<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.techradar.com/uk/feeds/tag/wordpress"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar UK in Wordpress ]]></title>
                <link>https://www.techradar.com/uk/tag/wordpress</link>
        <description><![CDATA[ All the latest wordpress content from the TechRadar  UK team ]]></description>
                                    <lastBuildDate>Tue, 21 Jul 2026 13:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-millions-of-wordpress-websites-could-be-at-risk-following-reveal-of-worrying-bugs</link>
                                                                            <description>
                            <![CDATA[ Hackers are chaining together two newly discovered flaws to achieve remote code execution. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U7wqkXxvNQXgVKZKgfnjpJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)</strong></li><li><strong>When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover</strong></li><li><strong>Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks</strong></li></ul><p>Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.</p><p>WordPress developers released a patch for two vulnerabilities - an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.</p><p>The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the world’s <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">most popular website builder</a>.</p><h2 id="exploitation-underway">Exploitation underway</h2><p>According to <a href="https://www.theregister.com/security/2026/07/20/attackers-pummel-critical-wordpress-vuln-to-create-all-sorts-of-mischief/5275265" target="_blank"><em>The Register</em></a>, these bugs are not that dangerous when looked at separately, since they are rather difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, which means full website takeover.</p><p>Security researchers at Knott say threat actors picked up on the scent rather quickly. </p><p>The patch was released on Friday, but “by the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Knott said.</p><p>“From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”</p><p>It is worth mentioning that these vulnerabilities affect WordPress directly, instead of different plugins or themes. WordPress is by far the most popular website builder platform in the world, powering more than half of all websites in existence today. </p><p>To protect your assets, make sure to upgrade WordPress to version 6.9.5, since it contains fixes for both flaws. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Companies that can serve both human and agent audiences will be the ones that survive’: WordPress VIP CTO spells out the future of GEO, SEO, and much more ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/companies-that-can-serve-both-human-and-agent-audiences-will-be-the-ones-that-survive-wordpress-vip-cto-spells-out-the-future-of-seo-geo-and-more</link>
                                                                            <description>
                            <![CDATA[ ‘For decades, we’ve all built websites for Google’: WordPress VIP’s CTO argues that publishers must optimize websites for both human readers and AI agents, without forgetting about trust. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e8LCf5vLHyX38REEntQpC4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2026 22:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Website Hosting]]></category>
                                                                                                <author><![CDATA[ desire.athow@futurenet.com (Desire Athow) ]]></author>                    <dc:creator><![CDATA[ Desire Athow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oEw3XiohQwun9z7gMxKzkB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Désiré has been musing and writing about technology during a career spanning four decades. He dabbled in &lt;a href=&quot;https://www.techradar.com/news/the-best-website-builder&quot;&gt;website builders&lt;/a&gt; and &lt;a href=&quot;https://www.techradar.com/web-hosting/best-web-hosting-service-websites&quot;&gt;web hosting&lt;/a&gt; when DHTML and frames were in vogue and started narrating about the impact of technology on society just before the start of the Y2K hysteria at the turn of the last millennium.&lt;/p&gt;&lt;p&gt;Then followed a weekly tech column in a local business magazine in Mauritius, a late night tech radio programme called &lt;a href=&quot;https://web.archive.org/web/20030414214749/http://www.clicplus.com/&quot;&gt;Clicplus&lt;/a&gt; and a freelancing gig at the now-defunct, Theinquirer, with the late Mike Magee as mentor. After an eight-year stint at ITProPortal.com, where he discovered the joys of global techfests and transformed the publication into one of the biggest tech B2B independent publishers, Désiré moved to TechRadar Pro where he has been the editor for nine years.&lt;/p&gt;&lt;p&gt;He has an affinity for anything hardware and staunchly refuses to stop writing reviews of obscure products or cover niche B2B software-as-a-service providers. He is an avid deal hunter and can be found lurking around on various deals forums.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Craig Hale ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:description>                                                            <media:text><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:text>
                                <media:title type="plain"><![CDATA[Data Search Technology Search Engine Optimization. man&#039;s hands are using laptop to Searching for information. Marketing ranking traffic website, SEO search engine optimization concept.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8CfKaJtTivypreUesyghSh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The internet is undergoing a major shift, with publishers, ecommerce platforms and everyone in between struggling to grow visibility and remain relevant in an AI-dominated era.</p><p>Today, AI overviews and summaries dominate traditional search, while agentic assistants autonomously browse the web for consumers who have already shifted their browsing habits to their favorite chatbot.</p><p>But for decades, the web has been designed for human visitors, with search engines acting as intermediaries that help direct human traffic toward specific web pages. With more and more online content now being consumed by machines and AI taking over the decision of which information and products reach consumers first, traditional SEO alone is over.</p><p>GEO, or generative engine optimization, is already a term that publishers are throwing around, but few are certain of what it means and how they should balance it with their SEO strategies.</p><h2 id="publishers-need-to-target-two-audiences-but-humans-are-no-less-valuable">Publishers need to target two audiences… but humans are no less valuable</h2><p>According to new data from WordPress VIP, nearly three in four enterprise decision-makers now consider AI discoverability and attribution a significant priority, with three in five seeing increased traffic from AI search engines and third parties – so the shift is well underway, and companies are already starting, or trying, to adapt.</p><p>Per the report, nearly twice as many enterprise decision-makers now plan to prioritize investments across social platforms (32%) and AI engines (30%) compared with conventional owned websites (17%).</p><p>But amid this machine revolution, consumers are still pressing for human connections, with nearly half (42%) saying they trust unattributed AI-generated answers less than the likes of confusing privacy policies.</p><p>Today, publishers face a battle between AI optimization and visibility, and personalization and human-ness.</p><p>But WordPress VIP isn’t too concerned about the challenges, seeing them as temporary and familiar. CTO Brian Alvey even believes they mirror previous shifts brought on by social media.</p><p>So to understand what this AI revolution means for publishers, brands and the future of the web in general, I sought advice directly from Alvey.</p><ul><li><strong>Brian, the report you published mentioned that online properties like TechRadar need to serve two masters: AI scrapers and human audience. How is that being done in real life by brands that are looking to juggle both?</strong></li></ul><p>For decades, we’ve all built websites for Google. Sure we write for other people, but we format content for search engines and social networks. But Google and social were just top of funnel sources for getting visitors to your site. But now there's an actual second audience.</p><p>Our more innovative customers are already building sites for both humans and agents. And they’re doing it in the block editor. The same way you can tell a three-column block to reformat and stack the content for display on mobile, these customers are making content blocks that reformat as markdown for agents. Now all of their data-filled interactive charts are no longer just for a human audience. Their content is agent-native. And the wild thing that’s happening as they make their content easier for AI agents to understand is that they’re seeing a lift in SEO.</p><p>And this totally new version of their website isn’t doubling their work. It’s just built into their workflows.</p><p>The website is no longer just a destination for people. It has already become a source of information for machines acting on behalf of people. And the sites that aren’t simple for agents to consume will effectively be invisible to this new half of the internet. Companies that can serve both human and agent audiences will be the ones that survive.</p><ul><li><strong>One fact that caught my eye was that the majority of consumers trust unattributed AI answers with a huge portion (86%) bothered by searching for the original source after scanning an AI summary. What do you make out of it? How does the future look through that lens?</strong></li></ul><p>This might sound crazy with all the fear and hate AI is getting these days, but AI might actually be the best thing that ever happened to trusted brands. When an answer engine chooses you as a source, that's a powerful endorsement. Sure, the clicks might not be there right now, but the credibility boost sure is. We've been worrying that AI would cut brands out of the conversation. What our data shows is that the brands people already trust are the ones AI keeps going back to.</p><p>Your goal has never changed: be the most trusted business in your space. In an AI world, that trust will get you cited. And the brands that get cited will be the only ones that still exist for customers when the AI answer engines fully take over the internet.</p><ul><li><strong>Another finding from your report that shocked me was that only 17% of enterprises in the report will prioritize investments in their own websites in 2027. It's shocking as it means that instead, they will rely on social media and search engines to bring in audience. What are your thoughts about this?</strong></li></ul><p>That 17% number shocked me too. Did all these companies learn nothing from search and social? It’s not surprising that marketing teams are chasing where the audiences are going. But that means they’re giving up on having strong direct relationships with their customers. Being satisfied with getting roughly 60% of your audience reach from third-party platforms isn’t healthy. That's a lot of dependency on platforms you don't control.</p><p>Even if you use email as your primary channel of communication, which is a fantastic direct connection to your audience and customers, you still can’t process a sale or sign up a new subscriber in an email message. Your website still matters. The companies that win will be the ones that treat AI, social and search as distribution channels while continuing to invest in customer experiences they own and can constantly improve.