elementor had a <a target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-24752\">reflected cross-site scripting (XSS) vulnerability<\/a> (CVE-2025-24752): input wasn\u2019t properly neutralized before being embedded into page output, so a crafted URL could run a script in a visitor\u2019s browser.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This plugin serves <strong>more than 2 million active users<\/strong>, per its WordPress.org listing, so a flaw like this has enormous potential reach. Reflected XSS can enable phishing, credential theft, or defacement if an attacker tricks a user into clicking a crafted link.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Popular plugin + simple input vector = widespread risk. A large install base magnifies even \u201cjust XSS\u201d vulnerabilities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. WPForms Lite<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>WPForms versions up to and including 1.9.5 were <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-3794\" target=\"_blank\">vulnerable to stored cross-site scripting<\/a> via the <strong><code>start_timestamp<\/code><\/strong> parameter (CVE-2025-3794). Authenticated users with <strong>Contributor role or above<\/strong> could inject scripts that persist and run whenever anyone views the compromised page.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because Contributor access is often granted (and then forgotten) on sites with multiple authors, the risk was real. Stored XSS doesn\u2019t end when a victim closes the tab: the payload lives in your database until someone finds and removes it, and it can steal cookies or session data from every user who loads the injected page.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Stored XSS via lower-privileged roles is dangerous. Audit who has accounts on your site \u2014 even \u201ctrusted\u201d users widen the attack surface.<\/p>\n\n\n\n<div class=\"article-newsletter article-newsletter--gradient\">\n\n\n<h2>Get Content Delivered Straight to Your Inbox<\/h2><p>Subscribe now to receive all the latest updates, delivered directly to your inbox.<\/p><form class=\"nwsl-form\" id=\"newsletter_block_\" novalidate><div class=\"messages\"><\/div><div class=\"form-group\"><label for=\"input_newsletter_block_\"><input type=\"email\"name=\"email\"id=\"input_newsletter_block_\"placeholder=\"Enter your email address\"novalidatedisabled=\"disabled\"\/><\/label><button type=\"submit\"class=\"btn btn--brand\"disabled=\"disabled\"><span>Sign Me Up!<\/span><svg width=\"21\" height=\"14\" viewBox=\"0 0 21 14\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n<path d=\"M13.8523 0.42524L12.9323 1.34521C12.7095 1.56801 12.7132 1.9304 12.9404 2.14865L16.7241 5.7823H0.5625C0.251859 5.7823 0 6.03416 0 6.3448V7.6573C0 7.96794 0.251859 8.2198 0.5625 8.2198H16.7241L12.9405 11.8535C12.7132 12.0717 12.7095 12.4341 12.9323 12.6569L13.8523 13.5769C14.072 13.7965 14.4281 13.7965 14.6478 13.5769L20.8259 7.39879C21.0456 7.17913 21.0456 6.82298 20.8259 6.60327L14.6477 0.42524C14.4281 0.205584 14.0719 0.205584 13.8523 0.42524Z\" fill=\"white\"\/>\n<\/svg>\n<\/button><\/div><\/form><\/div>\n\n\n<h3 class=\"wp-block-heading\">4. GiveWP<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>GiveWP versions 3.19.3 and earlier <a target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-22777\">contained a PHP object injection vulnerability<\/a> (CVE-2025-22777) caused by deserialization of untrusted data: crafted input could inject PHP objects into the application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GiveWP is one of the most popular donation plugins, with more than 100,000 active installs per its WordPress.org listing. A plugin that handles donor data and payment flows is exactly where you don\u2019t want attacker-controlled objects landing. For a nonprofit, that\u2019s a trust disaster on top of a technical one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Complex plugins like donation platforms handle sensitive data, which makes them prime targets. Always patch them quickly.<\/p>\n\n\n<div class=\"single__related-article\">\n\t<span>Related Article<\/span>\n\t<div class=\"single__related-article__wrap\">\n\t\t<div class=\"single__related-article__title\">\n\t\t\tTo Plugin, Or Not To Plugin? That Is The Question\n\t\t<\/div>\n\t\t<a href=\"https:\/\/www.dreamhost.com\/blog\/wordpress-plugins-good-or-bad\/\" class=\"btn btn--sm btn--brand\" target=\"_blank\" rel=\"noopener\">\n\t\t\tRead More\n\t\t<\/a>\n\t<\/div>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">5. AI Engine Plugin<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>AI Engine versions 2.8.0 through 2.8.3 were <a target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-5071\">missing a capability check<\/a> on the function guarding the plugin\u2019s MCP module (CVE-2025-5071). MCP, the Model Context Protocol, is the interface that lets AI agents take actions on your site. With that check missing, any subscriber-level user could access the MCP and run commands like <code>wp_create_user<\/code>, <code>wp_update_user<\/code>, and <code>wp_update_option<\/code> \u2014 a straight path to privilege escalation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Privilege escalation vulnerabilities are among the most devastating because they subvert the trust model: anyone who could register a basic account could hand themselves the keys. And AI Engine connects WordPress to OpenAI, Anthropic, Google, and other AI providers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>New plugin categories bring old vulnerability classes. Treat AI integrations with the same suspicion as any other code with admin-level power, and make role audits part of every monthly maintenance routine.