Sign in

The WordPress Guy

@wpguy.uk
1.2K followers 906 following 464 posts

#ActuallyAutistic WordPress developer specialising in forensic troubleshooting, security and performance. 20 years experience. 🏴󠁧󠁢󠁳󠁣󠁴󠁿 Political commentator at @bylines.scot

PostsRepliesMedia
The WordPress Guy @wpguy.uk · 24/09/2026
wpguy.uk
WordPress Core Flaw Scores 9.2: Patch Your Site Now
A flaw confirmed in WordPress core, in the software itself, means an attacker can read files from your server or execute malicious code without ever needing a username or password. No brute-force
000
The WordPress Guy @wpguy.uk · 23/09/2026
wpguy.uk
WordPress 6.7.2: Critical RCE Patch You Must Apply Now
Remote code execution means an attacker can run their own code on your web server without needing a username or a password. No login credentials, no weak password to guess, no employee to trick into
010
The WordPress Guy @wpguy.uk · 22/09/2026
wpguy.uk
eBay Grants for WooCommerce Sellers: Up to £200,000
Running a WooCommerce store and selling on eBay at the same time is a reasonable multi-channel strategy, but it creates a persistent operational problem: keeping product data, inventory counts, and
000
The WordPress Guy @wpguy.uk · 16/09/2026
wpguy.uk
The Events Calendar Plugin: Critical 9.8 Vulnerability
Over 600,000 websites running The Events Calendar plugin are currently exposed to a pair of vulnerabilities that allow an anonymous attacker to take complete control of a WordPress site without
000
The WordPress Guy @wpguy.uk · 15/09/2026
wpguy.uk
WooCommerce CVE-2026-48888: Update to 11.1.0 Now
If your business runs WooCommerce, a high-severity vulnerability is sitting in your store right now unless you have already updated to version 11.1.0. An attacker who finds your site before you patch
000
The WordPress Guy @wpguy.uk · 10/09/2026
wpguy.uk
Cut Delivery Costs with Locker Options in WooCommerce
Every WooCommerce store owner I speak to has an opinion on carrier rates. Most of them are watching the per-parcel price closely, renegotiating contracts, switching between couriers to shave pennies
000
The WordPress Guy @wpguy.uk · 09/09/2026
wpguy.uk
Prepare Your WooCommerce Store for TikTok Shop EU Launch
Running a WooCommerce store and selling on TikTok Shop already puts you ahead of most UK retailers. The next question is whether you will be positioned to sell into Europe when TikTok opens its Sell
000
The WordPress Guy @wpguy.uk · 08/09/2026
wpguy.uk
Critical WordPress Backup Plugin Flaw Risks Site Takeover
If your business uses WordPress, there is a reasonable chance your site is running the All-in-One WP Migration and Backup plugin. With over five million active installations, it is one of the most
000
The WordPress Guy @wpguy.uk · 07/09/2026
wpguy.uk
WooCommerce CVE-2026-57777: Fix Privilege Escalation Now
A vulnerability in WooCommerce allows an attacker to escalate their privileges on your site. Any store running a version below 11.0 is exposed: a user with a low-level account, a free subscriber
000
The WordPress Guy @wpguy.uk · 03/09/2026
wpguy.uk
WordPress Plugin Vulnerabilities and Site Takeover Risks
Your website is an asset. To an attacker, it is also infrastructure. When a critical vulnerability surfaces in a widely-used WordPress plugin, criminal operators do not wait weeks to act — they scan,
010
The WordPress Guy @wpguy.uk · 02/09/2026
wpguy.uk
EU Customs Duty 2026: Prepare Your WooCommerce Store Now
From 1 July 2026, every parcel you send to an EU customer carries a new per-tariff-line customs duty. The headline figure being discussed is €3 per line item. Send a customer three different products
000
The WordPress Guy @wpguy.uk · 01/09/2026
wpguy.uk
Amazon Pan-EU FBA Deadlines: What WooCommerce Sellers Need
