Security news
WordPress security, in plain English
The vulnerabilities that matter, whether you're affected, and exactly what to do about it.
critical
Mailgun for WordPress: an SSRF flaw that can reroute your password-reset emails
A critical flaw in the Mailgun for WordPress plugin let an attacker redirect your incoming mail, including password resets, to themselves. Update to 2.2.2.
critical
WordPress 7.1.2 fixes a critical flaw that needs no password — update today
A path traversal bug in WordPress core lets a stranger read files off your server, and run code on some hosts. It affects every version back to 4.7. Update now.
critical
The iPhone photo problem: a critical flaw in the software behind your uploads
A 9.8-severity flaw in libheif affects servers that process iPhone photos, including the official WordPress Docker image. Updating WordPress won't fix this one.
high
WordPress 7.1.1 fixes 11 security issues, including a one-click site takeover
WordPress 7.1.1 patches 11 security problems, one of which lets an attacker take over a site if an admin clicks the wrong link. Here's whether you're affected.
high
Tutor LMS: 100,000+ sites at risk of takeover, update to 4.0.8
A flaw in Tutor LMS lets a low-level user run code on your server. If your course site runs Tutor LMS 4.0.7 or earlier, update today.
critical
The Events Calendar: two 9.8 flaws let a blog comment take over 600,000+ sites
Two critical flaws in The Events Calendar plugin let an attacker run code on your server just by leaving a comment on an event. Update to 6.17.4.1.
critical
GiveWP donation plugin: a 10-out-of-10 flaw anyone on the internet could use
A maximum-severity flaw in GiveWP let anyone take over a donation site without logging in. Update to 4.16.7.2 and check who's been added to your site.
What we cover
Vulnerabilities in plugins and themes that are widely used, actively exploited, or serious enough to hand someone your site. We skip the noise.
Every post explains whether you're affected and what to do, and links to the original research.