Category: Security advisories
WordPress plugin and theme security advisories, disclosures and how to respond.
-

Staying ahead of WordPress plugin vulnerabilities
Most WordPress sites are not broken into through some clever, bespoke attack. They are broken into through a plugin or theme flaw that was disclosed weeks earlier, patched by the developer, and simply never updated on the site. Staying ahead of that is less about heroics and more about a routine: knowing where vulnerabilities are…