</p><ul><li><strong>35 years ago, the open web was merely a pipe dream. CompuServe, AOL and a bunch of other gated communities dominated the landscape. Fast forward to 2026 and it seems that we're gradually slipping into an era where the open web - as we know it - is set to disappear. Tech giants are "encouraging" audiences to produce and consume content on their proprietary platforms. Is it too late to do anything?</strong></li></ul><p>No, I don't think it's too late. If you look at the history of the internet, we've gone through versions of this before. Thirty years ago you only had closed systems, which were a great first step for getting the world online. The web opened things up, but then search and social became the new gatekeepers. AI is creating another layer of gatekeepers but what's different this time is that we’re ready.</p><p>The consumers we talked to crave attribution. They care strongly about open access to information. They need to know where the answers they’re getting come from. The web won’t disappear, but it does need to evolve. These are the conversations we have every day with the people who run the world’s biggest and most important websites. We all agree that the only thing that matters is whether publishers, creators, and brands can maintain a direct relationship with their audiences and customers as these new pathways emerge.</p><ul><li><strong>The general consensus is that the web (and our email infrastructure) we know wasn't built for AI. I remember the days of Web 1.0, Web 2.0 and Web 3.0. Are we already in the Web 4.0 era? How do you evolve this hybrid ecosystem bearing in mind what we discussed in Q1 and the previous one?</strong></li></ul><p>Because we’ve been through this before with the rise of search and the rise of social and the big “pivot to video,” we’ve never been more prepared to adapt. The difference this time is the speed and the scale. While search and social disrupted the top of the marketing and sales funnels, AI agents are disrupting nearly the entire funnel. And the disruption won’t be slow this time. Agents are crawling sites at rates that are orders of magnitude bigger than search and social combined. And agents are disrupting every facet of websites, from creation all the way through to consumption. It’s total disruption. The good news is that your business hasn’t changed. What you make and who you make it for hasn’t changed. But how you make it and how they buy it has changed for good. If AI is 80% threat and 20% opportunity, then your job is to dive into that 20% and make AI work for you.</p><ul><li><strong>Your study indicates that the average internet user hits "bot fatigue" in just 40 minutes, and almost three-quarters of the respondents say the internet is significantly less human than it was a decade ago. Can anything be done to change that course or it is just too late, meaning we have to just go with the flow.</strong></li></ul><p>In some ways, we’re never going back. AI is already part of every product and every workflow. The good news is that the fatigue you mentioned and all this distrust are reversible, but only for the brands willing to actually be human about it.</p><p>A certain volume of AI content is expected now. There is no excuse to publish slowly anymore. But what’s missing from that AI-boosted content production? Specificity is what’s missing. A real take, a weird opinion, someone who you can tell actually knows what they're talking about. The brands cutting through the fatigue are the ones with actual voices, not mindless content machines. I'd rather read one paragraph from someone who's lived it than ten paragraphs of well-organized AI vanilla bullet points. That's what people are hungry for. The antidote to bot fatigue is just humans being human.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 1 million WordPress sites at risk after popular plugin hacked — OptinMonster among those hit in CDN supply-chain attack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/over-1-million-wordpress-sites-at-risk-after-popular-plugin-hacked-optinmonster-among-those-hit-in-cdn-supply-chain-attack</link>
                                                                            <description>
                            <![CDATA[ Three popular plugins served malicious JavaScript through a compromised CDN. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FhpEVQ9eXHymmkwG3aVTh9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jun 2026 17:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Vulnerability in UpdraftPlus plugin on Awesome Motive’s marketing server enabled CDN compromise and malicious JavaScript injection</strong></li><li><strong>Malware targeted logged‑in WordPress admins, harvesting tokens and creating rogue accounts for full takeover</strong></li><li><strong>Site owners urged to check for fake admin accounts (‘developer_api1’, ‘dev_xxxxxx’), hidden backdoor plugins, and rotate credentials/security salts</strong></li></ul><p>More than a million WordPress websites were at risk of full website takeover, after a vulnerability in a plugin enabled a large-scale supply-chain attack. The attack was spotted over the weekend by the ecommerce security outfit Sansec, and later confirmed by the victim company.</p><p>According to the researchers, hackers found and exploited a vulnerability in the UpdraftPlus <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> running on a marketing server belonging to Awesome Motive, the company behind multiple popular WordPress products including OptinMonster, TrustPulse, and PushEngage.</p><p>Even though the vulnerable server was not part of the production environment, it stored credentials for the company’s content delivery network (CDN), and by using the stolen CDN API key, the attackers were able to modify JavaScript files distributed through Awesome Motive's CDN.</p><h2 id="targeting-admins-only">Targeting admins only</h2><p>The compromised files were later used by OptinMonster, TrustPulse, and PushEngine, meaning the attackers’ JavaScript was served to visitors, but not all of them.</p><p>The malware only activated when a logged-in WordPress admin visited an affected site, helping it remain hidden while targeting only high-privilege users. The malicious script then harvested administrator authentication tokens and WordPress nonces, using them to create new admin accounts. </p><p>In the next step, the attackers installed additional malicious plugins, established command-and-control infrastructure, and began exfiltrating sensitive data. The malware also enabled web shell functionality, arbitrary PHP code execution, file management features, and virtually anything else an admin might do. </p><p>Even after Awesome Motive removed the malicious CDN scripts, attackers retained control of already compromised websites through the rogue administrator accounts and hidden backdoor plugins. Therefore, website owners at risk of takeover should look for rogue admin accounts named ‘developer_api1’ or ‘dev_xxxxxx’, inspect the filesystem directly under wp-content/plugins for hidden backdoor plugins, and execute server-side malware scans. </p><p>Furthermore, they should rotate admin passwords, API keys, database credentials, and WordPress security salts. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/optinmonster-wordpress-plugin-hacked-in-cdn-supply-chain-attack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/wordpress-sites-are-being-hijacked-using-a-critical-flaw-in-everest-forms-pro</link>
                                                                            <description>
                            <![CDATA[ A popular WordPress plugin is once again being leveraged in website takeover attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o8exkZUAd7DQR2sZtkPJu8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Jun 2026 00:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Critical RCE flaw in Everest Forms Pro (CVE‑2026‑3300) actively exploited</strong></li><li><strong>Attackers create rogue admin account “diksimarina” via PHP injection</strong></li><li><strong>Nearly 30,000 takeover attempts blocked; admins urged to patch and block key IPs</strong></li></ul><p>Security researchers are warning of an ongoing hacking campaign targeting certain WordPress websites using a popular plugin tool.</p><p>Wordfence has claimed Everest Forms Pro, a popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a>,  was allegedly being used to create contract, registration, payment, and other application forms, carried a critical-severity vulnerability that allowed malicious actors to take over the sites entirely.</p><p>The bug was described as a Remote Code Execution (RCE) flaw via PHP code injection. It is tracked as CVE-2026-3300 and was given the severity rating of 9.8/10 (critical). It affects all versions of the plugin up to, and including, 1.9.12.</p><h2 id="patched-months-ago">Patched months ago</h2><p>Wordfence is now warning that the flaw is being actively abused in the wild to create malicious admin accounts on vulnerable websites:</p><p>“The attacker submits a value for a text field that begins with a single quote to close the wrapping string literal, followed by a PHP statement that calls wp_insert_user() to create a new administrator account with the username 'diksimarina’,” Wordfence warned in its report.</p><p>“The trailing // comment marker ensures the rest of the generated PHP code, including the closing quote, is treated as a comment and does not cause a syntax error.” “When the form is processed, and the calculation is evaluated, the injected PHP code is executed, and the malicious administrator account is created.”</p><p>By creating an admin account, malicious actors can do almost anything with the website, including exfiltrating stored files, redirecting visitors, or even serving malware. </p><p>The bug was first disclosed in February this year, and by mid-March, the Everest Forms developer released a fix. Wordfence says that exploitation attempts started roughly a month later, in mid-April. So far, it thwarted almost 30,000 attempts, most of which came from two IP addresses. </p><p>Admins worried about being potential targets should block the two IP addresses 202.56.2[.]126 and 209.146.60.26, and should review log files for the string “diksimarina.”</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ In the AI era, is Shopify the new WordPress? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/in-the-ai-era-is-shopify-the-new-wordpress</link>
                                                                            <description>
                            <![CDATA[ WordPress saw a generation of creators and Shopify has done something similar for commerce. Could there be parallels? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">R2WZQkiMpmPZEZtQ3XothL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vUGGQXBvMLxK65oJegUwgk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Jun 2026 10:53:16 +0000</pubDate>                                                                                                                                <updated>Tue, 09 Jun 2026 13:08:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jim Herbert ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ &lt;p&gt;With 25 years in eCommerce and a background in computer science, Jim Herbert is CEO of Patchworks, he’s on a mission to make integrations effortless, helping retailers, brands, agencies and tech providers connect their systems and scale without limits.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vUGGQXBvMLxK65oJegUwgk-1280-80.jpg">
