Third party plugin risk, not clever malware, is why a critical WooCommerce flaw patched in February is still being exploited in September.
WordPress security
-
-
A practical checklist for the WordPress Click2Shell flaw: whether you’re affected, how serious it really was, and the five things to check this week.
-
WordPress’s automated plugin review caught a real backdoor before it shipped. That is a genuine win, but it does nothing about the vulnerable plugins already on your site.
-
News
Your Contact Form Could Be the Weak Point: A Practical Guide to the Super Forms and Elementor Pro Flaws
Two WordPress plugins have taken over 440,000 exploit attempts between them. Here’s a plain-English breakdown of what happened and the checklist to run on your own site.
-
Five WordPress plugins and themes were hit by critical, no-login-required flaws this week. Here is a plain checklist for checking your own site, whether you run any of them or …
-
A critical Forminator plugin vulnerability lets attackers upload malicious files without logging in. Here is a quick checklist to find out if your site is exposed.
-
An exposed criminal server reveals exactly which plugin flaws powered a mass WordPress webshell attack. Use this checklist to check your own sites now.
-
Three ShapedPlugin Pro plugins served malware via official updates for three weeks. Updating the plugin is not enough — here is what site owners need to do.
-
The Gravity SMTP vulnerability (CVE-2026-4020) is being exploited at mass scale. But the real issue is structural: email plugins holding API keys create a risk that one permission bug can …
-
A CDN-level supply chain attack backdoored over 1.2 million WordPress sites via OptinMonster, TrustPulse and PushEngage. Here is exactly what to check and how to clean up.