Sign in

WP Security Ninja

@wpsecurityninja.bsky.social
1 followers 5 following 57 posts

Visit us at wpsecurityninja.com/?utm_source=blu…

PostsRepliesMedia
WP Security Ninja @wpsecurityninja.bsky.social · 15h
CrowdSec logged 30,813 IPs probing CVE-2026-87902 from Sep 23 to 27. Still active. Update to 7.1.2, or the patched release on your branch. Check for encoded pagename hits and PHP under /tmp. A plugin does not replace that update. wordpress.org/news/2026/09...
000
WP Security Ninja @wpsecurityninja.bsky.social · 29/09/2026
A federal judge let WP Engine's antitrust claims against Automattic and Matt Mullenweg go forward, reversing her dismissal. Not a verdict. Automattic's counterclaims mostly survived. www.searchenginejournal.com/automattic-m...
000
WP Security Ninja @wpsecurityninja.bsky.social · 28/09/2026
Monday: look at Users first. Plugin updates do not remove an admin you did not create. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 27/09/2026
If the only check is Monday morning, Sunday night is the gap. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 26/09/2026
Saturday: compare core files to WordPress.org. Then look at Users. wpsecurityninja.com/core-scanner/
000
WP Security Ninja @wpsecurityninja.bsky.social · 25/09/2026
David Ibiza’s Security Ninja walkthrough is live. If you try Pro after watching, coupon DAVIDIBIZA is in his description (10%). Video: www.youtube.com/watch?v=vSFz... #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 25/09/2026
s2Member has an unauthenticated RCE (CVE-2026-19804). Versions through 260814 are affected. Update to 260829+ and confirm the version on every membership install. Membership plugins can hit core-level severity when they go wrong. patchstack.com/database/wor...
000
WP Security Ninja @wpsecurityninja.bsky.social · 25/09/2026
Friday update is not a weekend plan. Look at Users. Look for PHP in uploads. Then leave it. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 24/09/2026
Agency checklist for CVE-2026-87902 (active exploitation): 1. Update every site still on ≤7.1.1 to 7.1.2 (or the backport for your branch) 2. Review logs for suspicious pagename/page_id probes 3. Check /tmp and /var/tmp for unexpected .php (wp-pear-rce-flag.php, poc87902.php, luci_.php, zeta_.php)
000
WP Security Ninja @wpsecurityninja.bsky.social · 24/09/2026
Yesterday: patch and probes. Today: attackers writing PHP via pearcmd on unpatched WordPress (CVE-2026-87902). Update past 7.1.1 to 7.1.2 (or your branch backport), then check logs and /tmp|/var/tmp for names like wp-pear-rce-flag.php, poc87902.php, luci_.php, zeta_.php.
000
WP Security Ninja @wpsecurityninja.bsky.social · 24/09/2026
Events can ping Slack when failed logins spike. You still decide what to do. wpsecurityninja.com/events-logger/
000
WP Security Ninja @wpsecurityninja.bsky.social · 23/09/2026
If Spanish isn’t your first language: David’s WP Security Ninja walkthrough is in Spanish, but YouTube’s auto-dub lets you listen in English. Same video, clearer access. www.youtube.com/watch?v=vSFz... #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 23/09/2026
If you stopped at Click2Shell / 7.1.1, you are not done. CVE-2026-87902 is unauth LFI in core template resolution. Patchstack saw probes the same day. Update to 7.1.2 or your backport. Hunt logs for odd pagename + page_id. Already patched? Drop a ✅. Agency life? Pass it to your clients.
000
WP Security Ninja @wpsecurityninja.bsky.social · 23/09/2026
Core Scanner compares your install to WordPress.org copies. A new file in wp-includes will not email you. wpsecurityninja.com/core-scanner/
000
WP Security Ninja @wpsecurityninja.bsky.social · 22/09/2026
What I like about David’s Security Ninja video: he runs the setup wizard and security tests on camera, not just a feature list. www.youtube.com/watch?v=vSFz... #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 22/09/2026
WordPress shipped another security release in 5 days. 7.1.1 on 17 Sep. 7.1.2 today (CVE-2026-87902). Update core, then inactive themes and comments. wpsecurityninja.com/wp2shell/?ut...