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1600\" height=\"1056\" data-src=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x.webp\" alt=\"Flowchart showing privilege escalation: subscriber gains basic access, exploits vulnerability\" class=\"wp-image-76589 lazyload\" data-srcset=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x.webp 1600w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-300x198.webp 300w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-1024x676.webp 1024w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-768x507.webp 768w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-1536x1014.webp 1536w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-600x396.webp 600w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-1200x792.webp 1200w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-730x482.webp 730w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-1460x964.webp 1460w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-784x517.webp 784w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-1568x1035.webp 1568w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/02-How-Privilege-Escalation-Attacks-Work_1x-877x579.webp 877w\" data-sizes=\"(max-width: 1600px) 100vw, 1600px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1600px; --smush-placeholder-aspect-ratio: 1600\/1056;\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">6. B Blocks Plugin<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>bBlocks (recorded as \u201cB Blocks\u201d in the CVE), a Gutenberg block plugin, shipped a registration function with <a target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-8059\">missing authorization and improper input validation<\/a> (CVE-2025-8059). In versions 2.0.6 and earlier, unauthenticated visitors could create a new account and assign it the administrator role. No login, no existing foothold, nothing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Any attacker who knew the endpoint could spin up a brand-new admin account. From there, they could install backdoors, export the database, or inject SEO spam links across the site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Unauthenticated privilege escalation is as bad as it gets. Check your user list regularly, even when you think everything is patched: a surprise administrator is the loudest alarm there is.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. Motors Theme<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>The <em>Motors<\/em> theme, a commercial theme sold for car dealership sites, didn\u2019t properly validate a user\u2019s identity before updating their password. In versions 5.6.67 and earlier, <a target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-4322\">unauthenticated attackers could change any user\u2019s password<\/a>, including an administrator\u2019s, and log straight into the account (CVE-2025-4322).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Attackers didn\u2019t need to be clever here. They could simply walk in through the front door with a password they set themselves, on a site advertising inventory, payments, and customer leads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Themes can be as dangerous as plugins. If you bought a theme years ago and haven\u2019t updated it, that theme may be your weakest link.<\/p>\n\n\n<div class=\"single__related-article\">\n\t<span>Related Article<\/span>\n\t<div class=\"single__related-article__wrap\">\n\t\t<div class=\"single__related-article__title\">\n\t\t\t22 WordPress Block Themes Perfect for Full Site Editing [2026]\n\t\t<\/div>\n\t\t<a href=\"https:\/\/www.dreamhost.com\/blog\/wordpress-block-themes\/\" class=\"btn btn--sm btn--brand\" target=\"_blank\" rel=\"noopener\">\n\t\t\tRead More\n\t\t<\/a>\n\t<\/div>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">8. Database for Contact Form 7 \/ WPForms \/ Elementor Forms<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>The Database for Contact Form 7, WPForms, and Elementor Forms plugin, an add-on that stores form submissions, allowed <a target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-7384\">unauthenticated PHP object injection<\/a> in versions 1.4.3 and earlier (CVE-2025-7384). Untrusted input was deserialized in the plugin\u2019s <code>get_lead_detail<\/code> function, and a \u201cPOP chain\u201d in Contact Form 7 (a plugin likely installed alongside it) let attackers turn the object injection into arbitrary file deletion. Delete <code>wp-config.php<\/code>, and the result is denial of service \u2014 or remote code execution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because this plugin extends three of the most popular form builders, the exposure multiplied across exactly the kind of sites agencies manage in bulk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Small \u201chelper\u201d add-ons deserve the same patch urgency as the big plugins they extend. An attacker doesn\u2019t care which plugin opened the door.