The WordPress Guy @wpguy.uk · 24/09/2026wpguy.ukWordPress Core Flaw Scores 9.2: Patch Your Site NowA flaw confirmed in WordPress core, in the software itself, means an attacker can read files from your server or execute malicious code without ever needing a username or password. No brute-force 000
The WordPress Guy @wpguy.uk · 23/09/2026wpguy.ukWordPress 6.7.2: Critical RCE Patch You Must Apply NowRemote code execution means an attacker can run their own code on your web server without needing a username or a password. No login credentials, no weak password to guess, no employee to trick into 010
The WordPress Guy @wpguy.uk · 22/09/2026wpguy.ukeBay Grants for WooCommerce Sellers: Up to £200,000Running a WooCommerce store and selling on eBay at the same time is a reasonable multi-channel strategy, but it creates a persistent operational problem: keeping product data, inventory counts, and 000
The WordPress Guy @wpguy.uk · 16/09/2026wpguy.ukThe Events Calendar Plugin: Critical 9.8 VulnerabilityOver 600,000 websites running The Events Calendar plugin are currently exposed to a pair of vulnerabilities that allow an anonymous attacker to take complete control of a WordPress site without 000
The WordPress Guy @wpguy.uk · 15/09/2026wpguy.ukWooCommerce CVE-2026-48888: Update to 11.1.0 NowIf your business runs WooCommerce, a high-severity vulnerability is sitting in your store right now unless you have already updated to version 11.1.0. An attacker who finds your site before you patch 000
The WordPress Guy @wpguy.uk · 10/09/2026wpguy.ukCut Delivery Costs with Locker Options in WooCommerceEvery WooCommerce store owner I speak to has an opinion on carrier rates. Most of them are watching the per-parcel price closely, renegotiating contracts, switching between couriers to shave pennies 000
The WordPress Guy @wpguy.uk · 09/09/2026wpguy.ukPrepare Your WooCommerce Store for TikTok Shop EU LaunchRunning a WooCommerce store and selling on TikTok Shop already puts you ahead of most UK retailers. The next question is whether you will be positioned to sell into Europe when TikTok opens its Sell 000
The WordPress Guy @wpguy.uk · 08/09/2026wpguy.ukCritical WordPress Backup Plugin Flaw Risks Site TakeoverIf your business uses WordPress, there is a reasonable chance your site is running the All-in-One WP Migration and Backup plugin. With over five million active installations, it is one of the most 000
The WordPress Guy @wpguy.uk · 07/09/2026wpguy.ukWooCommerce CVE-2026-57777: Fix Privilege Escalation NowA vulnerability in WooCommerce allows an attacker to escalate their privileges on your site. Any store running a version below 11.0 is exposed: a user with a low-level account, a free subscriber 000
The WordPress Guy @wpguy.uk · 03/09/2026wpguy.ukWordPress Plugin Vulnerabilities and Site Takeover RisksYour website is an asset. To an attacker, it is also infrastructure. When a critical vulnerability surfaces in a widely-used WordPress plugin, criminal operators do not wait weeks to act — they scan, 010
The WordPress Guy @wpguy.uk · 02/09/2026wpguy.ukEU Customs Duty 2026: Prepare Your WooCommerce Store NowFrom 1 July 2026, every parcel you send to an EU customer carries a new per-tariff-line customs duty. The headline figure being discussed is €3 per line item. Send a customer three different products 000
The WordPress Guy @wpguy.uk · 01/09/2026wpguy.ukAmazon Pan-EU FBA Deadlines: What WooCommerce Sellers NeedIf you sell via Amazon Pan-EU FBA and run a WooCommerce store alongside it, two deadlines are now sitting on your calendar whether you have noticed them yet or not. Amazon has introduced mandatory 000
The WordPress Guy @wpguy.uk · 31/08/2026wpguy.ukCritical Auth Bypass in WPMU DEV Dashboard PluginIf you are running the WPMU DEV Dashboard plugin on your WordPress site, you are currently exposed to a confirmed authentication bypass vulnerability that requires no technical skill to exploit. An 000
