Every Way Your WordPress Site Hands Out Usernames
WordPress publishes usernames through five separate paths, most of them core behaviour. Each one tested against a live install, with the fix, the fleet audit, and what to do first instead.
WordPress publishes usernames through five separate paths, most of them core behaviour. Each one tested against a live install, with the fix, the fleet audit, and what to do first instead.
An authenticated Author+ RCE via file upload on sites using Imagick and Ghostscript. Three checkable preconditions, the WP-CLI to answer each across a fleet, and what the CVE record does not yet say.
A reported campaign impersonates AI crawlers to scan for credential and config files left by AI coding tools. Why user-agent rules are theatre, how to verify a crawler properly, and the commands to check your own fleet.
Discovery got faster on both sides. Distribution of the fix did not. What AI actually changed about finding plugin bugs, what it did not, and the WP-CLI commands to measure your own exposure window.
Disable XML-RPC, block REST API user enumeration, and stop ?author= redirects with exact PHP hooks, Apache/.htaccess, and Nginx config examples.
Three high-severity WordPress vulnerabilities are under active exploitation right now — Ninja Forms file upload, Kali Forms, and Perfmatters file deletion. Here is what got disclosed between April 6 and April 18, who is affected, and the exact steps to take in the next 10 minutes if you run any of them.
A critical unauthenticated SQL injection vulnerability in the Ally accessibility plugin puts 400,000 WordPress sites at risk. How to check if you're affected, how to update, and what to do if you were already compromised.
Seven concrete security checks you can run on any WordPress site in under 5 minutes: SSL certificate status, security headers, exposed sensitive files, PHP version, external JavaScript sources, user roles, and file permissions.
A practical guide for developers and site owners on hardening WordPress against malware infections and crypto mining scripts - covering server hardening, file monitoring, mu-plugin security, wp-config hardening, malware detection techniques, and signs your site has been compromised.
Weekly analysis of WordPress vulnerabilities reported between February 23 and March 1. Covers critical and high-severity issues, affected plugins, CVE details, and the action items site owners need to take immediately.