Elektrine lite

โ† Feed

The WordPress Guy

wpguyuk@infosec.exchange

<p><a href="https://infosec.exchange/tags/ActuallyAutistic" class="mention hashtag" rel="tag">#<span>ActuallyAutistic</span></a> <a href="https://infosec.exchange/tags/WordPress" class="mention hashtag" rel="tag">#<span>WordPress</span></a> developer specialising in forensic troubleshooting, <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="tag">#<span>security</span></a> and <a href="https://infosec.exchange/tags/performance" class="mention hashtag" rel="tag">#<span>performance</span></a>. 20 years&#39; experience. ๐Ÿด๓ ง๓ ข๓ ณ๓ ฃ๓ ด๓ ฟ</p>

Posts

  • View post

    If your site runs Elementor Pro with a file upload field in any form, patch immediately. Versions 4.2.1 and below contain a critical flaw that allows complete site takeover โ€” no account, no password, no interaction required. The upload field your visitors use daily is the attack vector. I recommend updating now without delay. #WordPress #Elementor #WebSecurity #WordPressSecurity #SecurityHardening https://wpguy.uk/blog/elementor-pro-file-upload-vulnerability-patch-now/

  • View post

    With 59,000+ free plugins available, the question is never just &quot;which plugin does this job&quot; โ€” it is &quot;which plugin does this job without costing more than it delivers.&quot; Quality beats quantity every time. A lean set of well-coded plugins will always outperform a bloated collection. #WordPress #WebPerformance #WordPressPlugins #PerformanceOptimisation https://wpguy.uk/blog/which-wordpress-plugins-actually-improve-site-speed-and-business-performance/

  • View post

    PCI DSS certification confirms you met a minimum standard for handling cardholder data. It does not confirm your WooCommerce checkout is secure. Conflating the two is one of the more expensive mistakes a store owner can make โ€” and I see it regularly. #WordPress #WooCommerce #PCICompliance #WebSecurity #WordPressSecurity https://wpguy.uk/blog/why-pci-compliance-alone-will-not-protect-your-woocommerce-checkout/

  • View post

    Stricter returns policies are quietly killing WooCommerce sales. Locus research puts ยฃ34.1bn in UK online revenue at risk because shoppers are abandoning stores with tough returns rules. I see this with clients regularly โ€” tightening policy to cut costs often costs more in lost conversions. Worth reviewing before your next sale season. #WooCommerce #eCommerce #WordPress #ReturnsPolicies #OnlineRetail https://wpguy.uk/blog/could-your-returns-policy-be-costing-your-woocommerce-store-customers/

  • View post

    Quadrant, Lando Norris&amp;#39;s sports brand, chose Shopify to run their London pop-up at Outernet ahead of British Grand Prix week โ€” opening in days, not weeks. In my view, WooCommerce can handle pop-up retail, but it requires more setup time. Worth weighing up before your next physical activation. #WooCommerce #Shopify #WordPress #RetailTech #eCommerce https://wpguy.uk/blog/can-woocommerce-power-a-pop-up-store-as-well-as-shopify-can/

  • View post

    Up to ยฃ3.2 billion in UK online retail sales each year involve sellers fraudulently claiming to be UK-established to dodge VAT. That 20% margin gives overseas operators a structural pricing advantage over legitimate sellers. As a WooCommerce specialist, I&amp;#39;m watching this consultation closely โ€” the outcome will directly affect how UK stores compete. #WooCommerce #WordPress #UKVat #eCommerce #OnlineRetail https://wpguy.uk/blog/vat-loophole-costing-uk-online-sellers-millions-what-changes-...

  • View post

    Critical plugin flaws disclosed in June 2026 mean attackers can create admin accounts with no password โ€” WP Maps Pro exposes a nonce in every frontend page, making its &amp;quot;protection&amp;quot; worthless. I see sites exploited within hours of disclosure. Patch immediately or remove plugins you are not actively using. #WordPress #Security #WordPressSecurity #PluginSecurity https://wpguy.uk/blog/wordpress-plugin-flaws-in-june-2026-put-thousands-of-business-sites-at-risk/

  • View post

    Many self-employed owners only discover they have crossed the ยฃ90,000 VAT threshold at year end โ€” by which point they already owe VAT they never collected. If you expect to hit it within 30 days, you must register before reaching it. I have linked a full guide below. #WordPress #SelfEmployed #VAT #UKBusiness #SmallBusiness https://wpguy.uk/blog/vat-registration-for-the-self-employed-what-business-owners-must-know-in-2026/

  • View post

    Two CVEs in WordPress 6.8 and 6.9 were patched on 17 July 2026. One allows arbitrary code execution on your server โ€” that is as serious as it sounds. If my sites were still on either version, updating to 7.0.2 would be the first thing I did this morning. Both CVEs are publicly logged, meaning unpatched sites are visible targets. #WordPress #WordPressSecurity #CVE #WebSecurity #WPSecurity https://wpguy.uk/blog/wordpress-security-flaw-what-business-owners-must-do-right-now/

  • View post

    WP2Shell is being actively exploited right now. If your site runs WordPress 6.9.0โ€“6.9.4 or 7.0.0โ€“7.0.1, a single unauthenticated HTTP request can hand an attacker full control. No plugin, no login, no prior access needed. CVSS 9.8. Update immediately. #WordPress #WordPressSecurity #WP2Shell #CVE #SecurityHardening https://wpguy.uk/blog/wp2shell-what-wordpress-site-owners-must-do-right-now/

  • View post

    If your WordPress site runs 6.8.x, 6.9.x, or 7.0.x and has not been patched recently, the wp2shell vulnerability chain disclosed in July 2026 allows full admin takeover via SQL injection โ€” no credentials required. I would check your version right now and update immediately. #WordPress #Security #WordPressSecurity #RCE #Patching https://wpguy.uk/blog/is-your-wordpress-site-safe-after-july-2026s-record-security-patch-wave/

  • View post

    Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale โ€” High severity โ€” and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8. #WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity https://wpguy.uk/blog/high-vulnerability-in-fluent-forms-customizable-contact-forms-survey-quiz-amp-conversational-form-builder-fluent-forms-customizable-co...

