WordPress Site Monitoring: What We Actually Watch
Most WordPress maintenance providers monitor 4 to 6 things, mostly unverified. Here is the full stack we run on every site we manage, and the real example that shows why it matters.
Read MoreCard Testing Attack? How to Spot and Stop It on Your Store
TL;DR Card testing is a bot running stolen card numbers through your checkout to find out which ones still work. It is not trying to buy anything from you. The giveaway is a burst of declined orders with fake names, fake emails, and the same small charge amount hit over and over. Every declined attempt…
Read MoreWhat a Real WordPress Site Attack Looks Like (And How We Stopped It)
Most articles about WordPress security talk in generalities: keep your plugins updated, use strong passwords, install a firewall. This post is different. This is a real WordPress site attack that hit one of our client sites on July 13, 2026, told with the actual numbers, the actual IP addresses, and the actual fixes we deployed…
Read MoreWordPress 500 Internal Server Error: What It Means and How to Fix It
TL;DR A WordPress 500 Internal Server Error means the server hit an unexpected problem but won’t tell you what it was. The most common causes are a corrupted .htaccess file, a misbehaving plugin, or a PHP memory limit. To fix it: rename your .htaccess file, deactivate all plugins via FTP, or increase your PHP memory…
Read MoreYoast SEO – Advanced SEO with real-time guidance and built-in AI Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via ‘jsonText’ Block Attribute – CVE-2026-3427 | WordPress Plugin Vulnerability Report
Plugin Name: Yoast SEO – Advanced SEO with real-time guidance and built-in AI Key Information: Software Type: PluginSoftware Slug: wordpress-seoSoftware Status: ActiveSoftware Author: yoastSoftware Downloads: 930,902,675Active Installs: 10,000,000Last Updated: March 22, 2026Patched Versions: 27.2Affected Versions: <= 27.1.1 Vulnerability Details: Name: Yoast SEO <= 27.1.1Title: Authenticated (Contributor+) Stored Cross-Site Scripting via ‘jsonText’ Block AttributeType: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NCVE: CVE-2026-3427CVSS…
Read MoreThe Events Calendar Vulnerability – Missing Authorization to Authenticated (Subscriber+) Data Migration Control – CVE-2025-15043 | WordPress Plugin Vulnerability Report
Plugin Name: The Events Calendar Key Information Software Type: PluginSoftware Slug: the-events-calendarSoftware Status: ActiveSoftware Author: stellarwpSoftware Downloads: 78,686,265Active Installs: 700,000Last Updated: January 22, 2026Patched Versions: 6.15.13.1Affected Versions: ≤ 6.15.13 Vulnerability Details Name: The Events Calendar ≤ 6.15.13 – Missing Authorization to Authenticated Data Migration ControlTitle: Missing Authorization to Authenticated (Subscriber+) Data Migration ControlType: Missing Authorization…
Read MoreNewsletter – Send awesome emails from WordPress Vulnerability – Cross-Site Request Forgery to Newsletter Unsubscription – CVE-2026-1051 | WordPress Plugin Vulnerability Report
Plugin Name: Newsletter – Send awesome emails from WordPress Key Information Software Type: PluginSoftware Slug: newsletterSoftware Status: ActiveSoftware Author: satolloSoftware Downloads: 32,725,200 Active Installs: 300,000 Last Updated: January 20, 2026 Patched Versions: 9.1.1 Affected Versions: ≤ 9.1.0 Vulnerability Details Name: Newsletter – Send awesome emails from WordPress ≤ 9.1.0 Title: Cross-Site Request Forgery to Newsletter UnsubscriptionType:…
Read MoreCustom Fonts – Host Your Fonts Locally Vulnerability – Missing Authorization to Unauthenticated Font Deletion – CVE-2025-14351 | WordPress Plugin Vulnerability Report
Plugin Name: Custom Fonts – Host Your Fonts Locally Key Information Software Type: PluginSoftware Slug: custom-fontsSoftware Status: ActiveSoftware Author: brainstormforceSoftware Downloads: 6,158,177Active Installs: 300,000Last Updated: January 22, 2026Patched Versions: 2.1.17Affected Versions: ≤ 2.1.16 Vulnerability Details Name: Custom Fonts – Host Your Fonts Locally ≤ 2.1.16 Title: Missing Authorization to Unauthenticated Font DeletionType: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NCVE: CVE-2025-14351CVSS Score: 5.3Publicly…
Read MoreEssential Addons for Elementor – Popular Elementor Templates & Widgets Vulnerability – Missing Authorization to Unauthenticated Sensitive Information Exposure – CVE-2026-1004 | WordPress Plugin Vulnerability Report
Plugin Name: Essential Addons for Elementor – Popular Elementor Templates & Widgets Key Information Software Type: PluginSoftware Slug: essential-addons-for-elementor-liteSoftware Status: ActiveSoftware Author: wpdevteamSoftware Downloads: 117,159,772Active Installs: 2,000,000Last Updated: January 22, 2026Patched Versions: 6.5.6Affected Versions: ≤ 6.5.5 Vulnerability Details Name: Essential Addons for Elementor ≤ 6.5.5 – Missing Authorization to Unauthenticated Sensitive Information ExposureTitle: Missing Authorization…
Read MoreAll in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Vulnerability – Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure – CVE-2025-14384 | WordPress Plugin Vulnerability Report
Plugin Name: All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Key Information: Software Type: PluginSoftware Slug: all-in-one-seo-packSoftware Status: PatchedSoftware Author: smubSoftware Downloads: 196,420,959Active Installs: 3,000,000Last Updated: January 16, 2026Patched Versions: 4.9.3Affected Versions: ≤ 4.9.2 Vulnerability Details: Name: All in One SEO – Powerful SEO Plugin to Boost SEO…
Read More