How WordPress Vulnerabilities Get Found, Reported, and Patched
A look at the pipeline behind every WordPress security update, from researcher discovery to CVE listing to the patch gap that makes update urgency real.
All posts in this stream, newest first.
A look at the pipeline behind every WordPress security update, from researcher discovery to CVE listing to the patch gap that makes update urgency real.
Cross-site request forgery tricks your browser into spending your login session on the attacker's behalf. Here's how it works, how WordPress's nonce system helps, and what to check when a plugin's defenses are not enough.
A methodical, hour-long pass through users, updates, permissions, exposure, and backups that closes the door on most real-world WordPress attacks.
When a zero-day hits a plugin in your stack, the first hour matters more than the fix itself. Here is a calm, ordered way to triage it.
A plain-language look at how SQL injection actually works, why WordPress core rarely causes it, and the layered defenses that keep a real attack from becoming a real breach.
The OWASP Top 10 is written for web applications in general. Here is what each risk actually looks like on a WordPress site, and the one fix that matters most for each.
Decoy fields, fake endpoints, and canary tokens turn an attacker's reconnaissance into your alert, often before they ever get close to real data.
A shared spreadsheet of logins is a liability waiting to happen. Here is how to move a WordPress team onto a real password manager with proper role scoping and a clean offboarding process.
Not all second factors are created equal. Here is how SMS, authenticator apps, and passkeys actually hold up against phishing and SIM swaps, and how to get a reluctant team to turn any of them on.