                                                            <media:credit><![CDATA[Song_About_Summer / Shutterstoc]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Someone typing at a keyboard, with an ecommerce shopping cart symbol floating in the air.]]></media:description>                                                            <media:text><![CDATA[Someone typing at a keyboard, with an ecommerce shopping cart symbol floating in the air.]]></media:text>
                                <media:title type="plain"><![CDATA[Someone typing at a keyboard, with an ecommerce shopping cart symbol floating in the air.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vUGGQXBvMLxK65oJegUwgk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It’s a tempting comparison. <a href="https://www.techradar.com/best/wordpress-website-builder">WordPress</a> gave a generation of creators a way to publish without needing to understand code. Shopify has done something similar for commerce, turning what was once complex, expensive and <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developer</a>-led into something far more accessible.</p><p>But while the parallels are real, the story is a little more layered than a straight one-to-one.</p><p>WordPress didn’t just win because it was good. It won because it made the internet feel usable. You could set up a site quickly, choose from thousands of themes, and rely on a vast community to solve problems as they came up.</p><p>It lowered the barrier to entry so effectively that it became the default. If you wanted to exist online, WordPress was where you started.</p><p>Shopify has taken that same principle and applied it to selling. It has removed the friction from getting started. Payments, <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">hosting</a>, storefront design and checkout are all built in. You do not need a technical background to launch a store. You do not need a large budget to begin testing an idea.</p><p>That accessibility has changed the shape of retail, particularly for independent brands and smaller merchants who previously would have been locked out of the market.</p><h2 id="an-ecommerce-ecosystem">An ecommerce ecosystem</h2><p>But what really makes the comparison stick is the ecosystem. Shopify has not just built a platform. It has built an economy around that platform. Thousands of developers work inside Shopify.</p><p>Tens of thousands more build apps, themes and integrations around it. Agencies have reshaped themselves to specialize in it. An entire layer of commerce expertise now exists because Shopify made it viable.</p><p>Shopify now powers millions of merchants globally, with a partner ecosystem of over 100,000 companies and more than 16,000 apps extending core functionality. It’s effectively become a default stack for commerce, lowering the barrier to entry and accelerating a wave of agencies building on the same foundations.</p><p>Shopify accounts for ~30% of <a href="https://www.techradar.com/news/the-best-ecommerce-platform">ecommerce</a> platforms globally – and it’s one of the tech stories of recent years.</p><p>That creates a kind of gravitational pull. The more people build on it, the more useful it becomes. The more useful it becomes, the more people choose it. WordPress followed the same path. Over time, it became less of a tool and more of an infrastructure layer for the internet.</p><p>Shopify is moving in that direction for commerce. It is also increasingly positioned as the fastest route into building a “tech-enabled” <a href="https://www.techradar.com/best/best-business-plan-software">business</a>. A brand can launch on the same platform used by global retailers, access a marketplace of thousands of apps, and plug into multiple sales channels without needing to rebuild its core systems.</p><p>That sense of shared infrastructure is powerful. It means smaller businesses can operate with the same underlying capabilities as much larger ones.</p><p>This is where the comparison becomes more interesting, and more complicated. WordPress simplified publishing, but it did not eliminate complexity.</p><p>It redistributed it. Hosting, plugins, performance and security all became areas where expertise still mattered. Shopify is doing something similar, but the complexity it redistributes sits in a different place.</p><h2 id="it-s-a-little-more-complex">It’s a little more complex</h2><p>In commerce, the real challenge is less about launching a new <a href="https://www.techradar.com/news/the-best-website-builder">website</a> or store and more about connecting. What used to sit in custom development now sits in integration, orchestration and data flow.</p><p>A brand might have a storefront, a warehouse system, a <a href="https://www.techradar.com/best/best-crm-for-small-business">CRM</a>, a returns platform, a loyalty program and multiple marketplaces. Each of these systems needs to talk to the others. Each needs to stay in sync. Each needs to respond in real time to customer behavior.</p><p>That is where the pressure has moved. It is also where many businesses begin to struggle. The front end is easy to launch. The back end is where things either scale or break. Integration has been a consistent challenge across decades of ecommerce. </p><p>Every project eventually comes back to the same question. How do you connect systems in a way that is reliable, scalable and commercially viable?</p><p>This is not something WordPress had to contend with at the same level. Content is relatively simple compared to commerce. Selling involves inventory, fulfilment, pricing, tax, payments and increasingly personalization. Each layer adds complexity, and each connection introduces potential points of failure.</p><p>So while Shopify has lowered the barrier to entry, it has not removed the need for technical thinking. It has simply shifted where that thinking happens.</p><p>This shift is already shaping how brands compete. When many businesses are built on the same platform, differentiation becomes harder. If everyone can launch quickly and access similar tools, the advantage no longer sits in getting online. It sits in how well everything works together once you are there.</p><p>That includes how data flows across systems, how quickly operations can adapt, and how consistent the customer experience feels across channels. It also includes how brands use that data to drive retention, not just acquisition. The focus is moving away from launch and towards long-term performance.</p><p>Shopify is responding to this by evolving beyond a pure ecommerce platform. Its investment in POS, marketplaces and channel integrations points towards a broader vision of unified commerce. The aim is not just to help brands sell online, but to help them sell everywhere in a connected way.</p><p>That ambition is significant. It suggests Shopify does not just want to be the WordPress of commerce. It wants to be the operating system for retail. There are early signs of that playing out. Brands we work with using Shopify as part of a wider ecosystem that spans online, in-store and global expansion.</p><p>The platform is no longer just a starting point. For many, it becomes a central layer in how the business runs.</p><h2 id="the-role-of-ai">The role of AI</h2><p>At the same time, Shopify is embedding <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> into its platform, which further lowers the barrier to entry. Tasks that once required specialist knowledge are becoming automated or assisted.</p><p>Product descriptions, merchandising decisions, customer insights and even aspects of development are being simplified. This mirrors the way WordPress plugins and tools made content creation more intuitive over time.</p><p>But again, the complexity doesn’t disappear, it evolves. AI increases the need for clean, accessible data. It increases the importance of having systems that can respond quickly and accurately. It also raises the stakes for integration, as more processes become automated and interdependent.</p><p>If one part of the system fails, the impact can ripple much further.</p><h2 id="that-question-again">That question again</h2><p>So is Shopify the new WordPress? In some ways, yes. It has democratized access to a core digital capability. It has built a vast ecosystem. It has become the default starting point for a generation of businesses. But it is also operating in a more complex environment, where the challenges do not end at launch. They begin there.</p><p>WordPress gave people a voice online. Shopify has given people the ability to sell. The next phase is about what happens after that moment. How businesses connect, scale and differentiate in a world where the tools are increasingly the same. That is where the real competition sits now.</p><p>And it is why Shopify’s position, while strong, is not unassailable.</p><p>Its lead comes from momentum, ecosystem and ease of use. But as commerce becomes more composable, more data-driven and more dependent on integration, the centre of gravity may shift again. The platform still matters, but it is no longer the whole story.</p><p>Shopify may be the closest thing commerce has to a WordPress moment. But what comes next will be defined less by how easy it is to start, and more by how well everything works together once you do.</p><p><em></em><a href="https://www.techradar.com/news/best-ecommerce-hosting"><em>We've featured the best ecommerce hosting.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Steam Community Profiles abused as C2 network in new WordPress malware infection campaign ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/steam-community-profiles-abused-as-c2-network-in-new-wordpress-malware-infection-campaign</link>
                                                                            <description>
                            <![CDATA[ A new cheeky malware campaign abuses the comment section as a roadsign to malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EyczYyhYsLAgPaDCuuw3Fm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bx8fPhUoHLYdN39sZtNWZk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Jun 2026 12:18:13 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Jun 2026 12:18:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bx8fPhUoHLYdN39sZtNWZk-1280-80.jpg">
