WordPress security news.
Disclosures, campaigns, plugin deprecations, vendor moves, and the occasional post-mortem. What the WordPress security beat looks like when nobody’s selling you anything at the end of it.
What lands on this desk.
Five beats. One editor. Stories run when there’s something worth saying, not on a schedule.
Disclosures
CVEs in core, plugins, and themes that actually matter. What the bug does, how it’s exploited, who’s at risk this week.
Campaigns
Active exploitation waves, credential-stuffing runs, card-skimming injections. Indicators, traffic signatures, mitigations.
Plugin status
Abandonware, ownership changes, repository removals, forced updates. The lifecycle stuff that quietly leaves you exposed.
Vendor moves
Acquisitions, pricing changes, feature launches that change the threat model. Tracked with receipts.
Post-mortems
When a breach hits a known WordPress target and the story is worth slowing down for. Timelines, root causes, what held and what didn’t.
Recent reporting.
The Essential Plugin backdoor: how 31 WordPress plugins went malicious in eight hours
Sold on Flippa for six figures. Dormant for eight months. Activated April 6. The deserialization gadget, the Ethereum C2, and what to do if you were running any of the 31 affected plugins.
The Plausible Analytics speed module: how a performance shortcut could switch off your firewall
A must-use plugin that unloads every other plugin on proxy requests, keyed off a value printed on every page. We reported it, Plausible patched it in 2.5.8, and we walk the bypass and the fix.
Protect the Shire and the two threats one update button cannot both solve
The Protect the Shire cooldown holds every plugin release, fix or feature. We examine why auto-updates are a defense and a supply-chain liability at once.