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1600\" height=\"1373\" data-src=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x.webp\" alt=\"Diagram of website vulnerability layers: plugins, themes\" class=\"wp-image-76590 lazyload\" data-srcset=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x.webp 1600w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-300x257.webp 300w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-1024x879.webp 1024w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-768x659.webp 768w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-1536x1318.webp 1536w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-600x515.webp 600w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-1200x1030.webp 1200w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-730x626.webp 730w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-1460x1253.webp 1460w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-784x673.webp 784w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-1568x1346.webp 1568w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/03-Your-Website_-A-Stack-of-Potential-Vulnerabilities_1x-877x753.webp 877w\" data-sizes=\"(max-width: 1600px) 100vw, 1600px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1600px; --smush-placeholder-aspect-ratio: 1600\/1373;\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">9. OpenSSH on Ubuntu<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>Canonical patched several OpenSSH flaws on Ubuntu in 2025. <a target=\"_blank\" href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7270-1\">USN-7270-1<\/a> (February 2025) fixed two: with the non-default <code>VerifyHostKeyDNS<\/code> option enabled, an attacker could impersonate a server by bypassing the identity check (CVE-2025-26465), and a flaw in the transport-level ping facility could be used to drain resources on clients and servers, a denial-of-service risk affecting Ubuntu 24.04 LTS and 24.10 (CVE-2025-26466). Two months later, <a target=\"_blank\" href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7457-1\">USN-7457-1<\/a> fixed a bug where the <code>DisableForwarding<\/code> directive failed to disable X11 and agent forwarding, contrary to its own documentation (CVE-2025-32728).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenSSH is one of the most foundational packages on an Ubuntu server, and a directive that doesn\u2019t do what its name promises is its own kind of horror: your config file says you\u2019re safe when you\u2019re not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Don\u2019t assume critical packages are invulnerable. Even mature software like OpenSSH needs constant patching, plus a config review after every advisory that touches it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">10. PHP on Ubuntu<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What happened: <\/strong>A <a target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-6491\">vulnerability in PHP\u2019s SOAP extension<\/a> meant an oversized XML namespace prefix (over 2 GB) could trigger a null pointer dereference and crash PHP, affecting the availability of the server (CVE-2025-6491). It affected PHP 8.1 before 8.1.33, 8.2 before 8.2.29, 8.3 before 8.3.23, and 8.4 before 8.4.10. Canonical shipped the patch to Ubuntu 25.04, 24.04 LTS, and 22.04 LTS in <a target=\"_blank\" href=\"https:\/\/ubuntu.com\/security\/notices\/USN-7648-1\">USN-7648-1<\/a> (July 2025).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Plenty of WordPress plugins and themes depend on PHP\u2019s SOAP and XML functions for integrations like payment gateways, CRMs, and marketing automation. A crash at the interpreter level takes the site down no matter how clean your WordPress code is.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Key takeaway: <\/strong>Server software flaws are just as threatening as WordPress bugs. If your PHP process dies, your site dies with it.<\/p>\n\n\n\n<h2 id=\"h2_what-these-tales-teach-us\" class=\"wp-block-heading\">What these tales teach us<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Taken together, these 10 cases tell a consistent story: the scariest vulnerabilities of the past year weren\u2019t exotic zero-days in WordPress core. They were the everyday cracks in the walls: outdated plugins, neglected themes, and unpatched server software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three lessons stand out:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Plugins and themes dominate the disclosed vulnerability count. <\/strong>They accounted for nearly all of 2025\u2019s disclosed WordPress vulnerabilities, and their large install bases make them prime targets.<\/li>\n\n\n\n<li><strong>Privilege escalation is everywhere. <\/strong>From Post SMTP to AI Engine to bBlocks, attackers are hunting for shortcuts to admin rights. Once they have those, everything else is secondary.