Tag: wordpress
71 articles
Security
Nearly Two-Thirds of All-in-One WP Migration Installs Remain Unpatched Two Weeks Later
Only 35 percent of All-in-One WP Migration installs run the 7.110 fix. About 3.2 million sites are on a vulnerable version as the exploit chain goes public.
Security
Attacks on the Elementor Pro Flaw Began the Day It Was Disclosed
Exploit attempts against the Elementor Pro file upload flaw began the day it was disclosed, and one firewall alone blocked over 190,000 of them.
Security
A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
High-severity fixes for All-in-One WP Migration and Gravity Forms shipped August 20. One changelog called it a text fix, the other used a stock phrase.
Security
InMotion Rolls Out Monarx ThreatShield Inside the PHP Engine Across Its Fleet
InMotion is deploying Monarx ThreatShield across its server fleet, moving attack blocking into the PHP engine itself.
Events
What WebHosting.Today Learned at WordCamp US 2026
Four companies at WordCamp US split on how far AI should go, and two of them want two-factor authentication built into WordPress core.
Security
Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days
Forminator's 9.8 file upload flaw was patched seventeen days before it went public, and the changelog shows eleven more fixes around it.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
WordPress 7.0.4 fixes a flaw where an image hiding PostScript runs code on the server. It needs an author account, and multi-author sites should hurry.
Industry reports
Google’s Field Data Ranks the Platforms Behind Live Sites by Speed, and the Gap Is More Than Twofold
Google's field data, broken out by host: Wix customers pass Core Web Vitals at 80%, HostGator's at 39%. A measured speed ranking for the industry.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
An AI model found the WordPress core flaw in ten hours for about $25. After 7.0.2 shipped, attacks started 90 minutes later. WordPress 7.0.3 is out.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
WordPress did the rare thing and forced a core security fix to millions of sites. Within 72 hours the break-ins started anyway. The gap is the story.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
700articles