                                                            <media:credit><![CDATA[Valve]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Steam with game covers in the background]]></media:description>                                                            <media:text><![CDATA[Logo of Steam with game covers in the background]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Steam with game covers in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bx8fPhUoHLYdN39sZtNWZk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Malware hides payload in Steam Community comments</strong></li><li><strong>WordPress sites used to host backdoors</strong></li><li><strong>Nearly 2,000 sites compromised since July</strong></li></ul><p>Security researchers from GoDaddy found a cheeky new malware campaign that used comments made by Steam Community accounts as command-and-control (C2) infrastructure.</p><p>Here is how the attack plays out: The attackers would first find vulnerable <a href="https://www.techradar.com/best/wordpress-website-builder" target="_blank">WordPress websites,</a> or those protected by weak credentials, and use them to host PHP malware somewhere in the site’s files. For example, the sample was found in a theme’s ‘functions.php’ file. This malware contains both a JavaScript injection component, and a server-side backdoor. </p><p>Then, whenever a visitor loads the infected website, the malware contacts one of several Steam Community profiles and downloads the contents of profile comments. On surface level, these comments look harmless (albeit incoherent), but they also contain invisible Unicode characters which carry the actual payload. </p><h2 id="industry-support">Industry support</h2><p>“This encoding allows binary data to be embedded within normal-looking text. The visible characters serve as camouflage while the invisible characters carry the actual payload,” GoDaddy said.</p><p>The malware then extracts the characters, converts them into binary data, and reconstructs the original bytes. The researchers found that this recovered data contains a URL controlled by the attackers, which points to a domain hosting a JavaScript file spoofing a legitimate library. </p><p>The malware then uses WordPress to load the attacker-controlled JavaScript on every frontend page, which the visitors’ browsers then download and run, infecting themselves in the process.</p><p>In the campaign, there are two sets of targets - vulnerable WordPress websites, and their visitors. Since uncovering the campaign in July last year, GoDaddy said it found almost 2,000 compromised WordPress sites. Unfortunately, the research report stops short of describing what the malware does to visitors.</p><p>If you run a WordPress website, GoDaddy recommends to check for references to Steam Community URLs, external JavaScript injections, as well as outbound connections from WordPress to Steam. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/wordpress-malware-campaign-hides-payloads-in-steam-profiles/" target="_blank" rel="nofollow"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WP Maps Pro plugin flaw to create admin accounts on WordPress sites saw 3,600 attempts in a single day ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/wp-maps-pro-plugin-flaw-to-create-admin-accounts-on-wordpress-sites-saw-3-600-attempts-in-a-single-day</link>
                                                                            <description>
                            <![CDATA[ Thousands of attacks were seen in a single day as a patch is rolled out. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ywDdhfxzZfC7g3BeHJffRD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Jun 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers disclosed a critical flaw in WP Maps Pro allowing attackers to create hardcoded admin accounts</strong></li><li><strong>Exploitation is active: Wordfence blocked over 3,600 attempts in a single day </strong></li><li><strong>Patch released May 20 (v6.1.1); users must upgrade immediately</strong></li></ul><p>Criminals are actively exploiting a critical vulnerability in a popular <a href="https://www.techradar.com/best/wordpress-website-builder" target="_blank">WordPress</a> plugin to create admin accounts and thus take over entire websites. This is according to multiple security researchers including David Brown (who first disclosed the flaw), and Defiant, who confirmed in-the-wild exploitation attempts.</p><p>The plugin in question is called WP Maps Pro, it is a premium WordPress plugin used to create customizable maps, interactive store locators, and similar, using either Google Maps or OpenStreetMap. The plugin is currently used by more than 15,000 websites, according to Envato Market numbers.</p><p>As per Brown’s research, the plugin suffered from a “privilege escalation via administrator account creation” vulnerability which allowed threat actors to create a new WordPress user with a hardcoded admin role. The vulnerability is now tracked as CVE-2026-8732, and carries a severity score of 9.8/10 (critical). It was found in versions 6.1.0 and older.</p><h2 id="applying-a-fix">Applying a fix</h2><p>Defiant, the cybersecurity company behind Wordfence, said its researchers observed and stopped more than 3,600 exploitation attempts in just one day. </p><p>“When the request is made with a check_temp parameter set to false, the function creates a new WordPress user via wp_insert_user() with the hardcoded role of administrator, a randomly generated username, and the hardcoded email address support@flippercode.com,” the researchers said. “The function then generates a “magic login URL” using generate_login_link(), stores it as user meta, and returns it in the response body.”</p><p>The fix was released four days after initial disclosure, on May 20. Users are advised to upgrade to version 6.1.1 as soon as possible to avoid being targeted. </p><p>With WordPress powering much of today’s internet, it is also one of the most targeted platforms in existence. Its vast ecosystem of <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">plugins</a> and themes, both free and premium, are constantly being abused in attacks such as this one. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/wp-maps-pro-bug-exploited-to-create-admin-accounts-on-wordpress-sites/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another top WordPress plugin exploited — hackers target credit card details, here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/another-top-wordpress-plugin-exploited-hackers-target-credit-card-details-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Funnel Builder WordPress plugin is being exploited to steal people's credit cards but the flaw has since been patched. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5REbZDVmzN8NNe7zAtLQ3C</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 May 2026 15:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hackers are exploiting a critical flaw in the Funnel Builder plugin to inject credit card skimmers into checkout pages</strong></li><li><strong>FunnelKit released a patched version, but more than half of active sites remain on older, vulnerable builds</strong></li><li><strong>Stolen payment data is being monetized through dark web sales and fraudulent ad purchases</strong></li></ul><p>Hackers are exploiting a critical vulnerability in a popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> to steal credit card information from people making online purchases.</p><p>Security researchers Sansec said they recently spotted an active campaign targeting websites running the Funnel Builder plugin, which is apparently active on more than 40,000 ecommerce websites, letting businesses create sales funnels, landing pages, optimized checkout flows, upsells, and lead-generation campaigns, all without any coding.</p><p>Sansec found it carried a critical-severity vulnerability (no CVE yet), that allows threat actors to add malicious JavaScript snippets into WooCommerce checkout pages, without authentication. According to the researchers, someone used it to add a credit card skimmer capable of exfiltrating credit card numbers, CVVs, billing addresses, and other customer information.</p><h2 id="patching-the-flaw">Patching the flaw</h2><p>We don’t know how many websites have been compromised this way, or how many people lost their credit card information to the hackers - however, the data they stole is all they need to make fraudulent purchases online. </p><p>In most cases, though, they just sell it on the dark web to the highest bidder. Usually cybercriminals use stolen cards to purchase ads on reputable ad networks and promote malware that can lead to ransomware infections. </p><p>Most of the ads for malware and infostealing landing pages seen on Google are paid for with stolen credit cards and through compromised Google Ads accounts. </p><p>Since then, FunnelKit (the company behind the plugin) addressed the issue and released a new version - 3.15.0.3. All users are advised to upgrade to this version and secure their websites immediately. </p><p>At press time, the official <a href="https://www.techradar.com/news/best-wordpress-hosting-providers" target="_blank">WordPress site</a> shows 50.3% of all websites are running older versions of Funnel Builder, meaning at least 20,000 sites are directly exposed. The remaining 49.7% are shown as running version 3.15, so we don’t know how many have patched up. Therefore, number of websites at risk could possibly be even higher.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over a million WordPress sites hit in plugin flaw — so patch now or face the consequences ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/over-a-million-wordpress-sites-hit-in-plugin-flaw-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ A popular WordPress plugin was found carrying two flaws that can cause data leaks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JC4jvWxdzFSJPo764QL6n3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 May 2026 17:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Wordfence disclosed two flaws in Avada Builder, a WordPress plugin with around 1 million active installs</strong></li><li><strong>CVE‑2026‑4782 (Arbitrary File Read, medium severity) requires subscriber‑level access; CVE‑2026‑4798 (SQL injection, high severity) exploitable unauthenticated</strong></li><li><strong>Patches released in April and May 2026; users advised to update to v3.15.3+; researcher Rafie Muhammad earned ~$4,500 bounty</strong></li></ul><p>A popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> with roughly a million active installations contained two vulnerabilities that could have allowed malicious actors to exfiltrate sensitive data, such as password hashes and other valuable information.</p><p>Security researchers at Wordfence <a href="https://www.wordfence.com/blog/2026/05/1000000-wordpress-sites-affected-by-arbitrary-file-read-and-sql-injection-vulnerabilities-in-avada-builder-wordpress-plugin/" target="_blank">said</a> they were tipped off by a researcher Rafie Muhammad about the existence of an Arbitrary File Read and an SQL Injection vulnerability in Avada Builder. </p><p>Avada Builder is a drag-and-drop page builder for <a href="https://www.techradar.com/best/wordpress-website-builder" target="_blank">WordPress</a> that comes as part of the Avada ecosystem by ThemeFusion, with more than 1,050,000+ active installations right now. With it, users can build websites without needing to learn or write code. It works by dragging and dropping different elements like text blocks, images, sliders, buttons, forms, pricing tables, and layouts onto a page, and customizing them in real time.</p><h2 id="patches-available">Patches available</h2><p>The only prerequisite to be able to exploit the first bug is to have at least subscriber-level access, which shouldn’t be too difficult on most sites. This bug, now tracked as CVE-2026-4782, was assigned a severity score of 6.5/10 (medium).</p><p>The SQL injection vulnerability, on the other hand, can be exploited even by unauthenticated attackers, to extract sensitive data from the database, including hashed passwords. This one is now tracked as CVE-2026-4798 and was assigned a slightly higher severity score - 7.5/10 (high).</p><p>Wordfence said the flaws were disclosed to the Avada team on March 24 and 25, 2026, and the developers came back with patches within two months - one on April 13, and the other on May 12. </p><p>Users running Avada Builder on their website are advised to update the plugin to version 3.15.3 or newer as soon as possible. </p><p>Muhammad was paid roughly $4,500 in bounty for his troubles, Wordfence confirmed.</p><p>"Props to Rafie Muhammad who discovered and responsibly reported these vulnerabilities through the Wordfence Bug Bounty Program," it wrote in its report.</p><p>"Our mission is to secure WordPress through defense in depth, which is why we are investing in quality vulnerability research and collaborating with researchers of this caliber through our Bug Bounty Program. We are committed to making the WordPress ecosystem more secure through the detection and prevention of vulnerabilities, which is a critical element to the multi-layered approach to security."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This free WordPress tool could save businesses billions every year by slashing the AI tokens needed to read the web — saving enough electricity to power the entire USA for 24 hours ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/this-free-wordpress-tool-could-save-businesses-billions-every-year-by-slashing-the-ai-tokens-needed-to-read-the-web-saving-enough-electricity-to-power-the-entire-usa-for-24-hours</link>
