Insights on securing WordPress sites against vulnerabilities.
12 stories
Looks in titles, excerpts, and topics.
WordPress 7.0.4 is a security release fixing an Author+ RCE issue on sites using Imagick and Ghostscript. Update and verify now.
Wordfence reports a BdThemes supply chain compromise using poisoned JSON in wp-admin. Check affected plugins, admin users, webshells, and…
WordPress 7.0.3 is a security release with fixes for XSS, SSRF, privilege escalation, and information disclosure issues.
Patchstack says WordPress.org’s update delay helps with supply-chain risk, but may slow urgent plugin security fixes.
A critical vulnerability in WordPress allows unauthenticated attackers to create admin accounts. Site owners must update immediately to…
A critical vulnerability in the Advanced Responsive Video Embedder plugin allows unauthenticated access to WordPress sites. Immediate…
Wordfence’s AI project PRISM has autonomously discovered 202 vulnerabilities in just 30 days, enhancing WordPress security amid rising…
WordPress has released critical security updates addressing vulnerabilities that allow unauthenticated remote code execution. Update now to…
WordPress 7.0.2 is a critical security update that site owners must implement immediately, while 7.1 beta 3 is set to release soon.
Patchstack saw WordPress core RCE exploitation attempts 90 minutes after the patch. Update now and check for compromise signs.
Tampered CDN scripts for OptinMonster, TrustPulse and PushEngage could create rogue WordPress admin accounts. Here is what to check.
Patchstack says a trojanized WowShipping Pro 1.0.6 copy installed hidden malware. Updating helps, but cleanup may still be needed.