#ActuallyAutistic #WordPress developer specialising in forensic troubleshooting, #security and #performance. 20 years' experience. 🏴
The WordPress Guy
@wpguyuk@infosec.exchange
infosec.exchange
A critical WordPress RCE vulnerability, wp2shell, was disclosed on 17 July 2026. It chains a REST API route confusion flaw with an SQL injection in WP_Query — no login required, no plugin involved. If my site were unpatched, an attacker could take full control. Check your WordPress version now.
#WordPress #Security #WordPressSecurity #WebSecurity #RCE
https://wpguy.uk/blog/is-your-wordpress-site-exposed-to-the-wp2shell-remote-code-execution-flaw/
thecybersecguru
@thecybersecguru@infosec.exchange
infosec.exchange
🚨 CRITICAL: WordPress Core "wp2shell" RCE
A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations.
⚠️ No plugins.
⚠️ No themes.
⚠️ No authentication required.
Tracked as:
🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE)
🔴 CVE-2026-60137 (Facilitated SQL Injection)
Affected versions
• WordPress 6.9.0–6.9.4
• WordPress 7.0.0–7.0.1
✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations.
🔗 Full technical analysis:
https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/
#WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
The WordPress Guy
@wpguyuk@infosec.exchange
#ActuallyAutistic #WordPress developer specialising in forensic troubleshooting, #security and #performance. 20 years' experience. 🏴
infosec.exchange
250+ WordPress plugin vulnerabilities are disclosed every week in 2026 — that is not a spike, it is the baseline. What concerns me most is that 43% require no login to exploit. Automated scanners find vulnerable sites before most owners even know a patch exists. This is the environment I work in daily, and it demands a serious approach to hardening.
#WordPress #WebSecurity #WordPressSecurity #PluginSecurity
https://wpguy.uk/blog/wordpress-plugin-vulnerabilities-are-rising-what-business-owners-must-know/
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
Censys research finds 70% of WordPress sites run end-of-life PHP. Outdated plugins and defaults leave millions of sites wide open to attack.
#WordPress #OutdatedPHP #WordPressSecurity #EndOfLife #MRGreen
https://securityonline.info/wordpress-outdated-php-security-risk/?utm_source=mastodon&utm_medium=jetpack_social
The WordPress Guy
@wpguyuk@infosec.exchange
#ActuallyAutistic #WordPress developer specialising in forensic troubleshooting, #security and #performance. 20 years' experience. 🏴
infosec.exchange
Three plugins I keep a close eye on — WPForms (6M+ sites), WPvivid, and Smart Slider 3 — all had vulnerabilities publicly disclosed in June 2026. Patches are available for all three. If you have not updated recently, your site is likely exposed. Worth checking your versions today.
#WordPress #WordPressSecurity #WPForms #PluginUpdates #WebsiteSecurity
https://wpguy.uk/blog/wordpress-plugin-vulnerabilities-in-june-2026-what-site-owners-must-know/
Good Websites
@goodwebsitesnz@mastodon.world
Hello. We're Good Websites. A nice little web design company based in Tauranga (New Zealand) building WordPress and beautiful handcrafted One Page Websites.
mastodon.world
WordPress Security Update — 28 January 2026 🔒 Last week, 225 vulnerabilities were found in WordPress plugins and themes, and fixes are now being released. However, 123 plugins still need updates. This is a good time to check that your website is up-to-date and secure. ✅ #WordPressSecurity https://solidwp.com/blog/wordpress-vulnerability-report-january-28-2026/
You've seen all posts