Search
Items tagged with: wordpress
WordPress 7.0.4 is now available. This security release addresses an authenticated Author+ remote code execution vulnerability involving malicious file uploads on sites that use Imagick and Ghostscript. Update your sites immediately. Fixes are also being backported through the 4.7 branch. wp.me/pZhYe-5yH
👇
thehackernews.com/2026/08/new-…
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under specific conditions.The Hacker News
#wordpress question:
I changed the name of a webpage. I changed it in the WP editor and in the "quick edit" window in the admin area. I updated the slug and all menus with the new page title.
But the main header menu still lists the old page name and returns a 404. The two footer menus list the correct page title and go to it fine when clicked. It's the main menu and the "Prints" page header menu that have the problem.
I removed the link entirely from the main menu, but it still showed up.
This has to be a caching issue, no?
Other site changes update fine.
I've purged the Cloudflare cache several times and waited an hour or so, cleared the browser history, tried 3 browsers. Restarted my laptop. Checked on another laptop and phone. Always the same.
If you go to my site mikaljakubal.com do you see an "Ajo Library Show" link at the top? It's supposed to read "Tucson Library Prints." Does it still take you to a 404?
This is driving me nuts. TIA
WordPress Coding Standards 3.4.1 is a security release. All WordPressCS users are strongly encouraged to update as soon as possible.
Review the release details: github.com/WordPress/WordPress…
Release 3.4.1 - 2026-07-27 · WordPress/WordPress-Coding-Standards
This is a security release and all users are advised to update their WordPressCS install as soon as possible. Changed The minimum required PHPCSUtils version to 1.2.3 (was 1.2.2). #2770 The minimu...GitHub
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
GitHub - Icex0/wp2shell-poc: wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain - Icex0/wp2shell-pocGitHub
WordPress Coding Standards 3.4.0 is now available. 🧑💻
This release adds command-line documentation for more sniffs, resolves several false positives and negatives, and updates checks for WordPress features through 7.0.
Explore the release: github.com/WordPress/WordPress…
Release 3.4.0 · WordPress/WordPress-Coding-Standards
We're happy to welcome @rodrigoprimo as co-maintainer of WordPressCS as of this release. Added WordPress.Arrays.ArrayDeclarationSpacing: new allow_single_item_single_line_explicit_key_arrays prope...GitHub
