The WordPress Guy
#ActuallyAutistic #WordPress developer specialising in forensic troubleshooting, #security and #performance. 20 years' experience. 🏴
If your WordPress site runs 6.8.x, 6.9.x, or 7.0.x and has not been patched recently, the wp2shell vulnerability chain disclosed in July 2026 allows full admin takeover via SQL injection — no credentials required. I would check your version right now and update immediately.
#WordPress #Security #WordPressSecurity #RCE #Patching
https://wpguy.uk/blog/is-your-wordpress-site-safe-after-july-2026s-record-security-patch-wave/
WP2Shell is being actively exploited right now. If your site runs WordPress 6.9.0–6.9.4 or 7.0.0–7.0.1, a single unauthenticated HTTP request can hand an attacker full control. No plugin, no login, no prior access needed. CVSS 9.8. Update immediately.
#WordPress #WordPressSecurity #WP2Shell #CVE #SecurityHardening
https://wpguy.uk/blog/wp2shell-what-wordpress-site-owners-must-do-right-now/
Two CVEs in WordPress 6.8 and 6.9 were patched on 17 July 2026. One allows arbitrary code execution on your server — that is as serious as it sounds. If my sites were still on either version, updating to 7.0.2 would be the first thing I did this morning. Both CVEs are publicly logged, meaning unpatched sites are visible targets.
#WordPress #WordPressSecurity #CVE #WebSecurity #WPSecurity
https://wpguy.uk/blog/wordpress-security-flaw-what-business-owners-must-do-right-now/
Many self-employed owners only discover they have crossed the £90,000 VAT threshold at year end — by which point they already owe VAT they never collected. If you expect to hit it within 30 days, you must register before reaching it. I have linked a full guide below.
#WordPress #SelfEmployed #VAT #UKBusiness #SmallBusiness
https://wpguy.uk/blog/vat-registration-for-the-self-employed-what-business-owners-must-know-in-2026/
Critical plugin flaws disclosed in June 2026 mean attackers can create admin accounts with no password — WP Maps Pro exposes a nonce in every frontend page, making its "protection" worthless. I see sites exploited within hours of disclosure. Patch immediately or remove plugins you are not actively using.
#WordPress #Security #WordPressSecurity #PluginSecurity
https://wpguy.uk/blog/wordpress-plugin-flaws-in-june-2026-put-thousands-of-business-sites-at-risk/
Up to £3.2 billion in UK online retail sales each year involve sellers fraudulently claiming to be UK-established to dodge VAT. That 20% margin gives overseas operators a structural pricing advantage over legitimate sellers. As a WooCommerce specialist, I'm watching this consultation closely — the outcome will directly affect how UK stores compete.
#WooCommerce #WordPress #UKVat #eCommerce #OnlineRetail
https://wpguy.uk/blog/vat-loophole-costing-uk-online-sellers-millions-what-changes-next/
Quadrant, Lando Norris's sports brand, chose Shopify to run their London pop-up at Outernet ahead of British Grand Prix week — opening in days, not weeks. In my view, WooCommerce can handle pop-up retail, but it requires more setup time. Worth weighing up before your next physical activation.
#WooCommerce #Shopify #WordPress #RetailTech #eCommerce
https://wpguy.uk/blog/can-woocommerce-power-a-pop-up-store-as-well-as-shopify-can/
Stricter returns policies are quietly killing WooCommerce sales. Locus research puts £34.1bn in UK online revenue at risk because shoppers are abandoning stores with tough returns rules. I see this with clients regularly — tightening policy to cut costs often costs more in lost conversions. Worth reviewing before your next sale season.
#WooCommerce #eCommerce #WordPress #ReturnsPolicies #OnlineRetail
https://wpguy.uk/blog/could-your-returns-policy-be-costing-your-woocommerce-store-customers/
PCI DSS certification confirms you met a minimum standard for handling cardholder data. It does not confirm your WooCommerce checkout is secure. Conflating the two is one of the more expensive mistakes a store owner can make — and I see it regularly.
#WordPress #WooCommerce #PCICompliance #WebSecurity #WordPressSecurity
https://wpguy.uk/blog/why-pci-compliance-alone-will-not-protect-your-woocommerce-checkout/

