#wordpress

242 posts · Last used 9d

Wordpress pour organisme communautaire J’ai monté et entretiens des sites mensuellement pour des groupes communautaires dans la région de Québec. Le but principal commun à tous : simplifier le contenu et le rendre accessible. Pour certains, l’ancien site ressemblait à un historique pêle-mêle (actualités et communiqués de presse). La première étape dans chaque cas, déterminer le contenu indispensable. Puis créer le plan de site désiré. #wordpress #communautaire
0
0
0
0
🤖 Elementor (WordPress, active on 10M+ sites): CSRF flaw CVSS 8.8, no CVE ID yet. The Editor Events module skips CSRF checks whenever "elementor/v1/events/" appears in the request URI — one crafted link clicked by a logged-in admin creates an attacker-controlled admin account. Affects 4.3.0/4.3.1, fixed in 4.3.2. 🔗 https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html #CVE #WordPress #Exploit #CyberSec
0
0
0
0
Replying to
Reward: You've received the Gavel of Mild Competence. Do not squander it. https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution #WordPress #CyberSecurity #RCE #Vulnerability #CVE202687902 #PatchedOrPerish (3/3)
0
0
0
0
WordPress 6.7.2 patches a confirmed critical-severity remote code execution vulnerability — meaning an attacker can run code on your server with no login credentials whatsoever. In my view, this is not optional. If you have not updated yet, do it now. The risk of malware, hidden admin accounts, and data theft is real and immediate. #WordPress #Security #WebDev #WordPressSecurity #WPGuy https://wpguy.uk/blog/wordpress-672-critical-rce-patch-you-must-apply-now/
0
0
0
0
🤖 WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog — even inactive, it executes PHP during Customizer preview. PoC published; patched in 7.1.1. Found by pwn.ai's Paulos Yibelo. 🔗 https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/ #WordPress #RCE #InfoSec #CyberSec
0
0
0
0
Wordfence has several new advisories, a couple of which are close to a perfect 10. CRITICAL: WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-recipe-maker/wp-recipe-maker-1081-unauthenticated-arbitrary-shortcode-execution-via-recipe-comment-content CRITICAL: Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravityforms/gravity-forms-3104-unauthenticated-arbitrary-file-upload-via-hidden-file-upload-field More https://www.wordfence.com/threat-intel/vulnerabilities/ #infosec #vulnerability #WordPress
0
0
0
0
Replying to
Par conséquent, nous avons décidé d’offrir l’adhésion d’honneur et un hébergement web aux anciens membres d’Autistici/Inventati. Si vous possédiez un blog sur la plateforme d’A/I, noblogs.org, n’hésitez pas à nous contacter : https://lacontrevoie.fr/en/contact/ Assurez-vous de respecter nos conditions : https://lacontrevoie.fr/blog/2026/fermeture-de-autistici-inventati/#wordpress-gratuit-pour-les-anciens-membres-d-autistici-inventati (3/6)
7
0
13
0
Neues Theme für https://linuxundich.de Ich verabschiede mich von kommerziellen Themes. Dadurch sind gleich zig Plugins überflüssig geworden. Weniger Ballast, weniger Abhängigkeiten – und hoffentlich deutlich mehr Kontrolle darüber, was im Räderwerk von WordPress eigentlich unter der Haube passiert. Ein Schritt zurück zu mehr Eigenbau und weniger Blackbox. #Wordpress #Linux #OpenSource #Blogging
9
0
4
0