Your WordPress News Dashboard

The Ultimate Savings Event for WordPress Professionals

It’s the time of year when we roll out delicious savings! We’re offering new customers big savings on the essential plugins trusted by top developers and agencies worldwide. Whether you’re trying to move a complex website, offload a massive media… Continue Reading →

Podcast E612 – Do’s & Dont’s For BF/CM in 2025

This week I Share Do’s & Dont’s For BF/CM in 2025 [powerpress]

Plugin Fever: Catch the WordPress Buzz with WPPlugins AtoZ!

A WPProAtoZHost.com Company…. It’s Episode 660 and we have plugins for Posting Calendars while Monitoring Users Live, with some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post Plugin Fever: Catch the WordPress Buzz with WPPlugins AtoZ!… Continue Reading →

Podcast E611 – Getting A Coach For Your Business

This week I Talk About Getting A Coach For Your Business [powerpress]

100,000 WordPress Sites Affected by Privilege Escalation Vulnerability in AI Engine WordPress Plugin

On October 4th, 2025, we received a submission for a Sensitive Information Exposure vulnerability in AI Engine, a WordPress plugin with more than 100,000 active installations. This vulnerability can be exploited by unauthenticated attackers to extract the bearer token and… Continue Reading →

400,000 WordPress Sites Affected by Account Takeover Vulnerability in Post SMTP WordPress Plugin

On October 11th, 2025, we received a submission for an Account Takeover via Email Log Disclosure vulnerability in Post SMTP, a WordPress plugin with more than 400,000 active installations. This vulnerability makes it possible for an unauthenticated attacker to view… Continue Reading →

Podcast E610 –Spooky Dev & Business Stories

This week I Share “Scary” Business Stories [powerpress]

Comment on The Plugin Check Plugin now creates automatic security reports after each plugin update by mujuonly

Kudos to the PCP team.

Comment on The Plugin Check Plugin now creates automatic security reports after each plugin update by Mary Hubbard

I’m so happy to see this land and excited to see its progress! Great work.

Comment on The Plugin Check Plugin now creates automatic security reports after each plugin update by Fernando Tellado

In reply to Amber Hinds. It’s not bad, not at all, but a system like the one you propose could penalize a company or developer that has been delivering code without problems for years but that, in the latest update,… Continue Reading →

Comment on The Plugin Check Plugin now creates automatic security reports after each plugin update by Sarankumar

That’s a great move! When the PCP Checker was released, it helped us a lot in identifying and fixing issues across all the plugins we develop for WordPress and WooCommerce. We’d love to see even stricter security checks built into… Continue Reading →

Attackers Actively Exploiting Critical Vulnerability in WP Freeio Plugin

On September 25th, 2025, we received a submission for a Privilege Escalation vulnerability in WP Freeio, a WordPress plugin bundled in the Freeio premium theme with more than 1,700 sales. This vulnerability makes it possible for an unauthenticated attacker to… Continue Reading →

Comment on The Plugin Check Plugin now creates automatic security reports after each plugin update by Amber Hinds

I’d be interested in seeing public badges or data on plugin pages at some point that make this more transparent for users when comparing plugins. Even if it’s just flagging in the positive – something like X past releases with… Continue Reading →

The Plugin Check Plugin now creates automatic security reports after each plugin update

As an important part of the internet, the WordPress community, actively thinks about the security of the ecosystem. Community members, developers, specialized companies, and independent researchers all play a role in maintaining the security of the environment. In the Plugins… Continue Reading →

Rogue WordPress Plugin Conceals Multi-Tiered Credit Card Skimmers in Fake PNG Files

The Wordfence Threat Intelligence Team recently discovered a sophisticated malware campaign targeting WordPress e-commerce sites, specifically those using the WooCommerce plugin. This malware exhibits advanced features including custom encryption methods, fake images used to conceal malicious payloads, a robust persistence… Continue Reading →

100,000 WordPress Sites Affected by Arbitrary File Read Vulnerability in Anti-Malware Security and Brute-Force Firewall WordPress Plugin

On October 3rd, 2025, we received a submission for an Arbitrary File Read vulnerability in Anti-Malware Security and Brute-Force Firewall, a WordPress plugin with more than 100,000 active installations. This vulnerability makes it possible for an authenticated attacker, with subscriber-level… Continue Reading →

Plugin Pulse: WP Plugins A to Z Unplugged #3

A WPProAtoZHost.com Company…. I am Talking about unpopular ideas in WordPress today and I have a New Plugin review, some News tips, plugin extras and more all coming up on Plugin Pulse: WP Plugins A to Z Unplugged. The post… Continue Reading →

Podcast E609 – Using GeoIP

This week I Talk About Using GeoIP [powerpress]

Podcast E608 – When To Say Yes, No or Maybe

This week I Talk About Saying Yes, No, Maybe [powerpress]

How To Create A Carousel In Divi 5 (Without Extra Plugins)

Carousels are a design element that almost every site needs, whether it’s for products, testimonials, or client logos. In the past, Divi users often relied on third-party plugins or custom code to achieve their desired results. With Divi 5, that’s… Continue Reading →

Turbocharge Your Site: WPPlugins AtoZ Drops Plugin Gold!

A WPProAtoZHost.com Company…. It’s Episode 659 and we have plugins for Actively Logging with TweakMaster, and some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post Turbocharge Your Site: WPPlugins AtoZ Drops Plugin Gold! appeared first on… Continue Reading →

Podcast E606 – Shutdowns & Opportunity

This week I Talk About How Shut Downs Could Equal Opportunity [powerpress]

How to Find Local File Inclusion (LFI) Vulnerabilities in WordPress Plugins and Themes

Local File Inclusion (LFI) occurs when user-controlled input is used to build a path to a file that is then included by the application. In WordPress (and PHP web applications in general), this means values from $_GET, $_POST, $_REQUEST, or… Continue Reading →

Rev Up Your Website: WPPluginsAtoZ’s Hottest Plugin Finds!

A WPProAtoZHost.com Company…. It’s Episode 658 and we have plugins for WebP Conversion with some Charades thrown in, and some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post Rev Up Your Website: WPPluginsAtoZ’s Hottest Plugin Finds!… Continue Reading →

Podcast E605 – GEO vs SEO

This week I Talk About GEO vs SEO [powerpress]

Podcast E604 – Interview with Miriam Schwab

This week I Interviewed Miriam Schwab [powerpress]

Supercharge Your WP Game: WP Plugins A to Z’s Plugin Extravaganza!

A WPProAtoZHost.com Company…. It’s Episode 657 and we have plugins for Public Previewing while Working on SEO, and some WordPress News. It’s all coming up on WordPress Plugins A-Z! The post Supercharge Your WP Game: WP Plugins A to Z’s… Continue Reading →

Podcast E603 – Website Build Times

This week I Talk About Website Build Times [powerpress]

The 5 Best WordPress Subscription Plugins For Recurring Revenue

Want to wake up to sales every morning? These 5 WordPress subscription plugins help you turn one-time buyers into loyal, paying subscribers. Whether you run a digital store, membership site, or online service, this roundup shows you how to unlock… Continue Reading →

The Price of ‘Free’: How Nulled Plugins Are Used to Weaken Your Defense

The Wordfence Threat Intelligence Team has discovered a new malware campaign that highlights the hidden risks associated with “nulled plugins”, or premium plugins that have been tampered with by third parties. This campaign is particularly concerning because it doesn’t just… Continue Reading →

« Older posts

© 2025 WP News Desk — Powered by WordPress and WP RSS Aggregator | Hosted by WP Engine

Up ↑