#wordpresssecurity

6 posts · Last used 5d

Back to Timeline
The WordPress Guy @wpguyuk@infosec.exchange · 5d ago
A critical WordPress RCE vulnerability, wp2shell, was disclosed on 17 July 2026. It chains a REST API route confusion flaw with an SQL injection in WP_Query — no login required, no plugin involved. If my site were unpatched, an attacker could take full control. Check your WordPress version now. #WordPress #Security #WordPressSecurity #WebSecurity #RCE https://wpguy.uk/blog/is-your-wordpress-site-exposed-to-the-wp2shell-remote-code-execution-flaw/
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 18, 2026
🚨 CRITICAL: WordPress Core "wp2shell" RCE A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations. ⚠️ No plugins. ⚠️ No themes. ⚠️ No authentication required. Tracked as: 🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE) 🔴 CVE-2026-60137 (Facilitated SQL Injection) Affected versions • WordPress 6.9.0–6.9.4 • WordPress 7.0.0–7.0.1 ✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations. 🔗 Full technical analysis: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/ #WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
34
1
55
The WordPress Guy @wpguyuk@infosec.exchange · Jul 08, 2026
250+ WordPress plugin vulnerabilities are disclosed every week in 2026 — that is not a spike, it is the baseline. What concerns me most is that 43% require no login to exploit. Automated scanners find vulnerable sites before most owners even know a patch exists. This is the environment I work in daily, and it demands a serious approach to hardening. #WordPress #WebSecurity #WordPressSecurity #PluginSecurity https://wpguy.uk/blog/wordpress-plugin-vulnerabilities-are-rising-what-business-owners-must-know/
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 08, 2026
Censys research finds 70% of WordPress sites run end-of-life PHP. Outdated plugins and defaults leave millions of sites wide open to attack. #WordPress #OutdatedPHP #WordPressSecurity #EndOfLife #MRGreen https://securityonline.info/wordpress-outdated-php-security-risk/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
The WordPress Guy @wpguyuk@infosec.exchange · Jul 06, 2026
Three plugins I keep a close eye on — WPForms (6M+ sites), WPvivid, and Smart Slider 3 — all had vulnerabilities publicly disclosed in June 2026. Patches are available for all three. If you have not updated recently, your site is likely exposed. Worth checking your versions today. #WordPress #WordPressSecurity #WPForms #PluginUpdates #WebsiteSecurity https://wpguy.uk/blog/wordpress-plugin-vulnerabilities-in-june-2026-what-site-owners-must-know/
0
0
0
Good Websites @goodwebsitesnz@mastodon.world · Jan 28, 2026
WordPress Security Update — 28 January 2026 🔒 Last week, 225 vulnerabilities were found in WordPress plugins and themes, and fixes are now being released. However, 123 plugins still need updates. This is a good time to check that your website is up-to-date and secure. ✅ #WordPressSecurity https://solidwp.com/blog/wordpress-vulnerability-report-january-28-2026/
0
0
1

You've seen all posts