This update includes a fair number of security fixes found as the result of an external security audit. Kudos to the ACF team for having an external audit.

ACF Security Update 6.3.2
Liam Gladdy @ advancedcustomfields.com • 9 months ago
Liam Gladdy @ advancedcustomfields.com • 9 months ago
This update includes a fair number of security fixes found as the result of an external security audit. Kudos to the ACF team for having an external audit.
Jacklyn bBiggin @ developer.woocommerce.com • 9 months ago
WooCommerce XSS vulnerability notice. It has been patched, so there is an update available.
Vladimír Smitka @ smitka.me • 9 months ago
Here is part two of Vladimír Smitka’s series where he tested various Cloud panels for managing VPS. In this installment he looks at Enhance and FlyWP, which use Docker containers, and explains why they weren’t secure and explores some of the possible fixes.
Alexis Bryan @ solidwp.com • 9 months ago
Here’s a tutorial on how to clean a hacked site.
Elijah Mills @ oxygenbuilder.com • 10 months ago
Oxygen released version 4.8.3 which is a security update. The security issue addressed is a privilege escalation vulnerability that would allow a user with “contributor” or higher permissions to escalate their privileges to an admin (CVE-2024-4662). This issue impacts anyone that has granted untrusted users Contributor+ access to their WordPress website. It does not affect you if you do not have Contributor+ users on your WordPress website.
Joost De Valk @ poststatus.com • 10 months ago
Joost on the fear marketing of WordPress security.
Scott Kingsley Clark @ pods.io • 10 months ago
The latest version of Pods is a security release. Hotfixes for various Pods versions are available.
Roger Montti @ searchenginejournal.com • 11 months ago
Roger Montti of the Search Engine Journal asked WPScan and Wordfence what site owners need to know about medium level vulnerabilities?
Emil Tragardh @ youtube.com • 11 months ago
With the help of breakdance XSS any user can trick the admin user to execute PHP code without them knowing it. The code is written by the Editor (or any other user role) and later executed unknowingly by the administrator.