<\/li>\n\n\n\n<li><strong>OS-level bugs matter as much as application bugs. <\/strong>The OpenSSH and PHP flaws remind us that keeping Ubuntu packages current is just as important as updating WordPress itself.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"1600\" height=\"1009\" data-src=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x.webp\" alt=\"Security maintenance schedule showing weekly plugin\/theme updates, monthly role reviews\" class=\"wp-image-76591 lazyload\" data-srcset=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x.webp 1600w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-300x189.webp 300w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-1024x646.webp 1024w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-768x484.webp 768w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-1536x969.webp 1536w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-600x378.webp 600w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-1200x757.webp 1200w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-730x460.webp 730w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-1460x921.webp 1460w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-784x494.webp 784w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-1568x989.webp 1568w, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/04-Your-Defense-Strategy_-Stay-Ahead-of-the-Threats_1x-877x553.webp 877w\" data-sizes=\"(max-width: 1600px) 100vw, 1600px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1600px; --smush-placeholder-aspect-ratio: 1600\/1009;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The takeaway isn\u2019t to fear your software stack. Respect it and take care of it: every plugin, theme, or server package you install widens the surface area for attack, and the difference between a scary hosting tale and a routine patch cycle is how quickly you spot and close those gaps. For a practical checklist, start with our <a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/blog\/secure-your-wordpress-website\/\">20 WordPress security tips<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security doesn\u2019t have to be terrifying. With consistent updates, careful role management, and attention to advisories, you can keep the monsters at bay.<\/p>\n\n\n\n<h2 id=\"h-wordpress-security-faqs\" class=\"wp-block-heading\">WordPress and hosting security FAQs<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Where do most WordPress vulnerabilities come from?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Plugins and themes. Patchstack\u2019s WordPress vulnerability statistics for 2025 attribute 91% of disclosed vulnerabilities to plugins and 9% to themes, with only 2 recorded in WordPress core. The safest posture is fewer, better-maintained plugins, updated promptly.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Can a firewall or WAF protect my site from plugin vulnerabilities?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Partly. A web application firewall (WAF) filters requests before they reach your site and can block known exploit patterns, which buys you time between a disclosure and your next update. It can\u2019t fix vulnerable code, though, so treat a WAF as a layer in front of updates, never a replacement for them. Our <a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/blog\/web-application-firewall\/\">guide to web application firewalls<\/a> explains how to set one up.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What security does DreamHost include with hosting?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Every DreamHost plan ships with free Let\u2019s Encrypt SSL certificates, automated backups, DDoS protection and mitigation, 24\/7 server and network monitoring, and web application and network firewalls, with no additional setup or fees. The full list is on our <a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/features\/security\/\">website security page<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is DreamShield?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/products\/dreamshield\/\">DreamShield<\/a> is DreamHost\u2019s paid security add-on. It automatically scans your website daily, detects and blocks malware, and alerts you by email and in the DreamHost panel when something is wrong. Each DreamShield plan covers a single domain or subdomain, and it protects websites fully hosted on a DreamHost hosting plan.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do I still need to update plugins on managed hosting?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Yes. Managed hosting responsibilities vary, so check whether your plan updates third-party plugins and themes. If it doesn\u2019t, you or your maintenance provider must update them. Most of the vulnerabilities in this article lived in plugin code that only an update could fix. Here\u2019s how to tell whether your <a target=\"_blank\" href=\"https:\/\/www.dreamhost.com\/blog\/wordpress-hosting-security\/\">WordPress hosting has good security<\/a>.