wordpress
9 stories and discussions about wordpress, aggregated from every source we track.
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for ...
I thought I understood WordPress theme development because I knew HTML, CSS, PHP, templates, and the...
Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into
How we build VolunteerPress with AI, the checks every change has to pass, and the bug those checks...
<p>Other parts of the series:</p> <ul> <li><a href="https://spin0r.wordpress.com/2012/12/16/terminally-confused-part-one/" rel="ugc">https://spin0r.wordpress.com/2012/12/16/terminally-confused-part-one/</a></li> <li><a href="https://spin0r.wordpress.com/2012/12/16/terminally-confused-part-two/" rel="ugc">https://spin0r.wordpress.com/2012/12/16/terminally-confused-part-two/</a></li> <li><a href="https://spin0r.wordpress.com/2012/12/22/terminally-confused-part-three/" rel="ugc">https://spin0r.wordpress.com/2012/12/22/terminally-confused-part-three/</a></li> <li><a href="https://spin0r.wordpress.com/2012/12/23/terminally-confused-part-four/" rel="ugc">https://spin0r.wordpress.com/2012/12/23/terminally-confused-part-four/</a></li> <li><a href="https://spin0r.wordpress.com/2012/12/24/terminally-confused-part-five/" rel="ugc">https://spin0r.wordpress.com/2012/12/24/terminally-confused-part-five/</a></li> <li><a href="https://spin0r.wordpress.com/2012/12/25/terminally-confused-part-six/" rel="ugc">https://spin0r.wordpress.com/2012/12/25/terminally-confused-part-six/</a></li> <li><a href="https://spin0r.wordpress.com/2012/12/28/terminally-confused-part-seven/" rel="ugc">https://spin0r.wordpress.com/2012/12/28/terminally-confused-part-seven/</a></li> </ul>
Given that these departed board members were those who voted to put Mullenweg on a paid leave of absence to begin with, it makes sense that a board shakeup has taken place.
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
A technical breakdown of using a local AI model + RAG to convert static HTML sites into installable...
A blog about JavaScript, software development, Startup life and everything in between.