The WordPress Guy @wpguy.uk · 27/08/2026wpguy.ukAvada RCE Vulnerability: Patch Now or Risk Full TakeoverIf your website runs the Avada theme, a complete stranger on the internet can take full control of it right now without needing an account, a password, or any action from you or your staff. That is 000
The WordPress Guy @wpguy.uk · 26/08/2026wpguy.ukEU Customs Rules: What UK WooCommerce Stores Must KnowBlack Friday generates exactly the kind of orders that will hurt you most under the EU's new customs rules. Multi-item baskets across different product categories, the natural result of a well-run 000
The WordPress Guy @wpguy.uk · 24/08/2026wpguy.ukElementor Pro File Upload Vulnerability: Patch NowIf your site runs Elementor Pro and you have ever added a file upload field to a form, an attacker can take complete control of your site without holding an account, without guessing a password, and 000
The WordPress Guy @wpguy.uk · 20/08/2026wpguy.ukSide Income for Teachers: 10 Self-Employment ModelsMany teachers reach a point where the salary feels fixed whilst the workload keeps climbing. Private tutoring is the obvious move, but it is one option among many. Teachers carry a set of 000
The WordPress Guy @wpguy.uk · 19/08/2026wpguy.ukEU Customs Charges 2026: What WooCommerce Sellers Must DoFrom 1 July 2026, every item category shipped from the UK into the EU attracts a three euro customs charge. For WooCommerce stores dispatching volume into France and Germany, that cost compounds on 000
The WordPress Guy @wpguy.uk · 19/08/2026wpguy.ukEU Customs Charges 2026: What WooCommerce Sellers Must DoFrom 1 July 2026, every item category shipped from the UK into the EU attracts a three euro customs charge. For WooCommerce stores dispatching volume into France and Germany, that cost compounds on 000
The WordPress Guy @wpguy.uk · 18/08/2026wpguy.ukFluent Forms CVE-2026-18146: Update to 6.2.12 NowIf your site runs Fluent Forms and you have not updated it since 13 August 2026, an attacker may already be scanning for your installation. The [CVE-2026-18146 000
The WordPress Guy @wpguy.uk · 13/08/2026wpguy.ukUK Retail Shift: Why Your WooCommerce Store Must PerformPhysical retail for non-food goods is shrinking. [BRC July 2026 data](https://internetretailing.net/online-growth-offsets-weak-store-sales-as-uk-retail-growth-slows-in-july/) shows in-store non-food 000
The WordPress Guy @wpguy.uk · 12/08/2026wpguy.ukRoyal Mail's Electric Fleet: Update Your WooCommerce CheckoutYour checkout is the last thing a customer sees before they commit. If your shipping options don't reflect how your business actually operates, you're leaving trust on the table at exactly the wrong 000
The WordPress Guy @wpguy.uk · 10/08/2026wpguy.ukHow to Choose WordPress Plugins That Don't Slow You DownPlugin selection is a commercial decision. Every plugin you install adds maintenance overhead, broadens your security exposure, and either contributes to or drains your site's performance. With [more 000
The WordPress Guy @wpguy.uk · 06/08/2026wpguy.ukWordPress 7.1: How to Prepare Before the August ReleaseThe 19 August 2026 release date for WordPress 7.1 is fixed. WordCamp US is the backdrop, and the WordPress project has tied the release to that event, which means the timeline will not slip for 010
The WordPress Guy @wpguy.uk · 05/08/2026wpguy.ukIs Your WooCommerce Hosting Ready for AI-Driven Retail?The infrastructure powering online retail is being rebuilt at a pace most store owners have not registered. AWS reported its fastest growth in 18 quarters in its most recent financial results, with 000