  • View post

    UK WooCommerce merchants running both online and in-person sales have always faced a stock sync headache โ€” something selling at a market before the online listing updates. The new iPhone POS integration addresses that directly by keeping everything inside one system. Worth a look if you split your sales across locations. #WooCommerce #WordPress #pointofsale #ecommerce #ukbusiness https://wpguy.uk/blog/how-uk-woocommerce-stores-can-now-take-card-payments-with-just-an-iphone/

  • View post

    If you&#39;re running WordPress 6.9.0 through 7.0.1, working exploit scripts are already circulating publicly on GitHub โ€” right now, before 7.1 even ships on 19 August. I would not wait for release day on this one. Update the moment 7.1 lands. #WordPress #WordPressSecurity #WebDev #WordCamp #WPGuy https://wpguy.uk/blog/wordpress-71-is-coming-what-business-owners-need-to-know-now/

  • View post

    TikTok contributed ยฃ10 billion to the UK economy in 2025 and supported 153,000 jobs. If your WooCommerce store has no presence there, someone else is taking those sales. I help store owners connect WooCommerce to TikTok Shop so their products reach buyers who are already ready to purchase. #WooCommerce #TikTokShop #WordPress #eCommerce #WordPressEngineer https://wpguy.uk/blog/is-your-woocommerce-store-missing-out-on-tiktoks-10bn-sales-opportunity/

  • View post

    If your WooCommerce store relies heavily on Google Shopping, the EU&#39;s July 2026 Digital Markets Act decisions matter to you. Google must now share anonymised search ranking data with rivals, which could shift how product discovery works across the board. I&#39;d read up on this before assuming your current traffic sources stay stable. #WooCommerce #WordPress #GoogleShopping #DigitalMarketsAct #eCommerce https://wpguy.uk/blog/will-google-losing-its-eu-data-monopoly-change-how-your-woocommer...

  • View post

    A critical WordPress RCE vulnerability, wp2shell, was disclosed on 17 July 2026. It chains a REST API route confusion flaw with an SQL injection in WP_Query โ€” no login required, no plugin involved. If my site were unpatched, an attacker could take full control. Check your WordPress version now. #WordPress #Security #WordPressSecurity #WebSecurity #RCE https://wpguy.uk/blog/is-your-wordpress-site-exposed-to-the-wp2shell-remote-code-execution-flaw/

  • View post

    WordPress 7.1 drops on 19 August 2026. Beta 1 landed on 15 July, which means the testing window is already open. I&#39;ve seen live sites break on smaller releases than this โ€” a checkout or corrupted layout mid-upgrade is not a risk worth taking. My advice: test before August, not after. #WordPress #WordPressDeveloper #WebDevelopment #BusinessWebsites #WordCamp https://wpguy.uk/blog/wordpress-71-is-coming-what-business-owners-need-to-do-now/

  • View post

    Tide has attracted over 1.5 million UK businesses, which is worth pausing on. I took a proper look at whether their free plan genuinely suits small business workflows or quietly costs more than a paid account would. My verdict might surprise you. #WordPress #SmallBusiness #BusinessBanking #Tide #UKBusiness https://wpguy.uk/blog/free-uk-business-bank-account-is-tide-right-for-your-small-business/

  • View post

    UK high street footfall dropped 6.2% in June โ€” four times the May decline. Scotland, where it stayed cooler, actually saw a 1.7% increase. Shoppers are not disappearing, they are redirecting. For WooCommerce store owners, that shift is worth paying attention to. #WooCommerce #WordPress #eCommerce #UKRetail #OnlineShopping https://wpguy.uk/blog/why-uk-heatwaves-are-pushing-more-shoppers-to-buy-online/

  • View post

    250+ WordPress plugin vulnerabilities are disclosed every week in 2026 โ€” that is not a spike, it is the baseline. What concerns me most is that 43% require no login to exploit. Automated scanners find vulnerable sites before most owners even know a patch exists. This is the environment I work in daily, and it demands a serious approach to hardening. #WordPress #WebSecurity #WordPressSecurity #PluginSecurity https://wpguy.uk/blog/wordpress-plugin-vulnerabilities-are-rising-what-business-owners-...

  • View post

    Three plugins I keep a close eye on โ€” WPForms (6M+ sites), WPvivid, and Smart Slider 3 โ€” all had vulnerabilities publicly disclosed in June 2026. Patches are available for all three. If you have not updated recently, your site is likely exposed. Worth checking your versions today. #WordPress #WordPressSecurity #WPForms #PluginUpdates #WebsiteSecurity https://wpguy.uk/blog/wordpress-plugin-vulnerabilities-in-june-2026-what-site-owners-must-know/