Website security: weekly review (07.09.2026)
Weekly digest of the most important WordPress and Joomla vulnerabilities. This week we recorded 74 vulnerabilities; check whether any of them affects your website.
Read more →All articles in the "Security" category. 28 articles.
No articles match your search. Try another word.
Weekly digest of the most important WordPress and Joomla vulnerabilities. This week we recorded 74 vulnerabilities; check whether any of them affects your website.
Read more →The more popular an add-on, the wider a flaw's blast radius. Essential Addons for Elementor, over a million installs, let anyone reset any account's password in 2023.
Read more →Membership plugins can be a back door. A flaw in Ultimate Member let you become a site administrator right at registration, and it was exploited in the wild.
Read more →In 2023 a flaw in the WooCommerce Payments plugin let a stranger pose as the shop administrator. With a single request header. WordPress had to force updates.
Read more →LiteSpeed Cache is one of the most popular WordPress speed plugins, 5 million installs. In 2024 it had a flaw that let a stranger become an administrator.
Read more →Many people think only plugins are dangerous. Yet in 2024 the popular Bricks builder/theme let strangers run their own code on the server, without logging in.
Read more →