WordPress Security News

WordPress security news.

Disclosures, campaigns, plugin deprecations, vendor moves, and the occasional post-mortem. What the WordPress security beat looks like when nobody’s selling you anything at the end of it.

What lands on this desk.

Five beats. One editor. Stories run when there’s something worth saying, not on a schedule.

01

Disclosures

CVEs in core, plugins, and themes that actually matter. What the bug does, how it’s exploited, who’s at risk this week.

02

Campaigns

Active exploitation waves, credential-stuffing runs, card-skimming injections. Indicators, traffic signatures, mitigations.

03

Plugin status

Abandonware, ownership changes, repository removals, forced updates. The lifecycle stuff that quietly leaves you exposed.

04

Vendor moves

Acquisitions, pricing changes, feature launches that change the threat model. Tracked with receipts.

05

Post-mortems

When a breach hits a known WordPress target and the story is worth slowing down for. Timelines, root causes, what held and what didn’t.

Recent reporting.

Scroll to Top