Skip to content
BaeWP

WordPress News & Coverage

Sunday, September 13, 2026
  • Home
Latest WordPress Open Weights AI Letter: What It Means for Site Owners

Tag: wordpress security

Security

What the TranslatePress Account Takeover Flaw Teaches WordPress Site Owners About Credential Safety

What happened with TranslatePress In August 2026, the security team at Wordfence disclosed an unauthenticated account takeover flaw in TranslatePress, the multilingual plugin with more than 400,000 active installations. A researcher using the handle momopon1415 (Yuto Hyakumoto) submitted the issue through the Wordfence Bug Bounty Program on August 11, 2026. The vendor, Cozmoslabs, acknowledged the […]

Aug 30, 2026 · 5 min read
Security

Critical Unauthenticated Authentication Bypass Vulnerability Patched in UpdraftPlus WordPress Plugin

A critical unauthenticated authentication bypass vulnerability in UpdraftPlus was patched in June 2026. This flaw allows attackers to execute arbitrary commands as administrators on sites connected to UpdraftCentral, risking full site compromise. Immediate plugin updates and firewall protections are essential.

Jul 8, 2026 · 6 min read
UpdraftPlus vulnerability
Security

Quarterly WordPress Threat Intelligence Report – Q1 2026

The Wordfence Q1 2026 Threat Intelligence Report highlights a 23.7% rise in WordPress vulnerabilities and a surge in attack attempts, underscoring the need for layered, real-time security strategies tailored to WordPress environments.

Jun 16, 2026 · 6 min read
WordPress vulnerabilities
Security

Unpatched SQL Injection Vulnerability Discovered in TI WooCommerce Wishlist Plugin

An unpatched SQL injection vulnerability in TI WooCommerce Wishlist plugin affects 100,000+ sites, allowing unauthenticated attackers to compromise WordPress databases.

May 17, 2026 · 5 min read
TI WooCommerce Wishlist vulnerability
Security

Critical Malware Campaign Exploits WP-Automatic Plugin Vulnerability in Over 5 Million Attacks

A critical SQL injection vulnerability in WP-Automatic plugin has led to over 5.5 million attack attempts, enabling attackers to gain admin access and upload malware.

May 17, 2026 · 5 min read
wp-automatic vulnerability
Security

Identifying Traffic from Shell Finder Bots Targeting WordPress Sites

Shell finder bots are scanning WordPress sites for backdoor shells, enabling attackers to maintain stealthy access. Recognizing and blocking these scans is vital for site security.

May 17, 2026 · 5 min read
wordpress shell finder bots
Security

Surge of JavaScript Malware Exploits Vulnerable LiteSpeed Cache Plugin Versions

A wave of JavaScript malware is exploiting vulnerable LiteSpeed Cache plugin versions below 5.7.0.1, injecting malicious code and creating unauthorized admin users.

May 17, 2026 · 5 min read
LiteSpeed Cache vulnerability

Browse Coverage

  • Community 170
  • Hosting 246
  • Industry 115
  • Jobs 1
  • Security 30
  • WordPress Core 101

Recent Stories

  1. 1 WordPress Open Weights AI Letter: What It Means for Site Owners
  2. 2 Should WordPress Site Owners Install the Official Browser Extension?
  3. 3 WordPress 7.1 Mary Lou Brings Client-Side Media, Responsive Styles, and an AI-Ready Abilities API
  4. 4 How to Evaluate AI Features in WordPress Before Using Them
  5. 5 How to Evaluate AI Features in WordPress Before Using Them

BaeWP

Covering WordPress core, security, hosting, and the ecosystem. Trusted by developers, agencies, and site owners worldwide.

Coverage

  • WordPress Core
  • Security
  • Hosting
  • Industry
  • Community
  • Jobs

Recent

  • WordPress Open Weights AI Letter: What It Means for Site Owners
  • Should WordPress Site Owners Install the Official Browser Extension?
  • WordPress 7.1 Mary Lou Brings Client-Side Media, Responsive Styles, and an AI-Ready Abilities API
  • How to Evaluate AI Features in WordPress Before Using Them
  • How to Evaluate AI Features in WordPress Before Using Them

Info

  • Home
© 2026 BaeWP. All rights reserved. Affiliate Disclosure