Blog
Practical advice on websites, security, SEO, CRM and AI for service businesses — from our YouTube channel.
-
WordPress 7.1.2: Critical Core Flaw, No Login Needed
A critical WordPress core path traversal flaw, rated 9.2, needs no login and affects versions back to 4.7. Here's who should update, how, and…
Read more -
WP User Manager Flaw Can Redirect Your Stripe Payments
A WP User Manager flaw could redirect Stripe payments to an attacker, plus vulnerabilities in Divi Essential, HUSKY, WP Table Builder and Give Tributes,…
Read more -
Click2Shell: One Link Could Give Hackers Your WordPress Site
Click2Shell's attack chain behind a WordPress 7.1.1 fix is now public, plus vulnerabilities in NextGEN Gallery, Unlimited Elements for Elementor, ManageWP Worker and Amelia…
Read more -
Gravity Forms Critical Flaw: Hackers Could Upload Code
A critical Gravity Forms flaw could let attackers upload code without logging in, plus vulnerabilities in Forminator, Botiga Pro, WP Recipe Maker and LiteSpeed…
Read more -
Should Business Owners Panic About WordPress 7.1.1?
What WordPress 7.1.1's 11 security fixes actually mean for business owners, from a stored comment attack to permission flaws, and the simple steps to…
Read more -
The Events Calendar Flaw: 600,000 WordPress Sites, No Login
The Events Calendar flaw lets attackers run code on 600,000 WordPress sites without logging in, plus vulnerabilities in Tutor LMS, Popup Maker, Booking Calendar…
Read more -
5 WordPress Vulnerabilities Today: One Has No Fix
WordPress 7.1.1 fixes 11 security issues, plus flaws in JetFormBuilder, WP Import Export Lite, WP Cookie Consent and a Gravity Forms uploader with no…
Read more