Security News
New vulnerabilities, plugin removals and security releases.
6
Guides
Elementor Pro <= 4.2.1 - Unauthenticated Arbitrary File Upload to RCE
Elementor Pro versions up to 4.2.1 contain a critical unauthenticated arbitrary file upload vulnerability in the Forms module. Update to 4.2.2 or later and inspect Elementor form upload…
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload
Forminator Forms versions up to 1.56.1 contain a critical unauthenticated arbitrary file upload vulnerability. Update to 1.56.2 or later and review public forms that combine Select and File…
WordPress Vulnerabilities — July 2026
What mattered in WordPress plugin security last month, and what to do about it.
WordPress Security Plugins Compared: What Each Type Actually Does
Firewalls, scanners, backup tools and vulnerability monitors solve different problems. Mixing them up leaves gaps.
WordPress Vulnerabilities — June 2026
June’s WordPress plugin security disclosures, and the recurring themes behind them.
WordPress Updates from Core and Security: How to Read Patch Signals
Do not wait for a dramatic changelog line. Many serious WordPress fixes arrive in plain maintenance language, and attackers read the diff faster than most site owners read…