Your WordPress News Dashboard

400,000 WordPress Sites Affected by Account Takeover Vulnerability in Post SMTP WordPress Plugin

On October 11th, 2025, we received a submission for an Account Takeover via Email Log Disclosure vulnerability in Post SMTP, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for an unauthenticated attacker to view… Continue Reading →

Podcast E610 –Spooky Dev & Business Stories

This week I Share “Scary” Business Stories [powerpress]

Attackers Actively Exploiting Critical Vulnerability in WP Freeio Plugin

On September 25th, 2025, we received a submission for a Privilege Escalation vulnerability in WP Freeio, a WordPress plugin bundled in the Freeio premium theme with more than 1,700 sales. This vulnerability makes it possible for an unauthenticated attacker to… Continue Reading →

The Plugin Check Plugin now creates automatic security reports after each plugin update

As an important part of the internet, the WordPress community, actively thinks about the security of the ecosystem. Community members, developers, specialized companies, and independent researchers all play a role in maintaining the security of the environment. In the Plugins… Continue Reading →

Rogue WordPress Plugin Conceals Multi-Tiered Credit Card Skimmers in Fake PNG Files

The Wordfence Threat Intelligence Team recently discovered a sophisticated malware campaign targeting WordPress e-commerce sites, specifically those using the WooCommerce plugin. This malware exhibits advanced features including custom encryption methods, fake images used to conceal malicious payloads, a robust persistence… Continue Reading →

100,000 WordPress Sites Affected by Arbitrary File Read Vulnerability in Anti-Malware Security and Brute-Force Firewall WordPress Plugin

On October 3rd, 2025, we received a submission for an Arbitrary File Read vulnerability in Anti-Malware Security and Brute-Force Firewall, a WordPress plugin with more than 100,000 active installations. This vulnerability makes it possible for an authenticated attacker, with subscriber-level… Continue Reading →

Plugin Pulse: WP Plugins A to Z Unplugged #3

A WPProAtoZHost.com Company…. I am Talking about unpopular ideas in WordPress today and I have a New Plugin review, some News tips, plugin extras and more all coming up on Plugin Pulse: WP Plugins A to Z Unplugged. The post… Continue Reading →

Podcast E609 – Using GeoIP

This week I Talk About Using GeoIP [powerpress]

Podcast E608 – When To Say Yes, No or Maybe

This week I Talk About Saying Yes, No, Maybe [powerpress]

How To Create A Carousel In Divi 5 (Without Extra Plugins)

Carousels are a design element that almost every site needs, whether it’s for products, testimonials, or client logos. In the past, Divi users often relied on third-party plugins or custom code to achieve their desired results. With Divi 5, that’s… Continue Reading →

Turbocharge Your Site: WPPlugins AtoZ Drops Plugin Gold!

A WPProAtoZHost.com Company…. It’s Episode 659 and we have plugins for Actively Logging with TweakMaster, and some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post Turbocharge Your Site: WPPlugins AtoZ Drops Plugin Gold! appeared first on… Continue Reading →

Podcast E606 – Shutdowns & Opportunity

This week I Talk About How Shut Downs Could Equal Opportunity [powerpress]

How to Find Local File Inclusion (LFI) Vulnerabilities in WordPress Plugins and Themes

Local File Inclusion (LFI) occurs when user-controlled input is used to build a path to a file that is then included by the application. In WordPress (and PHP web applications in general), this means values from $_GET, $_POST, $_REQUEST, or… Continue Reading →

Rev Up Your Website: WPPluginsAtoZ’s Hottest Plugin Finds!

A WPProAtoZHost.com Company…. It’s Episode 658 and we have plugins for WebP Conversion with some Charades thrown in, and some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post Rev Up Your Website: WPPluginsAtoZ’s Hottest Plugin Finds!… Continue Reading →

Podcast E605 – GEO vs SEO

This week I Talk About GEO vs SEO [powerpress]

Podcast E604 – Interview with Miriam Schwab

This week I Interviewed Miriam Schwab [powerpress]

Supercharge Your WP Game: WP Plugins A to Z’s Plugin Extravaganza!

A WPProAtoZHost.com Company…. It’s Episode 657 and we have plugins for Public Previewing while Working on SEO, and some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post Supercharge Your WP Game: WP Plugins A to Z’s… Continue Reading →

Podcast E603 – Website Build Times

This week I Talk About Website Build Times [powerpress]

The 5 Best WordPress Subscription Plugins For Recurring Revenue

Want to wake up to sales every morning? These 5 WordPress subscription plugins help you turn one-time buyers into loyal, paying subscribers. Whether you run a digital store, membership site, or online service, this roundup shows you how to unlock… Continue Reading →

The Price of ‘Free’: How Nulled Plugins Are Used to Weaken Your Defense

The Wordfence Threat Intelligence Team has discovered a new malware campaign that highlights the hidden risks associated with “nulled plugins”, or premium plugins that have been tampered with by third parties. This campaign is particularly concerning because it doesn’t just… Continue Reading →

Podcast E602 – Lessons Learned After 600 Episodes

This week I Share What I’ve Learned After 601 Episodes [powerpress]

Comment on Stats of Plugins Team after WordCamp US by pradeepkkuldeep

Plugin Upload Precheck helped me to rectify in plugin upload issue.

Comment on Plugin Rollout: Phased Releases by Rebecca Markowitz

This is a really exciting development! Thank you to everyone who has been working on it. Gradual rollouts will be a huge step forward for plugin stability and user trust, and we’re very appreciative of the effort that’s gone into… Continue Reading →

Comment on Stats of Plugins Team after WordCamp US by Sarankumar

As developers, the PCP Checker Plugin has been a huge help in identifying and fixing issues before submission. It has completely transformed our plugin submission process.”

Podcast E601 – My WordCampUS 2025 Recap

This week I Recap WordCamp US 2025 [powerpress]

Stats of Plugins Team after WordCamp US

After WordCamp US, we have prepared some insights about our team and we wanted to share it with the community. These are the insights from the Plugins Team: We now have 60,187 plugins published in the directory. Today, we received as many… Continue Reading →

Podcast E600 – Interview with Adam Warner

This week I Share My Interview with Adam Warner [powerpress]

Comment on Plugin Rollout: Phased Releases by csforwp

I would love to see this addition. Something that would make it more appealing to me would be the ability to invite specific users to upgrade. This would allow for granular control over the release without having to install the… Continue Reading →

WP Plugins A to Z Serves Up WordPress Wow Factor!

A WPProAtoZHost.com Company…. It’s Episode 656 and we have plugins for ClickTocking with a Peaceful Protocol, and some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post WP Plugins A to Z Serves Up WordPress Wow Factor!… Continue Reading →

Podcast E599 – Listener Q & A

This week I Answer Listener Questions [powerpress]

« Older posts

© 2025 WP News Desk — Powered by WordPress and WP RSS Aggregator | Hosted by WP Engine

Up ↑