Jeffro
Jeffro@wptoots.social
<p>I like trains, weather, classic rock music, comedy, and being WYSIWYG. I am the engineer of <a href="http://wpmainline.com" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">http://</span><span class="">wpmainline.com</span><span class="invisible"></span></a> where I write and talk about WordPress.</p>
Posts
- Post #3960583
-
Post #3941037
This vulnerability is OMGWTFBBQ level of seriousness. wp2shell is a pre-authentication RCE in WordPress Core. No login, no plugins, no preconditions. An anonymous attacker can hit a stock install and take over the site. The worst WP security vulnerability in a long time. Update!
-
Post #3907995
It's Friday. What better way to celebrate than making sure your WordPress sites are updated to 7.0.2 to implement some major security fixes https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
-
Post #2312285
WP Beacon tracks every plugin on wordpress dot org — its authors, committers, and releases — to flag ownership transfers, dormant-then-activated takeovers, and release patterns that match known attacks. https://wpbeacon.io/
-
Post #889641
Wellp, we used up our last lifeline today. After this, if I don&#39;t find stable employment soon, we&#39;ll likely lose the house, or I&#39;ll need to file for bankruptcy. So if you have any WordPress work, see any gigs I might be good for, inside or OUTSIDE of WordPress, send em my way