When a "security" plugin lets the burglar in itself
Pure irony: a popular security plugin on 4 million sites had a flaw that let you log in as any user, including the administrator.
Read more →All articles in the "Security" category. 28 articles.
No articles match your search. Try another word.
Pure irony: a popular security plugin on 4 million sites had a flaw that let you log in as any user, including the administrator.
Read more →A popular file management plugin had a flaw that let a stranger upload their own code to the server. Without logging in. Bots started exploiting it within hours.
Read more →In 2017 a small bug in WordPress let strangers edit any post on a site, without logging in. Within days the content of over 1.5 million pages was rewritten. Here is what the story teaches.
Read more →A new flaw on the WordPress login screen (CVE-2026-64638) can, in the worst case, lead to PHP code execution on the server. It affects almost every version. The fix is in 7.0.3, see what to do.
Read more →The most common way into a site is not a sophisticated attack, but a weak password. Here is how to close that door in a few minutes, a password manager and two-factor login in plain words.
Read more →XML-RPC is an old WordPress mechanism that today serves attackers more often than site owners. We explain in plain words what it is and when it is safe to disable.
Read more →