                                                                            <description>
                            <![CDATA[ Free WordPress plugin could slash AI web traffic data use enough to rival daily USA electricity consumption if widely adopted. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BEB4WU4vWNDTGxCcbVRRAb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjKrKLGKRzqBqXXJbXCh7k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 02 May 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ waynewilliams@onmail.com (Wayne Williams) ]]></author>                    <dc:creator><![CDATA[ Wayne Williams ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/7YTAnzyJ2Ci96hP5duFpQm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjKrKLGKRzqBqXXJbXCh7k-1280-80.jpg">
                                                            <media:credit><![CDATA[Generated by Gemini]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress Markdown for Agents tool saves electricity]]></media:description>                                                            <media:text><![CDATA[WordPress Markdown for Agents tool saves electricity]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress Markdown for Agents tool saves electricity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjKrKLGKRzqBqXXJbXCh7k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Clean Markdown delivery cuts AI processing waste and lowers large scale computing loads</strong></li><li><strong>Global WordPress adoption could shrink billions of gigabytes of unnecessary data transfers</strong></li><li><strong>Estimated energy savings rival electricity needed to briefly power the United States </strong></li></ul><p>A new open source WordPress plugin focuses on the growing load created by AI systems constantly crawling websites and processing pages never built for machines in the first place.</p><p>The <a href="https://labs.chancerylaneproject.org/project/wordpress-markdown-for-agents/" target="_blank" rel="nofollow">WordPress Markdown for Agents tool</a>, released by The Chancery Lane Project, serves simplified Markdown versions of webpages when AI agents visit, stripping out scripts, navigation elements, and other extras that machines tend to ignore anyway.</p><p>Instead of forcing AI systems to process full HTML pages packed with layout code and styling, the plugin delivers only readable content, cutting token usage and reducing computing demand when bots access supported pages.</p><h2 id="websites-are-built-for-humans-not-ai">Websites are built for humans, not AI</h2><p>Estimates tied to common webpage sizes and automated traffic patterns suggest the impact could scale quickly if widely adopted across WordPress installations, which account for hundreds of millions of sites globally.</p><p>Serving Markdown instead of raw HTML typically shrinks transferred data by around 80%, turning a 2.3MB page into something closer to 0.46MB once layout elements and supporting code are removed.</p><p>With conservative estimates placing automated AI visits at roughly 1,000 requests per month per site, each site could reduce transferred data by about 22GB annually when serving simplified content to supported crawlers.</p><p>Multiply that across large numbers of WordPress deployments, and total reductions climb into the range of 17.8 billion gigabytes saved each year under those same assumptions.</p><p>Energy consumption tied to moving and processing data adds another layer to the discussion, since estimates place average electricity use for data transfer and hosting at roughly 0.81kWh per gigabyte.</p><p>Using those figures, total annual energy reductions could reach roughly 14.4 billion kilowatt-hours if adoption spread broadly across WordPress deployments, although real-world totals would naturally depend heavily on traffic patterns and adoption levels.</p><p>“If climate action scales through law, then ensuring that legal knowledge can travel effectively in an AI-driven world is essential. Most websites are built for human users, not AI, which means systems often process large amounts of irrelevant data, increasing cost and energy use," said Ben Metz, Executive Director of The Chancery Lane Project. </p><p>"For TCLP, this is about maintaining access to high-quality, climate-aligned legal content at a time when the way information is accessed is fundamentally changing. This plugin addresses that by delivering a clean, machine-readable version of content, enabling more efficient retrieval for tasks such as research, drafting, and analysis,”  he added.</p><p>Early testing cited reductions of up to 90% in token usage when AI systems accessed pages via Markdown delivery rather than full webpage rendering.</p><p>“Improving the efficiency of digital systems is not just a technical concern. It has real environmental implications,” said Felix Cohen, the company's Director of Digital.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Building a great website now means simplifying your tech stack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/building-a-great-website-now-means-simplifying-your-tech-stack</link>
                                                                            <description>
                            <![CDATA[ Simplifying website tech stacks reduces complexity, improves performance, and enables scalable, efficient growth. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UsuHronocyBLMNChTbYxTj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zwBWPNAfpJdnNkfJY3wUKM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Apr 2026 14:25:42 +0000</pubDate>                                                                                                                                <updated>Wed, 22 Apr 2026 16:06:26 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ayaz Ahmed Khan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zwBWPNAfpJdnNkfJY3wUKM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A data center in a blue light]]></media:description>                                                            <media:text><![CDATA[A data center in a blue light]]></media:text>
                                <media:title type="plain"><![CDATA[A data center in a blue light]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zwBWPNAfpJdnNkfJY3wUKM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Building a website has never been easier. Launching one, however, and keeping it running as traffic scales has never been more complicated.</p><p>Most modern websites depend on a long list of tools working behind the scenes: hosting <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a>, analytics platforms, marketing integrations, security layers, performance optimization tools, and accessibility checks. </p><p>Each one exists for a good reason. Together, they help businesses deliver the fast, reliable experiences customers now expect online.</p><p>When everything works as it should, the results can be monumental. A well-built website can load instantly, rank well in search, capture leads automatically, and support <a href="https://www.techradar.com/best/best-email-marketing-software">marketing</a> campaigns around the clock. </p><p>For many businesses, the website has quietly become one of the most important growth engines they have. But getting to that point is rarely straightforward.</p><p>Before a site even launches, teams often spend hours installing <a href="https://www.techradar.com/best/best-wordpress-plugins">plugins</a>, configuring integrations, and checking all the tools work together. Performance tools must not conflict with security layers. </p><p>Marketing integrations must connect cleanly to analytics systems. Updates must not break the site entirely. What looks simple in theory can become frustratingly complicated in practice.</p><p>For many <a href="https://www.techradar.com/best/best-linux-distro-for-developers">developers</a>, agencies, and businesses, preparing the environment behind a website now takes as much time as building the site itself.</p><h2 id="why-modern-website-stacks-became-so-complex">Why modern website stacks became so complex</h2><p>Part of the reason modern website stacks become so complex is because of 2026’s <a href="https://www.techradar.com/pro/best-ai-website-builder">website</a> expectations. A modern site might need to support ecommerce transactions, run marketing campaigns, track analytics, protect customer data, and meet accessibility standards. Delivering all of this requires specialized tools.</p><p>Hosting infrastructure provides the foundation. <a href="https://www.techradar.com/best/cms">Content management systems</a> power the site itself. Plugins and integrations extend functionality into areas like <a href="https://www.techradar.com/news/best-seo-tool">SEO</a>, email marketing, analytics tracking, and performance monitoring.</p><p>This modular model is one of the web’s greatest strengths. Instead of relying on one system to do everything, businesses can choose the tools that best suit their needs – giving them the technological flexibility needed to compete with enterprise players.</p><p>Interestingly, looking at real usage data across more than 100,000 <a href="https://www.techradar.com/best/wordpress-website-builder">WordPress</a> applications running on Cloudways, most website stacks end up looking quite similar. A small number of tool categories appear repeatedly: SEO plugins, marketing integrations, page builders, accessibility tools, and optimization layers across a huge number of projects.</p><p>These tools are popular because they work. But teams often end up rebuilding the same stack repeatedly. Each new project starts with researching plugins, testing integrations, and fixing compatibility issues before the environment becomes stable. The flexibility to mix and match tools makes this possible – but it also adds complexity.</p><h2 id="the-hidden-operational-cost-of-tool-sprawl">The hidden operational cost of tool sprawl</h2><p>That complexity usually shows up in day-to-day operations. Teams spend more time maintaining the website environment than improving the site itself. Plugins need updating. Integrations need monitoring. Performance issues need investigating.</p><p>For agencies managing dozens of client websites, or <a href="https://www.techradar.com/news/the-best-ecommerce-platform">ecommerce</a> teams responsible for high-traffic stores, this maintenance work adds up quickly.</p><p>Troubleshooting can also become difficult. When a site slows down or experiences downtime, the cause is rarely obvious. The issue might come from <a href="https://www.techradar.com/news/best-dedicated-server-hosting-providers">server</a> configuration, plugin conflicts, <a href="https://www.techradar.com/best/best-database-software">database</a> queries, or external services. With multiple systems involved, identifying the root cause can take time that most businesses don’t have.</p><p><a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> creates another layer of work. Every integration introduces another component that needs monitoring and updating. Keeping everything secure and compatible requires consistent attention, especially for teams without dedicated infrastructure specialists.