If you sell via Amazon Pan-EU FBA and run a WooCommerce store alongside it, two deadlines are now sitting on your calendar whether you have noticed them yet or not. Amazon has introduced mandatory
000
The WordPress Guy @wpguy.uk · 31/08/2026
wpguy.uk
Critical Auth Bypass in WPMU DEV Dashboard Plugin
If you are running the WPMU DEV Dashboard plugin on your WordPress site, you are currently exposed to a confirmed authentication bypass vulnerability that requires no technical skill to exploit. An
000
The WordPress Guy @wpguy.uk · 27/08/2026
wpguy.uk
Avada RCE Vulnerability: Patch Now or Risk Full Takeover
If your website runs the Avada theme, a complete stranger on the internet can take full control of it right now without needing an account, a password, or any action from you or your staff. That is
000
The WordPress Guy @wpguy.uk · 26/08/2026
wpguy.uk
EU Customs Rules: What UK WooCommerce Stores Must Know
Black Friday generates exactly the kind of orders that will hurt you most under the EU's new customs rules. Multi-item baskets across different product categories, the natural result of a well-run
000
The WordPress Guy @wpguy.uk · 24/08/2026
wpguy.uk
Elementor Pro File Upload Vulnerability: Patch Now
If your site runs Elementor Pro and you have ever added a file upload field to a form, an attacker can take complete control of your site without holding an account, without guessing a password, and
000
The WordPress Guy @wpguy.uk · 20/08/2026
wpguy.uk
Side Income for Teachers: 10 Self-Employment Models
Many teachers reach a point where the salary feels fixed whilst the workload keeps climbing. Private tutoring is the obvious move, but it is one option among many. Teachers carry a set of
000
The WordPress Guy @wpguy.uk · 19/08/2026
wpguy.uk
EU Customs Charges 2026: What WooCommerce Sellers Must Do
From 1 July 2026, every item category shipped from the UK into the EU attracts a three euro customs charge. For WooCommerce stores dispatching volume into France and Germany, that cost compounds on
000
The WordPress Guy @wpguy.uk · 19/08/2026
wpguy.uk
EU Customs Charges 2026: What WooCommerce Sellers Must Do
From 1 July 2026, every item category shipped from the UK into the EU attracts a three euro customs charge. For WooCommerce stores dispatching volume into France and Germany, that cost compounds on
000
The WordPress Guy @wpguy.uk · 18/08/2026
wpguy.uk
Fluent Forms CVE-2026-18146: Update to 6.2.12 Now
If your site runs Fluent Forms and you have not updated it since 13 August 2026, an attacker may already be scanning for your installation. The [CVE-2026-18146
000
The WordPress Guy @wpguy.uk · 13/08/2026
wpguy.uk
UK Retail Shift: Why Your WooCommerce Store Must Perform
Physical retail for non-food goods is shrinking. [BRC July 2026 data](https://internetretailing.net/online-growth-offsets-weak-store-sales-as-uk-retail-growth-slows-in-july/) shows in-store non-food
000
The WordPress Guy @wpguy.uk · 12/08/2026
wpguy.uk
Royal Mail's Electric Fleet: Update Your WooCommerce Checkout
Your checkout is the last thing a customer sees before they commit. If your shipping options don't reflect how your business actually operates, you're leaving trust on the table at exactly the wrong
000
The WordPress Guy @wpguy.uk · 10/08/2026
wpguy.uk
How to Choose WordPress Plugins That Don't Slow You Down
Plugin selection is a commercial decision. Every plugin you install adds maintenance overhead, broadens your security exposure, and either contributes to or drains your site's performance. With [more
000
The WordPress Guy @wpguy.uk · 06/08/2026
wpguy.uk
WordPress 7.1: How to Prepare Before the August Release
The 19 August 2026 release date for WordPress 7.1 is fixed. WordCamp US is the backdrop, and the WordPress project has tied the release to that event, which means the timeline will not slip for
010
The WordPress Guy @wpguy.uk · 05/08/2026
wpguy.uk
Is Your WooCommerce Hosting Ready for AI-Driven Retail?