001
WP Security Ninja @wpsecurityninja.bsky.social · 22/09/2026
WordPress 7.1.2 (22 Sep) is a critical security release. Update now. Unauthenticated attackers can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If server and theme preconditions are met, that can lead to RCE
000
WP Security Ninja @wpsecurityninja.bsky.social · 22/09/2026
WordPress 7.1.1 (17 Sep) patched Click2Shell and Comment2Shell (CVE-2026-93485). Public PoCs and mainstream write-ups landed 21–22 Sep. Agency checklist: 1) Confirm every install is on 7.1.1 or your branch’s security backport 2) Check inactive themes you did not expect 3) Tighten comment moderation
000
WP Security Ninja @wpsecurityninja.bsky.social · 22/09/2026
Turn on 2FA on the client admin they still use. Not only yours. wpsecurityninja.com/how-to-enabl...
000
WP Security Ninja @wpsecurityninja.bsky.social · 21/09/2026
New Spanish walkthrough of WP Security Ninja by David Ibiza — and yes, you can listen in English via YouTube’s auto-dub. www.youtube.com/watch?v=vSFz... #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 21/09/2026
For my Spanish-speaking friends: David Ibiza’s full WP Security Ninja walkthrough is live. Spanish original + YouTube auto-dub for English listen. www.youtube.com/watch?v=vSFz... #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 21/09/2026
Forminator Forms ≤1.57.2 has an unauthenticated shortcode-execution hole (CVE-2026-92229). If you run quizzes or forms with it, update to 1.57.3 now. No login needed for the bad request. patchstack.com/database/wor... #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 21/09/2026
A security plugin and hired cleanup are different purchases. Buy a plugin for protection you operate. Hire when the site is already compromised. wpsecurityninja.com/wordpress-se...
000
WP Security Ninja @wpsecurityninja.bsky.social · 20/09/2026
If the only security check is Monday morning, Sunday night is the gap. wpsecurityninja.com/
001
WP Security Ninja @wpsecurityninja.bsky.social · 19/09/2026
Saturday check: look at Users for an admin you did not create. Then look for PHP under uploads. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 18/09/2026
WordPress 7.1.1 is out (maintenance + security). 11 security fixes, including stored XSS in Core wpautop() from an ordinary comment (CVE-2026-93485). Update to 7.1.1 now. Auto-updates pick it up if enabled. wordpress.org/news/2026/09... #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 18/09/2026
Page-cache debug log can become unauth RCE if that non-default debug option is on. Hummingbird ≤3.21.0. Patch 3.21.1+. Turn off unused debug logs. Keep caching plugins patched. www.cve.org/CVERecord?id...
000
WP Security Ninja @wpsecurityninja.bsky.social · 17/09/2026
“WordPress core files were modified” means a checksum no longer matches wordpress.org. The site can still look fine. Open the diff. Restore stock files you did not edit. wpsecurityninja.com/wordpress-co...
000
WP Security Ninja @wpsecurityninja.bsky.social · 16/09/2026
7.110 fixed a second-order SQLi that can turn a restore into RCE. The changelog buried it. Update. Turn off unused trackbacks. Check mu-plugins. www.bleepingcomputer.com/news/securit...
000
WP Security Ninja @wpsecurityninja.bsky.social · 15/09/2026
Elementor Pro Form File Upload is being mass exploited. Patch was 4.2.2 on Aug 19. Then check PHP under wp-content/uploads/elementor/forms/. www.securityweek.com/elementor-pr...