</p><p>None of these tasks are unusual. The challenge is how many of them accumulate over time.</p><h2 id="how-businesses-can-simplify-their-website-infrastructure">How businesses can simplify their website infrastructure</h2><p>The answer is not removing tools entirely. The flexibility of the web ecosystem is essential to a successful website. Instead, businesses need to manage their stacks in ways that reduce unnecessary complexity.</p><p>A strong hosting foundation is a good place to start. <a href="https://www.techradar.com/web-hosting/best-managed-web-hosting">Managed hosting</a> platforms that handle server management, monitoring, and performance optimization can remove a large amount of operational work. </p><p>When <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">web hosting</a> environments include automated diagnostics and monitoring, teams can identify issues earlier and resolve them faster. Many hosts also surface trusted integrations and partner tools, helping teams extend their stack without starting the research process from scratch.</p><p>It also helps to rely on proven tools. Despite the vast number of plugins available, most successful websites rely on a relatively small group of well-established solutions. Using widely adopted tools reduces compatibility risks and makes maintenance easier.</p><p>Regularly reviewing the stack is equally important. Websites often accumulate duplicate plugins performing similar tasks. Removing redundant tools can simplify the environment and improve performance at the same time.</p><p>Finally, compatibility matters. Tools designed to work well together dramatically reduce troubleshooting. Platforms that test and validate integrations before deployment can save teams considerable time during setup.</p><h2 id="simplicity-is-becoming-a-competitive-advantage">Simplicity is becoming a competitive advantage</h2><p>Websites will only become more capable as new technologies emerge. But as the ecosystem grows, the ability to manage complexity becomes more important.</p><p>Businesses that simplify their website infrastructure can launch projects faster, maintain <a href="https://www.techradar.com/best/best-talent-software">performance</a> more easily, and respond to problems before they affect customers. Instead of spending time maintaining tools and fixing integrations, teams can focus on improving the website experience itself.</p><p>In an online environment where performance directly affects trust, engagement, and revenue, that shift matters. The future of web infrastructure may not depend on how many tools businesses can add to their stack, but on how well the right tools work together from the start.</p><p><a href="https://www.techradar.com/news/the-best-website-builder"><em>We've ranked the best website builders</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'Update immediately': 60,000 WordPress websites at risk after experts discover flaw that allows hackers to create hidden admin accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/update-immediately-60-000-wordpress-websites-at-risk-after-experts-discover-flaw-that-allows-hackers-to-create-hidden-admin-accounts</link>
                                                                            <description>
                            <![CDATA[ A critical WordPress plugin flaw allows attackers to bypass authentication and gain full administrative control, exposing websites to data theft and malware attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sbuVVsKNsM8XkPBhaPud2c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 18 Apr 2026 16:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>User Registration & Membership plugin flaw allows attackers to gain admin access without login</strong></li><li><strong>Exposed nonce values enable unauthorized backend requests and privilege escalation</strong></li><li><strong>Sensitive user data becomes exposed once administrative privileges are obtained</strong></li></ul><p>A critical security flaw in a widely used <a href="https://www.techradar.com/best/best-wordpress-plugins">WordPress plugin</a> allows unauthenticated attackers to bypass authentication controls and gain full administrative access to affected websites.</p><p>The vulnerability, tracked as CVE-2026-1492, affects the User Registration & Membership plugin, versions 5.1.2 and earlier.</p><p>Experts at <a href="https://www.cyfirma.com/research/cve-2026-1492-wordpress-user-registration-membership-authentication-bypass-flaw/" target="_blank" rel="nofollow">Cyfirma</a> say improper server-side validation and weak authorization checks within the membership registration workflow create this dangerous gap.</p><h2 id="how-attackers-exploit-the-vulnerability-without-any-credentials">How attackers exploit the vulnerability without any credentials</h2><p>Attackers can abuse exposed client-side data and insufficient backend validation to manipulate parameters that directly influence authentication and privilege assignment.</p><p>The vulnerability stems from trusting user-controlled input rather than enforcing strict server-side validation.</p><p>Backend endpoints process membership-related actions without proper authentication or authorization checks.</p><p>This weakness becomes dangerous because exposed nonce values within client-side JavaScript are accessible to unauthenticated users.</p><p>Attackers can then reuse these nonce values in crafted requests to manipulate backend behavior, even for <a href="https://www.techradar.com/news/the-best-website-builder">website builders</a>.</p><p>By inspecting these values, attackers can construct malicious requests targeting the WordPress AJAX endpoint at /wp-admin/admin-ajax.php.</p><p>The backend processes these requests without verifying the request origin or authorization state.</p><p>This results in automatic authentication and privilege escalation, where administrative access is granted without any legitimate login process taking place.</p><p>Successful exploitation grants attackers unrestricted administrative privileges over the entire WordPress environment.</p><p>With this level of access, attackers can install malicious plugins and modify themes to execute arbitrary code.</p><p>They can also access sensitive user data, including credentials and configuration files.</p><p>Hidden admin accounts can be created to ensure persistent access even after initial detection.</p><p>These attackers can also redirect website visitors to phishing pages or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> distribution sites.</p><p>Website defacement, content tampering, and malicious script injection become trivial once administrative control is established.</p><p>All versions of the User Registration & Membership plugin up to and including version 5.1.2 are vulnerable to this flaw - but the issue has been addressed in version 5.1.3 through improved validation and authorization mechanisms — so website administrators must update immediately.</p><p>After updating, administrators should review existing user accounts, especially those with administrative privileges, which will help identify any unauthorized accounts created before patching.</p><p>Suspicious sessions should be invalidated, and credentials reset if compromise is suspected.</p><p>The vulnerability carries a CVSS v4.0 score of 9.8 out of 10, indicating critical severity.</p><p>Observed discussions in underground forums show active interest in exploiting this vulnerability.</p><p>Hackers are already sharing exploitation techniques among themselves and discussing automation strategies.</p><p>Initial Access Brokers may leverage this flaw to obtain administrative access and resell it for ransomware deployment, SEO spam campaigns, or credential harvesting operations.</p><p>Given the low complexity of exploitation and public awareness of the technique, website owners running the affected plugin should treat their systems as actively at risk and prioritize remediation immediately.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WordPress websites under attack — expert report says dozens of plugins hijacked to target thousands of sites ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/wordpress-websites-under-attack-expert-report-says-dozens-of-plugins-hijacked-to-target-thousands-of-sites</link>
                                                                            <description>
                            <![CDATA[ A malicious actor found a struggling WordPress plugin company, bought it, and introduced malware to each product. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">283qMFw7YpBiC7TW6BmWwR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Apr 2026 16:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Person editing a WordPress site]]></media:text>
                                <media:title type="plain"><![CDATA[Person editing a WordPress site]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Malicious actor bought 31 WordPress plugins from Essential Plugin</strong></li><li><strong>Updates injected backdoors, granting full site access</strong></li><li><strong>Spam campaigns hidden from owners, C2 resolved via Ethereum smart contract</strong></li></ul><p>A hacker bought more than 30 legitimate <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a> and abused their good standing to infect tens of thousands of websites with backdoors. </p><p>Austin Ginder, founder of Anchor Hosting, reported how a client recently alerted him of a known plugin suddenly allowing unauthorized third-party access. The investigation led him to a somewhat troubling discovery: a company that developed 31 WordPress plugins, both free and premium versions, was sold in early 2025, to a person calling themselves “Kris”.</p><p>That person then added malicious code to all plugins and pushed the update to the WordPress websites actively using them.</p><h2 id="injecting-sophisticated-code">Injecting sophisticated code</h2><p>The malicious company is called Essential Plugin, and claims its products have been installed more than 400,000 times and were being actively used by more than 15,000 customers. The official WordPress repository shows more than 20,000 active WordPress installations. </p><p>The malware was essentially a backdoor that granted the attacker full access to the websites. The goal seems to have been to propagate existing spam campaigns:</p><p>“The injected code was sophisticated,” Ginder explained. “It fetched spam links, redirects, and fake pages from a command-and-control server. It only showed the spam to Googlebot, making it invisible to site owners. And here is the wildest part. It resolved its C2 domain through an Ethereum smart contract, querying public blockchain RPC endpoints. Traditional domain takedowns would not work because the attacker could update the smart contract to point to a new domain at any time.”</p><p>The full list of compromised plugins can be found on <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/" target="_blank">this link</a>. If you are using any of these, it would be wise to replace them with a safer alternative. Ginder also shared a patching method on his blog.</p><p>In the meantime, WordPress removed all of the malicious plugins from the repository.