<\/p>\n\n\n\n\n<div class=\"article-cta-shared article-cta-small article-cta--product\">\n\t<div class=\"tr-img-wrap-outer jsLoading\"><img decoding=\"async\" class=\"js-img-lazy \" src=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/themes\/blog2018\/assets\/img\/lazy-loading-transparent.webp\" data-srcset=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2024\/03\/product-cta-wordpress-hosting-877x586.webp 1x, https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2024\/03\/product-cta-wordpress-hosting.webp 2x\"  alt=\"website management by DreamHost\" \/><\/div>\n\n\t<a href='https:\/\/www.dreamhost.com\/wordpress\/managed\/' class='link-top' target='_blank' rel='noopener noreferrer'>\n\t\t<span>WordPress Hosting<\/span>\n\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 384 512\" width=\"15\"><path d=\"M342.6 233.4c12.5 12.5 12.5 32.8 0 45.3l-192 192c-12.5 12.5-32.8 12.5-45.3 0s-12.5-32.8 0-45.3L274.7 256 105.4 86.6c-12.5-12.5-12.5-32.8 0-45.3s32.8-12.5 45.3 0l192 192z\"\/><\/svg>\n\t<\/a>\n\n\t<div class=\"content-btm\">\n\t\t<h2 class=\"h2--md\">\n\t\t\tUnbeatable WordPress Hosting\n\t\t<\/h2>\n\t\t<p class=\"p--md\">\n\t\t\tReliable, lightning-fast hosting solutions specifically optimized for WordPress.\n\t\t<\/p>\n\n\t\t        <a\n            href=\"https:\/\/www.dreamhost.com\/wordpress\/managed\/\"\n                        class=\"btn btn--white-outline btn--sm btn--round\"\n                                    target=\"_blank\"\n            rel=\"noopener noreferrer\"\n            >\n                            See More                    <\/a>\n\n\t<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Stay ahead of hackers. These are the top website security vulnerabilities of 2025 \u2014 and what small businesses can do to stay safe.<\/p>\n","protected":false},"author":1036,"featured_media":76587,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_opengraph-title":"10 WordPress & Ubuntu Security Risks Haunting Sites in 2026","_yoast_wpseo_opengraph-description":"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.","_yoast_wpseo_twitter-title":"10 WordPress & Ubuntu Security Risks Haunting Sites in 2026","_yoast_wpseo_twitter-description":"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.","toc_headlines":"[[\"h-what-does-the-2026-threat-landscape-look-like-for-wordpress-plugins-and-ubuntu-packages\",\"What do the threats to WordPress plugins and Ubuntu packages look like in 2026?\"],[\"h2_the-10-scary-tales-of-2025-what-went-wrong-and-what-can-we-learn-from-it\",\"The 10 scary tales: what went wrong (and what can we learn from it)?\"],[\"h2_what-these-tales-teach-us\",\"What these tales teach us\"],[\"h-wordpress-security-faqs\",\"WordPress and hosting security FAQs\"]]","hide_toc":false,"show_updated_at":"1","footnotes":""},"categories":[10025],"tags":[],"class_list":["post-76586","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-talk"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>10 WordPress &amp; Ubuntu Security Risks Haunting Sites in 2026<\/title>\n<meta name=\"description\" content=\"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.dreamhost.com\/blog\/top-cves\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"10 WordPress &amp; Ubuntu Security Risks Haunting Sites in 2026\" \/>\n<meta property=\"og:description\" content=\"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.dreamhost.com\/blog\/top-cves\/\" \/>\n<meta property=\"og:site_name\" content=\"DreamHost Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/DreamHost\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-15T08:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-26T03:55:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/1220x628_OGIMAGE_Scary-Hosting-Tales_-10-Security-Risks-Haunting-2025_1x.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Luke Odom\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"10 WordPress &amp; Ubuntu Security Risks Haunting Sites in 2026\" \/>\n<meta name=\"twitter:description\" content=\"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.\" \/>\n<meta name=\"twitter:creator\" content=\"@dreamhost\" \/>\n<meta name=\"twitter:site\" content=\"@dreamhost\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Luke Odom\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"10 WordPress & Ubuntu Security Risks Haunting Sites in 2026","description":"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.dreamhost.com\/blog\/top-cves\/","og_locale":"en_US","og_type":"article","og_title":"10 WordPress & Ubuntu Security Risks Haunting Sites in 2026","og_description":"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.","og_url":"https:\/\/www.dreamhost.com\/blog\/top-cves\/","og_site_name":"DreamHost Blog","article_publisher":"https:\/\/www.facebook.com\/DreamHost\/","article_published_time":"2025-10-15T08:00:00+00:00","article_modified_time":"2026-08-26T03:55:05+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/1220x628_OGIMAGE_Scary-Hosting-Tales_-10-Security-Risks-Haunting-2025_1x.webp","type":"image\/webp"}],"author":"Luke Odom","twitter_card":"summary_large_image","twitter_title":"10 WordPress & Ubuntu Security Risks Haunting Sites in 2026","twitter_description":"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.","twitter_creator":"@dreamhost","twitter_site":"@dreamhost","twitter_misc":{"Written by":"Luke Odom","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/#article","isPartOf":{"@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/"},"author":{"name":"Luke Odom","@id":"https:\/\/www.dreamhost.com\/blog\/#\/schema\/person\/0d2c5145a8428841b58d0d07f8f97f2e"},"headline":"Scary Hosting Tales: 10 Security Risks Still Haunting Sites in 2026","datePublished":"2025-10-15T08:00:00+00:00","dateModified":"2026-08-26T03:55:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/"},"wordCount":2349,"publisher":{"@id":"https:\/\/www.dreamhost.