The infrastructure powering online retail is being rebuilt at a pace most store owners have not registered. AWS reported its fastest growth in 18 quarters in its most recent financial results, with
000
The WordPress Guy @wpguy.uk · 04/08/2026
wpguy.uk
wp2shell WordPress RCE Flaw: Check and Patch Now
Your WordPress site may already be compromised. If it runs any version from the 6.8.x, 6.9.x, or 7.0.x branches and has not been updated in the past few weeks, an attacker can take full
000
The WordPress Guy @wpguy.uk · 03/08/2026
wpguy.uk
Fluent Forms CVE-2026-16655: Update to 6.2.8 Now
If your site runs Fluent Forms and the plugin is below version 6.2.8, an attacker can exploit a confirmed vulnerability to manipulate or extract data from your site without needing administrative
000
The WordPress Guy @wpguy.uk · 30/07/2026
wpguy.uk
WP2Shell: Critical WordPress RCE Flaw Actively Exploited
Two critical vulnerabilities in WordPress Core, collectively known as WP2Shell, are being actively exploited right now. If your site is running WordPress 6.9.0 through 6.9.4, or 7.0.0 through 7.0.1,
000
The WordPress Guy @wpguy.uk · 28/07/2026
wpguy.uk
WooCommerce iPhone POS Now Live for UK Merchants
If you sell online through WooCommerce and also take money face-to-face at markets, pop-ups, or a physical location, you have probably dealt with the awkward reality of running two separate systems.
000
The WordPress Guy @wpguy.uk · 27/07/2026
wpguy.uk
WordPress 7.1: Security Flaw Puts 6.9–7.0.1 Sites at Risk
A major WordPress update lands on 19 August 2026, timed with WordCamp US 2026, and the beta cycle is already revealing exactly why this one deserves your attention before the release date arrives. If
000
The WordPress Guy @wpguy.uk · 23/07/2026
wpguy.uk
Grow Your WooCommerce Store With TikTok Shop Integration
TikTok contributed £10 billion to the UK economy in 2025 and supported 153,000 jobs, according to [a Public First and EY
000
The WordPress Guy @wpguy.uk · 22/07/2026
wpguy.uk
Google's EU Data Ruling: What WooCommerce Stores Must Know
If your WooCommerce store gets most of its traffic from Google Shopping and Google's AI-powered product discovery tools, you are building on ground that regulators are actively digging up. The
010
The WordPress Guy @wpguy.uk · 21/07/2026
wpguy.uk
wp2shell: Patch the WordPress RCE Flaw Now
A critical flaw in WordPress core was made public on 17 July 2026. If your site has not received the patch, an attacker can take full control of it without logging in, without exploiting a plugin,
000
The WordPress Guy @wpguy.uk · 20/07/2026
wpguy.uk
WordPress Security Vulnerabilities Fixed in Version 7.0.2
If your WordPress site is running version 6.8 or 6.9, two formally tracked security vulnerabilities were sitting in your codebase until 17 July 2026. One of them could give an attacker the ability to
000
The WordPress Guy @wpguy.uk · 16/07/2026
wpguy.uk
WordPress 7.1: What Business Sites Must Do Before August
The release date is fixed. WordPress 7.1 arrives on 19 August 2026, timed with WordCamp US, and the window between now and then is preparation time. If you run a business on WordPress and have not
000
The WordPress Guy @wpguy.uk · 15/07/2026
wpguy.uk
VAT Registration Guide for UK Self-Employed Business Owners
The VAT threshold sits at £90,000 of taxable turnover over any rolling 12-month period. Cross it, and registration becomes a legal requirement. If you expect to hit that figure within the next 30
000
The WordPress Guy @wpguy.uk · 13/07/2026
wpguy.uk
How Heatwaves Are Driving Shoppers Online to WooCommerce
UK high street footfall fell 6.2% year-on-year in June, against a 1.5% decline in May — a fourfold acceleration in a single month. [British Retail Consortium
000
The WordPress Guy @wpguy.uk · 08/07/2026
wpguy.uk
WordPress Plugin Vulnerabilities: What's At Stake in 2026
Over 250 new WordPress plugin vulnerabilities are disclosed every week. This is the normal operating condition of the WordPress plugin ecosystem in 2026, not a seasonal spike or the fallout from a