</p><p><em>Via </em><a href="https://techcrunch.com/2026/04/14/someone-planted-backdoors-in-dozens-of-wordpress-plugins-used-in-thousands-of-websites/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top WordPress Slider plugin hijacked to spread malware — here's what to look out for ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/top-wordpress-slider-plugin-hijacked-to-spread-malware-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ A tainted version was pushed as an update to more than 800,000 active websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9rrqMAPLMJDqcS4oQgrod</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yDX5VaYZa9C9jFuEEHgxiD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Apr 2026 09:57:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yDX5VaYZa9C9jFuEEHgxiD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Shutterstock]]></media:description>                                                            <media:text><![CDATA[WordPress on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yDX5VaYZa9C9jFuEEHgxiD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Smart Slider 3 plugin update compromised with backdoors</strong></li><li><strong>Malicious version 3.5.1.35 pushed to 800,000+ sites</strong></li><li><strong>Nextendweb urges rollback or upgrade to clean release</strong></li></ul><p>If you are using the Smart Slider 3 <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">plugin</a> for either WordPress or Joomla, make sure to update immediately, as experts have warned the tool was recently abused to distribute malware.</p><p>Nextendweb, the maintainers of Smart Slider 3, recently published a new security advisory, saying that on around April 7, 2026, unidentified threat actors broke into the system used for distributing patches, tainting the Pro version of the plugin with “multiple backdoors and persistence layers”, before pushing the poisoned version as an update to more than 800,000 websites.</p><p>An unknown number of websites likely installed the compromised version 3.5.1.35, before the developers spotted the attack and released a clean version - 3.5.1.36. Users are now urged to upgrade to this, or roll back to version 3.5.1.34. </p><h2 id="rolling-back-the-updates">Rolling back the updates</h2><p>“If you have an available backup point, we strongly recommend rolling back your server to a backup created before version 3.5.1.35,” the advisory reads. </p><p>“The compromised update was released by the attacker on April 7, 2026. Due to time zone differences, it is safest to restore from a backup dated April 5, 2026 or earlier.”</p><p>Nextendweb says the malicious plugin version includes multiple backdoors which allow threat actors to execute system commands remotely (via HTTP headers) or execute arbitrary PHP code via hidden request parameters. The backdoors also create a hidden admin user and hide it from the admin interface. Persistent backdoors were found in these locations: </p><p>wp-content/mu-plugins/object-cache-helper.php        </p><p>theme functions.php        </p><p>wp-includes/class-wp-locale-helper.php        </p><p>Finally, the backdoor can send site and credential data to an external server which is why, Nextendweb says, affected sites “should be considered fully compromised.”</p><p>Besides rolling back the update, there is a number of steps website admins should use to make sure their assets are cleaned, which can be found on <a href="https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise" target="_blank">this link</a>.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/smart-slider-updates-hijacked-to-push-malicious-wordpress-joomla-versions/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'A more secure, scalable platform that runs on modern infrastructure and supports AI-native workflows': Why Cloudflare's new EmDash is the "spiritual successor" to WordPress ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/a-more-secure-scalable-platform-that-runs-on-modern-infrastructure-and-supports-ai-native-workflows-why-cloudflares-new-emdash-is-the-spiritual-successor-to-wordpress</link>
                                                                            <description>
                            <![CDATA[ Cloudflare outlines its vision for EmDash as a modern CMS designed to improve security, support AI-native workflows, and modernize how websites are built and managed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XSECgttLR2gxk5uhNSdrJS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RNQPLK7aw68GurzYN6ijoG-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Apr 2026 18:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ desire.athow@futurenet.com (Desire Athow) ]]></author>                    <dc:creator><![CDATA[ Desire Athow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oEw3XiohQwun9z7gMxKzkB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Désiré has been musing and writing about technology during a career spanning four decades. He dabbled in &lt;a href=&quot;https://www.techradar.com/news/the-best-website-builder&quot;&gt;website builders&lt;/a&gt; and &lt;a href=&quot;https://www.techradar.com/web-hosting/best-web-hosting-service-websites&quot;&gt;web hosting&lt;/a&gt; when DHTML and frames were in vogue and started narrating about the impact of technology on society just before the start of the Y2K hysteria at the turn of the last millennium.&lt;/p&gt;&lt;p&gt;Then followed a weekly tech column in a local business magazine in Mauritius, a late night tech radio programme called &lt;a href=&quot;https://web.archive.org/web/20030414214749/http://www.clicplus.com/&quot;&gt;Clicplus&lt;/a&gt; and a freelancing gig at the now-defunct, Theinquirer, with the late Mike Magee as mentor. After an eight-year stint at ITProPortal.com, where he discovered the joys of global techfests and transformed the publication into one of the biggest tech B2B independent publishers, Désiré moved to TechRadar Pro where he has been the editor for nine years.&lt;/p&gt;&lt;p&gt;He has an affinity for anything hardware and staunchly refuses to stop writing reviews of obscure products or cover niche B2B software-as-a-service providers. He is an avid deal hunter and can be found lurking around on various deals forums.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Wayne Williams ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/RNQPLK7aw68GurzYN6ijoG-1280-80.png">
                                                            <media:credit><![CDATA[Cloudflare]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EmDash by Cloudflare]]></media:description>                                                            <media:text><![CDATA[EmDash by Cloudflare]]></media:text>
                                <media:title type="plain"><![CDATA[EmDash by Cloudflare]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RNQPLK7aw68GurzYN6ijoG-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloudflare’s <a href="https://www.techradar.com/pro/cloudflare-launches-emdash-the-spiritual-successor-that-wants-to-take-on-wordpress" target="_blank">recent launch of EmDash</a> marks one of the most ambitious attempts in years to rethink the foundations of content management on the web.</p><p><a href="https://www.techradar.com/pro/what-is-wordpress">WordPress</a> has dominated the space for nearly a quarter of a century, powering over 40% of all websites and allowing millions of people and businesses to publish content online. Its success helped democratize publishing, but its architecture — first introduced 24 years ago — was designed for a very different era of the internet.</p><p>Today’s web is shaped by serverless infrastructure, distributed computing, and increasingly by AI-driven workflows, and many of WordPress’s core assumptions no longer reflect that reality.</p><p>One of the most persistent challenges facing WordPress is security, particularly around plugins. While they have always been central to WordPress’s flexibility, they are also its greatest vulnerability.</p><h2 id="a-fully-open-source-serverless-cms">A fully open source, serverless CMS</h2><p>Industry data shows the overwhelming majority of WordPress security issues originate from plugins, largely because they run with broad access to a site’s core systems.</p><p>This creates a model where flexibility comes at the cost of trust, forcing administrators to rely heavily on reputation, manual reviews, and marketplace controls to decrease risk.</p><p>This is where EmDash comes in. Intended as a modern alternative, it has been built specifically to address these long-standing structural issues.</p><p>Designed as a fully open source, serverless <a href="https://www.techradar.com/best/cms">CMS </a>written in TypeScript, it introduces a fundamentally different plugin architecture in which extensions operate within isolated sandboxes and can only perform actions they explicitly request.</p><p>EmDash, which you can <a href="https://emdashcms.com/_emdash/admin" target="_blank" rel="nofollow">play around with here</a>, also reflects changes in how today's websites are built and managed, including native integration with AI tools, automated workflows, and new payment mechanisms for machine-to-machine access.</p><p>Rather than attempting to replace WordPress outright, EmDash represents an effort to evolve the publishing model. I spoke to <a href="https://www.linkedin.com/in/mattietk/" target="_blank">Matt Taylor</a>, Senior Product Manager at Cloudflare to find out more.</p><ul><li><strong>Let's start with the most obvious question. Why did Cloudflare decide to launch a "spiritual" successor to WordPress?</strong></li></ul><p>We built EmDash to modernize what WordPress started, for today’s web. WordPress was created over two decades ago for a very different Internet. Since then, hosting has shifted toward serverless infrastructure, where applications can scale to zero, and many capabilities that once required plugins — like storage, authentication, and payments  — are now built directly into the platform.</p><p>As a result, the plugin model has become both less necessary and an increasing security risk, while AI is reshaping how software is built and how content is created.</p><p>EmDash is designed to address these shifts directly: a more secure, scalable platform that runs on modern infrastructure and supports AI-native workflows.</p><ul><li><strong>Why choose to do it now, rather than before?</strong></li></ul><p>Because the economics of publishing are now under real pressure in ways they weren’t before. The Internet is entering an AI-driven phase where agents are consuming content at scale, often without attribution, visibility, or compensation for the creators. That puts publishers and content owners at risk of losing control over the very assets their businesses depend on.</p><p>Luckily, technology has reached a point where a different model is possible. With AI, serverless infrastructure, and new approaches to payments and access, there’s now an opportunity to rebuild how publishing works — so content can be discovered, protected, and monetized in a way that’s sustainable in an AI-driven Internet.</p><ul><li><strong>You already have Payload on Workers as a CMS product. What will happen to that project?</strong></li></ul><p>Payload is a CMS designed to be run ‘headless’, which means you bring your own frontend and link it up to Payload. EmDash, by comparison, is more like WordPress, in being full-stack and containing both a frontend and administration interface.</p><p>The Payload template is operated by the Payload team, who are now at Figma, and we expect no change to their support for that template.</p><ul><li><strong>Auttomatic has been very, very proactive when it comes to defending its brand. I assume that Cloudflare had a word with Matt Mullenweg before adopting the "spiritual successor to WordPress" tagline rather than say, alternative to WP.</strong></li></ul><p>As Matt <a href="https://ma.tt/2026/04/emdash-feedback/" target="_blank">noted in his blog post</a>, we met with him beforehand to give him a demo on what we were going to release to hear his thoughts. WordPress has done some incredible things for the Internet over its life, as we have said, but it is architecturally stymied, and is simply not the default choice of new developers.