2025 midyear security report

2025 Mid-Year Vulnerability Report

Oliver Side @ patchstack.com • 2 weeks ago

Patchstack released a mid-year vulnerability report. There is some self-congratulation of their success as Patchstack now reports far more CVE’s than others in the WordPress space, but also now they apparently file more security issues than Microsoft. An interesting insight is that more than half of the vulnerabilities reported so far this year can be exploited without needing to hack credentials or have site access.

acf security update

ACF Releases Security Update

Liam Gladdy @ advancedcustomfields.com • 4 weeks ago

Advanced Custom Fields version 6.4.3 is now available. This release contains several security fixes for ACF and ACF PRO, including additional HTML escaping for field group labels, post titles, and Select2 elements to prevent JS vulnerabilities in the WordPress admin. These vulnerabilities all required an ACF admin user to save malicious HTML. For this reason, it’s important to only ever import ACF JSON files from trusted sources.