000
The WordPress Guy @wpguy.uk · 06/07/2026
wpguy.uk
WPForms, WPvivid & Smart Slider 3 Vulnerabilities Patched
If your WordPress site is running WPForms, WPvivid, or Smart Slider 3, and those plugins have not been updated in the past few weeks, your site is exposed to vulnerabilities publicly disclosed in
000
The WordPress Guy @wpguy.uk · 02/07/2026
wpguy.uk
Critical WordPress Plugin Flaws Enable Admin Takeover
Attackers run automated scans continuously, and when a flaw is disclosed, exploitation attempts begin within hours. In June 2026, several critical vulnerabilities in widely used WordPress plugins
010
The WordPress Guy @wpguy.uk · 01/07/2026
wpguy.uk
UK VAT Reform: What WooCommerce Sellers Need to Know
Up to £3.2 billion of UK online retail sales each year involve sellers who avoid VAT collection by falsely claiming to be UK-established. That figure comes from [independent economic
000
The WordPress Guy @wpguy.uk · 30/06/2026
wpguy.uk
WooCommerce vs Shopify POS: Can WooCommerce Handle Pop-Ups?
When a brand with a global following needs to open a physical store in days rather than weeks, platform choice stops being a technical question and becomes an operational one. Quadrant, the sports
000
The WordPress Guy @wpguy.uk · 29/06/2026
wpguy.uk
How Strict Returns Policies Hurt WooCommerce Sales
Your returns policy is visible to every shopper who visits your store. Whether they read it carefully or simply check that one exists, its presence or absence shapes whether they complete a purchase
000
The WordPress Guy @wpguy.uk · 25/06/2026
wpguy.uk
Why PCI Compliance Alone Won't Secure Your WooCommerce Store
A PCI DSS certificate on the wall does not mean your WooCommerce checkout is secure. It means you have met a minimum standard for handling cardholder data, and confusing those two things is one of
000
The WordPress Guy @wpguy.uk · 24/06/2026
wpguy.uk
EU €3 Customs Charge: What WooCommerce Sellers Must Know
From 1 July 2026, every parcel you ship from the UK to an EU customer valued at €150 or below will attract a €3 customs duty charge per item type. The VAT exemption that made low-value cross-border
000
The WordPress Guy @wpguy.uk · 23/06/2026
wpguy.uk
Critical WooCommerce Flaw CVE-2022-50972: Act Now
Any WooCommerce store running a version below 7.1.0 is currently exposed to a vulnerability with no available fix. An attacker who successfully exploits it can take full administrative control of the
000
The WordPress Guy @wpguy.uk · 22/06/2026
wpguy.uk
High Vulnerability in Really Simple Security – Simple and Performant Security (formerly Really Simple SSL): Really Simple Security — Simple and Performant Security (formerly Really Simple SSL) [
Any WordPress site running Really Simple Security below version 9.5.10.1 is currently exposed to an attacker who can exploit a high-severity vulnerability without needing administrative credentials.
020
The WordPress Guy @wpguy.uk · 18/06/2026
wpguy.uk
Your WordPress Email Plugin May Be Handing Attackers the Keys to Your Site
If your site uses Gravity SMTP to handle transactional email, it is exposed to an actively exploited vulnerability right now. The flaw, a Sensitive Information Exposure weakness in a plugin with an
021
The WordPress Guy @wpguy.uk · 17/06/2026
wpguy.uk
New UK Marketplace JoyBuy Opening to Third-Party Sellers: Should You List?
Every e-commerce business owner running a WooCommerce store faces the same recurring question: when a new marketplace opens, do you list, or do you protect your margins and stay focused on your own
000
The WordPress Guy @wpguy.uk · 16/06/2026
wpguy.uk
How WooCommerce Store Owners Can Offer 350,000 European Pickup Locations at Checkout
European shoppers have a clear preference: when given the choice, many will select a parcel locker or local pickup point over home delivery. If your WooCommerce checkout does not offer that choice, a
000