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/1460x1095-BLOG-HERO-Scary-Hosting-Tales_-10-Security-Risks-Haunting-2025_1x.webp","articleSection":["Tech Talk"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/","url":"https:\/\/www.dreamhost.com\/blog\/top-cves\/","name":"10 WordPress & Ubuntu Security Risks Haunting Sites in 2026","isPartOf":{"@id":"https:\/\/www.dreamhost.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/#primaryimage"},"image":{"@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/1460x1095-BLOG-HERO-Scary-Hosting-Tales_-10-Security-Risks-Haunting-2025_1x.webp","datePublished":"2025-10-15T08:00:00+00:00","dateModified":"2026-08-26T03:55:05+00:00","description":"The biggest share of 2025 WordPress vulnerabilities appeared in plugins and themes. See 10 notable WordPress and Ubuntu risks and how to stay patched.","breadcrumb":{"@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.dreamhost.com\/blog\/top-cves\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/#primaryimage","url":"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/1460x1095-BLOG-HERO-Scary-Hosting-Tales_-10-Security-Risks-Haunting-2025_1x.webp","contentUrl":"https:\/\/www.dreamhost.com\/blog\/wp-content\/uploads\/2025\/10\/1460x1095-BLOG-HERO-Scary-Hosting-Tales_-10-Security-Risks-Haunting-2025_1x.webp","width":1460,"height":1095,"caption":"Scary Hosting Tales: 10 Security Risks Haunting 2025"},{"@type":"BreadcrumbList","@id":"https:\/\/www.dreamhost.com\/blog\/top-cves\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.dreamhost.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Scary Hosting Tales: 10 Security Risks Still Haunting Sites in 2026"}]},{"@type":"WebSite","@id":"https:\/\/www.dreamhost.com\/blog\/#website","url":"https:\/\/www.dreamhost.com\/blog\/","name":"DreamHost Blog","description":"","publisher":{"@id":"https:\/\/www.dreamhost.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.dreamhost.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.dreamhost.com\/blog\/#organization","name":"DreamHost","url":"https:\/\/www.dreamhost.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dreamhost.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/dhblog.dream.press\/blog\/wp-content\/uploads\/2019\/01\/dh_logo-blue-2.png","contentUrl":"https:\/\/dhblog.dream.press\/blog\/wp-content\/uploads\/2019\/01\/dh_logo-blue-2.png","width":1200,"height":168,"caption":"DreamHost"},"image":{"@id":"https:\/\/www.dreamhost.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/DreamHost\/","https:\/\/x.com\/dreamhost","https:\/\/www.instagram.com\/dreamhost\/","https:\/\/www.linkedin.com\/company\/dreamhost\/","https:\/\/www.youtube.com\/user\/dreamhostusa"]},{"@type":"Person","@id":"https:\/\/www.dreamhost.com\/blog\/#\/schema\/person\/0d2c5145a8428841b58d0d07f8f97f2e","name":"Luke Odom","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c56e64d8cecd561c4e2cb65fc16717105fc6d29044bbd8c78cbd4619a31e7098?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c56e64d8cecd561c4e2cb65fc16717105fc6d29044bbd8c78cbd4619a31e7098?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c56e64d8cecd561c4e2cb65fc16717105fc6d29044bbd8c78cbd4619a31e7098?s=96&d=mm&r=g","caption":"Luke Odom"},"description":"Luke is the Director of IT Operations. He is responsible for the teams that keep operations running smoothly... In his free time, he enjoys reading fantasy\/sci-fi and hanging out with his wife and 4 kids. Connect with Luke on LinkedIn: https:\/\/www.linkedin.com\/in\/luke-odom-039986a\/","url":"https:\/\/www.dreamhost.com\/blog\/author\/dreamhostluke\/"}]}},"lang":"en","translations":{"en":76586,"it":76689,"nl":76682,"es":76603,"fr":76679,"pt":76684,"de":76707,"pl":76710,"ru":76715,"uk":76725},"pll_sync_post":{},"_links":{"self":[{"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/posts\/76586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/users\/1036"}],"version-history":[{"count":2,"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/posts\/76586\/revisions"}],"predecessor-version":[{"id":90231,"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/posts\/76586\/revisions\/90231"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/media\/76587"}],"wp:attachment":[{"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/media?parent=76586"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/categories?post=76586"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dreamhost.com\/blog\/wp-json\/wp\/v2\/tags?post=76586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}