Security
Insights on securing WordPress sites against vulnerabilities.
14 stories
WordPress 7.0.4 fixes an RCE vulnerability – check your core update now
WordPress 7.0.4 is a security release fixing an Author+ RCE issue on sites using Imagick and Ghostscript. Update and verify now. […] Read…
BdThemes supply chain compromise: WordPress admins should check affected sites now
Wordfence reports a BdThemes supply chain compromise using poisoned JSON in wp-admin. Check affected plugins, admin users, webshells, and…
WordPress 7.0.3 fixes security issues – update your site now
WordPress 7.0.3 is a security release with fixes for XSS, SSRF, privilege escalation, and information disclosure issues. […] Read More… f…
Wordfence Bug Bounty Report: April 2026 Highlights Vulnerabilities and Rewards
In April 2026, the Wordfence Bug Bounty Program reported 1288 vulnerabilities, emphasizing community-driven security efforts in WordPress…
Protect The Shire may delay urgent WordPress plugin security fixes
Patchstack says WordPress.org’s update delay helps with supply-chain risk, but may slow urgent plugin security fixes. […] Read More… from…
Critical WordPress Security Vulnerability: Immediate Update Required!
A critical vulnerability in WordPress allows unauthenticated attackers to create admin accounts. Site owners must update immediately to a…
Critical Vulnerability in Advanced Responsive Video Embedder – Immediate Action Required
A critical vulnerability in the Advanced Responsive Video Embedder plugin allows unauthenticated access to WordPress sites. Immediate uni…
Wordfence’s AI Project PRISM Identifies 202 Vulnerabilities in 30 Days
Wordfence’s AI project PRISM has autonomously discovered 202 vulnerabilities in just 30 days, enhancing WordPress security amid rising th…
Urgent WordPress 7.0.2 Security Update and Upcoming 7.1 Beta Release
WordPress 7.0.2 is a critical security update that site owners must implement immediately, while 7.1 beta 3 is set to release soon. […] R…
Critical WordPress Security Update: Immediate Action Required to Address wp2shell Vulnerabilities
WordPress has released critical security updates addressing vulnerabilities that allow unauthenticated remote code execution. Update now …
WordPress Core RCE Attacks Started 90 Minutes After the Patch – Check Updates and Logs Now
Patchstack saw WordPress core RCE exploitation attempts 90 minutes after the patch. Update now and check for compromise signs. […] Read M…
Legacy PHP in WordPress is a security risk – check your hosting before it checks you
WP Tavern’s interview with Milan Petrovic explains why old PHP versions are a real WordPress security and performance risk. […] Read More…
OptinMonster, TrustPulse and PushEngage CDN attack: WordPress admins should check for rogue users
Tampered CDN scripts for OptinMonster, TrustPulse and PushEngage could create rogue WordPress admin accounts. Here is what to check. […] …
WowShipping Pro 1.0.6 malware warning: WooCommerce stores may need cleanup after updating
Patchstack says a trojanized WowShipping Pro 1.0.6 copy installed hidden malware. Updating helps, but cleanup may still be needed. […] Re…