
Rank Math Created an Admin Password on 4 Million Sites. Check What Else Has One.
Rank Math's paused Support Agent created a WordPress Application Password without asking. Here is how to audit every credential on your site.
14 articles about Security from the team building MagicWP.

Rank Math's paused Support Agent created a WordPress Application Password without asking. Here is how to audit every credential on your site.

CVE-2026-18978 lets unmoderated comments inject scripts on LiteSpeed Cache sites up to 7.8.1. Update to 7.9 and check two settings.

Two miniOrange SAML SSO flaws let anyone log in as admin. Paid editions read as patched because seven version lines share one plugin slug.

Avada 7.16.1 fixes a remote code execution flaw in the Fusion Patcher. What is confirmed, what is not, and how to check and update every Avada site you run.

TranslatePress 3.3.4 patches an unauthenticated flaw reachable from the comment form. Here is who is affected, what to check, and how to clean up.

Elementor Pro 4.2.1 and below let anonymous visitors upload PHP through a form field. Update to 4.2.2, then check your uploads folder.

CVE-2026-19598 lets unauthenticated attackers take over sites running Pods 2.8 through 3.3.9. How to check your version, patch it, and look for damage.

Elementor Pro 4.2.1 and below let anonymous visitors upload PHP through the Forms file field. Update to 4.2.2 and check your uploads directory.

CVE-2026-15748 lets unauthenticated attackers upload PHP files through Forminator. Check whether your forms are exposed and which version really patches it.

WordPress still has no built-in 2FA in 2026. Here's how to set it up properly, which method to pick, and what 2FA genuinely can't protect.

WordPress 7.0.4 patches CVE-2026-65640, an Author-level RCE on servers using Imagick and Ghostscript. How to check your exposure and update safely.

CVE-2026-64638 is a pre-auth reflected XSS on the WordPress login screen that can escalate to PHP execution. Here is who is affected and how to fix it.

A backdoored WordPress plugin was caught within about two hours of publication. Here's what the code did, and why it barely spread.

wp2shell is a pre-auth RCE chain in WordPress core (CVE-2026-63030 + CVE-2026-60137). Here's what it is, who's affected, and how to protect your site.