000
WP Security Ninja @wpsecurityninja.bsky.social · 14/09/2026
Plugin updates do not remove an admin you did not create. Look at Users first. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 13/09/2026
Handoff check: rotate admin passwords, change salts, then look for users you did not create. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 12/09/2026
Saturday check: a new file in wp-includes will not email you. Core Scanner compares your install to WordPress.org copies. wpsecurityninja.com/core-scanner/
000
WP Security Ninja @wpsecurityninja.bsky.social · 11/09/2026
Friday updates used to be a coin flip for agencies. .org holds releases 6h, runs AI + Jetpack Scan, blocks high-risk ones. July backdoor never hit clients. Glad it shipped. make.wordpress.org/plugins/2026... #WordPress
001
WP Security Ninja @wpsecurityninja.bsky.social · 11/09/2026
Turn on 2FA before the weekend, on the client admin they still use. Not only yours. wpsecurityninja.com/how-to-enabl...
000
WP Security Ninja @wpsecurityninja.bsky.social · 10/09/2026
.org auto-blocks high-risk plugin releases in the 6h cooldown. AI + Jetpack Scan. July backdoor (~20k installs) never hit the update API. Useful win. Still patch and scan. make.wordpress.org/plugins/2026... #WordPress
000
WP Security Ninja @wpsecurityninja.bsky.social · 10/09/2026
The vulnerability list is a Friday habit, not a news feed. Update what is listed before Monday’s client call. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 09/09/2026
If you already live in MainWP, run security from there too. Scans and vuln checks without opening every wp-admin. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 08/09/2026
Yes, you can hide the Security Ninja name on client sites. White label is Pro: your reports, your brand. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 07/09/2026
If a scanner says core files were modified, open the diff. wp-config.php is normal. PHP in wp-includes you did not edit is not. After wp2shell, that is often leftover access. wpsecurityninja.com/wordpress-co...
000
WP Security Ninja @wpsecurityninja.bsky.social · 07/09/2026
5.302 is out. Firewall no longer fills wp_options one row per IP, leftover rows get cleaned, and REST user listing is actually blocked. wpsecurityninja.com/changelog/
000
WP Security Ninja @wpsecurityninja.bsky.social · 06/09/2026
Would you notice a new file in wp-includes overnight? Core Scanner compares your install to WordPress.org copies. wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 05/09/2026
Check the vulnerability list on Friday, not Monday morning. Weekend surprises are just last week's skipped updates. wpsecurityninja.com/
000
Reposted by WP Security Ninja
InfluenceWP @influencewp.com · 06/07/2026
FREE Giveaway—$119 Value—Ends Today!!! WP Security Ninja helps WordPress site owners protect their websites without needing to be security experts. Effortless Entry. No Purchase Required. influencewp.com/iwp/giveaway @wpsecurityninja.bsky.social
021
WP Security Ninja @wpsecurityninja.bsky.social · 04/09/2026
The next GiveWP-class bug is already on a site you manage. Run the vulnerability list before the advisory hits your timeline. Update what is listed. Do not wait for the recap. wpsecurityninja.com/ #WordPress #WordPressSecurity
000
WP Security Ninja @wpsecurityninja.bsky.social · 03/09/2026
Firewall, malware scanning, and 50+ security tests in one plugin. Install wizard, then it keeps watch. Start free: wpsecurityninja.com/
000
WP Security Ninja @wpsecurityninja.bsky.social · 01/09/2026
WP Security Ninja 5.302: firewall that stays light. No more options-table bloat per IP on busy sites. Fewer DNS lookups on normal traffic. REST username enumeration blocked. wpsecurityninja.com/?utm_source=...
000
WP Security Ninja @wpsecurityninja.bsky.social · 01/09/2026
Know your WordPress core is clean. The Core Scanner compares your install to the official WordPress.org copies and flags unauthorized changes, infected files, and unexpected additions. wpsecurityninja.com/core-scanner/
000
WP Security Ninja @wpsecurityninja.bsky.social · 31/08/2026
wp2shell (Aug 31): nearly 7 weeks later. FortiGuard still lists scanning. Confirm 6.8.6 / 6.9.5 / 7.0.2. Then leftover admins + mu-plugins. Patched is not clean. wpsecurityninja.com/wp2shell/?ut...
000
WP Security Ninja @wpsecurityninja.bsky.social · 28/08/2026
50+ security tests. Weighted score. Details on every fail. Things that show up on real sites: a user still named admin, public readme.html, a wp-config.php.bak in the web root. wpsecurityninja.com/security-tests/
000