WPDeeply
Download free plugin

WPdeeply

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.

51 published guides
Tutor LMS <= 4.0.7 - Subscriber+ PHP Object Injection to RCE (CVE-2026-78175) CVE-2026-78175 allows subscriber-level attackers to reach PHP Object Injection and remote code execution in Tutor LMS 4.0.7 and earlier. Update to 4.0.8 or later. Plugin Security 19 Sep 2026, 4 min WordPress Core <= 7.1 - 11 Security Fixes Including Stored XSS and Click2Shell WordPress 7.1.1 fixes 11 security issues, including CVE-2026-93485 stored XSS and the Click2Shell crafted-URL chain. Update WordPress Core immediately. Security News 19 Sep 2026, 4 min How to Perform VAPT Penetration Testing on Your WordPress Site VAPT has two parts: vulnerability assessment and penetration testing. Most WordPress owners can automate the assessment phase, then reserve manual testing for the risks that actually matter. Security Research 19 Sep 2026, 2 min Are Budget Hosts Secure? A Security-First Review of GoDaddy and Namecheap Budget hosting can be acceptable for WordPress, but it does not remove your application-layer responsibility. Your host protects the server; you still need to protect WordPress. Hardening 17 Sep 2026, 2 min Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload CVE-2026-87796 is a critical unauthenticated arbitrary file upload in Multi Uploader for Gravity Forms 1.1.9 and earlier. No patched release is known; deactivate the plugin and investigate uploads. Plugin Security 17 Sep 2026, 3 min All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Credential Storage via Basic Auth Header CVE-2026-89064 affects All-in-One WP Migration and Backup 7.110 and earlier. Update to 7.111 and review exposed authentication workflows. Plugin Security 17 Sep 2026, 3 min WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Active Exploitation of Unauthenticated File Upload RCE Active attacks are exploiting an unauthenticated file upload flaw in WooCommerce Wholesale Lead Capture 2.0.3.1 and earlier. Update to 2.0.3.2 and investigate for PHP webshells. Plugin Security 16 Sep 2026, 4 min How to Install WordPress Securely: A Step-by-Step Hardening Guide A secure WordPress install starts before the first login. Choose sane credentials, limit file risk, harden configuration, and run a baseline vulnerability scan before adding traffic. Hardening 15 Sep 2026, 2 min The Events Calendar <= 6.17.4 - Unauthenticated RCE via Widget Instance Handling CVE-2026-78006 and CVE-2026-78159 affect The Events Calendar. Update to 6.17.4.1 or later immediately. Plugin Security 13 Sep 2026, 3 min Why WordPress Maintenance Is Actually Security Maintenance If your maintenance plan does not include vulnerability patching, abandoned plugin detection, and component risk review, it is not maintenance. It is delay. Hardening 10 Sep 2026, 2 min