The WordPress Guy @wpguy.uk · 04/08/2026wpguy.ukwp2shell WordPress RCE Flaw: Check and Patch NowYour WordPress site may already be compromised. If it runs any version from the 6.8.x, 6.9.x, or 7.0.x branches and has not been updated in the past few weeks, an attacker can take full 000
The WordPress Guy @wpguy.uk · 03/08/2026wpguy.ukFluent Forms CVE-2026-16655: Update to 6.2.8 NowIf your site runs Fluent Forms and the plugin is below version 6.2.8, an attacker can exploit a confirmed vulnerability to manipulate or extract data from your site without needing administrative 000
The WordPress Guy @wpguy.uk · 30/07/2026wpguy.ukWP2Shell: Critical WordPress RCE Flaw Actively ExploitedTwo critical vulnerabilities in WordPress Core, collectively known as WP2Shell, are being actively exploited right now. If your site is running WordPress 6.9.0 through 6.9.4, or 7.0.0 through 7.0.1, 000
The WordPress Guy @wpguy.uk · 28/07/2026wpguy.ukWooCommerce iPhone POS Now Live for UK MerchantsIf you sell online through WooCommerce and also take money face-to-face at markets, pop-ups, or a physical location, you have probably dealt with the awkward reality of running two separate systems. 000
The WordPress Guy @wpguy.uk · 27/07/2026wpguy.ukWordPress 7.1: Security Flaw Puts 6.9–7.0.1 Sites at RiskA major WordPress update lands on 19 August 2026, timed with WordCamp US 2026, and the beta cycle is already revealing exactly why this one deserves your attention before the release date arrives. If 000
The WordPress Guy @wpguy.uk · 23/07/2026wpguy.ukGrow Your WooCommerce Store With TikTok Shop IntegrationTikTok contributed £10 billion to the UK economy in 2025 and supported 153,000 jobs, according to [a Public First and EY 000
The WordPress Guy @wpguy.uk · 22/07/2026wpguy.ukGoogle's EU Data Ruling: What WooCommerce Stores Must KnowIf your WooCommerce store gets most of its traffic from Google Shopping and Google's AI-powered product discovery tools, you are building on ground that regulators are actively digging up. The 010
The WordPress Guy @wpguy.uk · 21/07/2026wpguy.ukwp2shell: Patch the WordPress RCE Flaw NowA critical flaw in WordPress core was made public on 17 July 2026. If your site has not received the patch, an attacker can take full control of it without logging in, without exploiting a plugin, 000
The WordPress Guy @wpguy.uk · 20/07/2026wpguy.ukWordPress Security Vulnerabilities Fixed in Version 7.0.2If your WordPress site is running version 6.8 or 6.9, two formally tracked security vulnerabilities were sitting in your codebase until 17 July 2026. One of them could give an attacker the ability to 000
The WordPress Guy @wpguy.uk · 16/07/2026wpguy.ukWordPress 7.1: What Business Sites Must Do Before AugustThe release date is fixed. WordPress 7.1 arrives on 19 August 2026, timed with WordCamp US, and the window between now and then is preparation time. If you run a business on WordPress and have not 000
The WordPress Guy @wpguy.uk · 15/07/2026wpguy.ukVAT Registration Guide for UK Self-Employed Business OwnersThe VAT threshold sits at £90,000 of taxable turnover over any rolling 12-month period. Cross it, and registration becomes a legal requirement. If you expect to hit that figure within the next 30 000
The WordPress Guy @wpguy.uk · 13/07/2026wpguy.ukHow Heatwaves Are Driving Shoppers Online to WooCommerceUK high street footfall fell 6.2% year-on-year in June, against a 1.5% decline in May — a fourfold acceleration in a single month. [British Retail Consortium 000
The WordPress Guy @wpguy.uk · 08/07/2026wpguy.ukWordPress Plugin Vulnerabilities: What's At Stake in 2026Over 250 new WordPress plugin vulnerabilities are disclosed every week. This is the normal operating condition of the WordPress plugin ecosystem in 2026, not a seasonal spike or the fallout from a 000
The WordPress Guy @wpguy.uk · 06/07/2026wpguy.ukWPForms, WPvivid & Smart Slider 3 Vulnerabilities PatchedIf your WordPress site is running WPForms, WPvivid, or Smart Slider 3, and those plugins have not been updated in the past few weeks, your site is exposed to vulnerabilities publicly disclosed in 000
The WordPress Guy @wpguy.uk · 02/07/2026wpguy.ukCritical WordPress Plugin Flaws Enable Admin TakeoverAttackers run automated scans continuously, and when a flaw is disclosed, exploitation attempts begin within hours. In June 2026, several critical vulnerabilities in widely used WordPress plugins 010
The WordPress Guy @wpguy.uk · 01/07/2026wpguy.ukUK VAT Reform: What WooCommerce Sellers Need to KnowUp to £3.2 billion of UK online retail sales each year involve sellers who avoid VAT collection by falsely claiming to be UK-established. That figure comes from [independent economic 000
The WordPress Guy @wpguy.uk · 30/06/2026wpguy.ukWooCommerce vs Shopify POS: Can WooCommerce Handle Pop-Ups?When a brand with a global following needs to open a physical store in days rather than weeks, platform choice stops being a technical question and becomes an operational one. Quadrant, the sports 000
The WordPress Guy @wpguy.uk · 29/06/2026wpguy.ukHow Strict Returns Policies Hurt WooCommerce SalesYour returns policy is visible to every shopper who visits your store. Whether they read it carefully or simply check that one exists, its presence or absence shapes whether they complete a purchase 000
The WordPress Guy @wpguy.uk · 25/06/2026wpguy.ukWhy PCI Compliance Alone Won't Secure Your WooCommerce StoreA PCI DSS certificate on the wall does not mean your WooCommerce checkout is secure. It means you have met a minimum standard for handling cardholder data, and confusing those two things is one of 000
The WordPress Guy @wpguy.uk · 24/06/2026wpguy.ukEU €3 Customs Charge: What WooCommerce Sellers Must KnowFrom 1 July 2026, every parcel you ship from the UK to an EU customer valued at €150 or below will attract a €3 customs duty charge per item type. The VAT exemption that made low-value cross-border 000
The WordPress Guy @wpguy.uk · 23/06/2026wpguy.ukCritical WooCommerce Flaw CVE-2022-50972: Act NowAny WooCommerce store running a version below 7.1.0 is currently exposed to a vulnerability with no available fix. An attacker who successfully exploits it can take full administrative control of the 000
The WordPress Guy @wpguy.uk · 22/06/2026wpguy.ukHigh Vulnerability in Really Simple Security – Simple and Performant Security (formerly Really Simple SSL): Really Simple Security — Simple and Performant Security (formerly Really Simple SSL) [Any WordPress site running Really Simple Security below version 9.5.10.1 is currently exposed to an attacker who can exploit a high-severity vulnerability without needing administrative credentials. 020
The WordPress Guy @wpguy.uk · 18/06/2026wpguy.ukYour WordPress Email Plugin May Be Handing Attackers the Keys to Your SiteIf your site uses Gravity SMTP to handle transactional email, it is exposed to an actively exploited vulnerability right now. The flaw, a Sensitive Information Exposure weakness in a plugin with an 021
The WordPress Guy @wpguy.uk · 17/06/2026wpguy.ukNew UK Marketplace JoyBuy Opening to Third-Party Sellers: Should You List?Every e-commerce business owner running a WooCommerce store faces the same recurring question: when a new marketplace opens, do you list, or do you protect your margins and stay focused on your own 000
The WordPress Guy @wpguy.uk · 16/06/2026wpguy.ukHow WooCommerce Store Owners Can Offer 350,000 European Pickup Locations at CheckoutEuropean shoppers have a clear preference: when given the choice, many will select a parcel locker or local pickup point over home delivery. If your WooCommerce checkout does not offer that choice, a 000