</p><p>We wanted to build something for this generation, which is spiritually to them what WordPress was to us when we were young developers.</p><ul><li><strong>What's the support plan for EmDash and how are you planning to develop the Em-Dash community?</strong></li></ul><p>Dynamic Workers are in public beta and have no free tier at the moment, but are included on the $5 Workers plan.</p><p>Cloudflare has a history of launching new products to paid customers first, before making them available via our generous free tier. For example, we just launched a free queues tier: <a href="https://developers.cloudflare.com/changelog/post/2026-02-04-queues-free-plan/" target="_blank">https://developers.cloudflare.com/changelog/post/2026-02-04-queues-free-plan/</a></p><ul><li><strong>You mentioned that your AI coding agents have built this entire platform in 60 days. Can you tell us more?</strong></li></ul><p>Agents are becoming more capable every day. Matt Kane orchestrated thousands of agentic sessions, each planning, coding, testing and verifying against one another. As with the work we did on Vitest, the experience required to understand good practice — and the quality of your specifications — are now some of the most important skills in software engineering.</p><p>A lot of what made up EmDash pre-release were dozens of files of extremely detailed instructions on what the system should do, how it should perform it, and how it would know when it didn’t hit the mark. This context is critical for agents.</p><ul><li><strong>WordPress is an open source project. EmDash is an open source project. Why didn't you contribute or get your own WP fork like others before?</strong></li></ul><p>EmDash was rebuilt from the ground up without using any WordPress code. That allowed us to address long-standing issues — particularly around plugin security and legacy architecture — and design for serverless environments from the start. It also enabled us to adopt a permissive license and create a system that is not constrained by past design decisions.</p><ul><li><strong>Why did Cloudflare choose the MIT license rather than GPL? Is it a deliberate move towards a more organized ecosystem?</strong></li></ul><p>We have noticed that the GPL license for WordPress, which is known as a ‘viral’ copyleft license, restricts the commercial opportunities around developing in its proximity, and we wanted to make EmDash more permissive.</p><p>Lawyers get very worried when you mention including GPL code at software companies, and we didn’t want EmDash to be on their radar.</p><ul><li><strong>What is the current roadmap for EmDash? How far are we from an autonomous CMS managed entirely by AI agents?</strong></li></ul><p>Closer than you might think: there are already plugins for CMSs like WordPress that are entirely autonomously operated, with humans providing the most basic of approvals. </p><p>From our perspective we’re more interested in how an AI agent can assist you in managing your CMS and its content. Though folks are welcome to build on the APIs we have in EmDash to provide an entirely autonomous CMS if they wish!</p><ul><li><strong>One of my colleagues highlighted the trend of infrastructure firms launching, buying or sponsoring OSS projects that run best or prioritize the vendor’s own stack. Is that sustainable? Is it in the spirit of OSS?</strong></li></ul><p>We want users to have a range of options for building on the web. Where we can support projects to broaden that range, we historically have to the benefit of the wider ecosystem.</p><p>As an example, vinext was created to address challenges with deploying Next.js outside of Vercel, but vinext was not built exclusively for Cloudflare and can improve the experience of Next.js users on other platforms like Netlify, AWS, and Google Cloud.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'I think EmDash was created to sell more Cloudflare services': WordPress co-founder Matt Mullenweg gives his verdict on Cloudflare's EmDash ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/i-think-emdash-was-created-to-sell-more-cloudflare-services-wordpress-co-founder-matt-mullenweg-gives-his-verdict-on-cloudflares-emdash</link>
                                                                            <description>
                            <![CDATA[ WordPress co-founder Mullenweg isn't too critical about EmDash or Cloudflare, says he sees it as a commercial opportunity, not a 'spiritual successor'. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QTsVWefw8wk9SvD5rbzYf3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ff3pwtEhN99YNuV3BLeNKa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Apr 2026 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Website Building]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ff3pwtEhN99YNuV3BLeNKa-1280-80.jpg">
                                                            <media:credit><![CDATA[Cloudflare]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EmDash]]></media:description>                                                            <media:text><![CDATA[EmDash]]></media:text>
                                <media:title type="plain"><![CDATA[EmDash]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ff3pwtEhN99YNuV3BLeNKa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Matt Mullenweg welcomes the competition, innovation and open-source nature of EmDash</strong></li><li><strong>He sees it as an opportunity for Cloudflare to plug its own services</strong></li><li><strong>Mullenweg says it's great, but it's not a 'spiritual successor'</strong></li></ul><p>Automattic and WordPress.com CEO Matt Mullenweg has weighed in on <a href="https://www.techradar.com/pro/cloudflare-launches-emdash-the-spiritual-successor-that-wants-to-take-on-wordpress" target="_blank">Cloudflare's launch of EmDash</a>, rejecting the company's claim that the new project is WordPress's spiritual successor.</p><p>In a <a href="https://ma.tt/2026/04/emdash-feedback/" target="_blank">blog post</a>, Mullenweg explains why EmDash isn't the <a href="https://www.techradar.com/news/the-best-website-builder">website builder's</a> spiritual successor, why EmDash hasn't solved the plug-in problem it criticized WordPress for, and how security issues can be fixed in the future.</p><p>"It’s all built on open source and web standards," he asserts. "You can run it anywhere; there’s no lock-in."</p><h2 id="mullenweg-rejects-emdash-claims">Mullenweg rejects EmDash claims </h2><p>Mullenweg explained WordPress can run anywhere, from a Raspberry Pi or a smartphone to a cheap server or across multiple hyperscaler data centers – it's all the same code. On the flip side, he sees EmDash as an opportunity to sell Cloudflare services.</p><p>Mullenweg uses the post to praise Cloudflare, noting the company's status as a "top engineering organization" that's pro-open-source. </p><p>All in all, he doesn't have a bad word to say about EmDash or Cloudflare in principle, however for interoperability and avoiding vendor lock-in, he notes that EmDash only runs optimally on Cloudflare.</p><p>As for the plug-in issue, Mullenweg explained that their unrestricted power is a feature, not a flaw, but artificial intelligence could significantly improve their security within the next 18 months.</p><p>"I actually think the product is very solid, there’s some excellent engineering, migration tools, it’s very fast, and the Astro integration is nice," he concludes.</p><p>So while EmDash isn't the spiritual successor to WordPress in Mullenweg's eyes, he welcomes the competition and supports that it's open-source. However, if there is to be a spiritual successor, it would be "even more open."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloudflare launches EmDash — the 'spiritual successor' that wants to take on WordPress ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/cloudflare-launches-emdash-the-spiritual-successor-that-wants-to-take-on-wordpress</link>
                                                                            <description>
                            <![CDATA[ Cloudflare says WordPress's plugin problem is out of hand – EmDash plugins take a different, more secure route. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5tXP4F4G7V25uxnj6s8gog</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ff3pwtEhN99YNuV3BLeNKa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Apr 2026 08:55:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Website Building]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ff3pwtEhN99YNuV3BLeNKa-1280-80.jpg">
                                                            <media:credit><![CDATA[Cloudflare]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EmDash]]></media:description>                                                            <media:text><![CDATA[EmDash]]></media:text>
                                <media:title type="plain"><![CDATA[EmDash]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ff3pwtEhN99YNuV3BLeNKa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cloudflare has launched its very own CMS – EmDash</strong></li><li><strong>EmDash plugins are secure by design, WordPress has a queue of 800 to test</strong></li><li><strong>WordPress users can easily migrate to the "AI native CMS" that is EmDash</strong></li></ul><p>Cloudflare has lifted the wraps off EmDash, a new open source <a href="https://www.techradar.com/best/cms">CMS</a> that it deems to be the "spiritual successor" to WordPress.</p><p>The company <a href="https://blog.cloudflare.com/emdash-wordpress/" target="_blank">explained</a> an overwhelming majority (96%) of WordPress vulnerabilities come from plugins, which have full access to the database and filesystem, and run in the same environment as the core code without any isolation.</p><p>To tackle this, Cloudflare is putting each EmDash plugin in an isolated sandbox, called Dynamic Workers, with plugins having to declare exactly which permission it needs upfront.</p><h2 id="cloudflare-says-emdash-is-more-secure-than-wordpress">Cloudflare says EmDash is more secure than WordPress</h2><p>In its announcement, Cloudflare criticized the fact that existing <a href="https://www.techradar.com/best/best-wordpress-plugins">WordPress plugins</a> must be trusted, and that their availability on centralized plugin marketplaces serves to give them a good reputation. WordPress.org currently manually reviews and approves every plugin for the platform, and there's a queue of around 800 plugins right now that need to be verified.</p><p>Instead of this trust, EmDash plugins must be secure by design. And because developers can ship plugins with any license running independently of EmDash that run in secure sandboxes, Cloudflare is able to do away with the marketplace lock-in it criticizes.</p><p>Better still, EmDash is built to the scale-to-zero principle, meaning that it only bills for CPU time when it's actually operating – "it scales back down to zero if there are no requests," the company wrote.</p><p>"We’ve bet on this architecture at Cloudflare in part because we believe in having low cost and free tiers, and that everyone should be able to build websites that scale," Senior Product Manager Matt Taylor and Senior Principal Systems Engineer Matt Kane added.</p><p>For the front end, EmDash is powered by Astro which allows users to build themes of pages, layouts, components, styles and and more.</p><p>Finally, Cloudflare describes EmDash as an "AI native CMS" that includes Agent Skills, CLI and a built-in MCP server.</p><p>Users wishing to migrate from WordPress can either import their WXR file or do so by, funnily enough, installing a plugin (EmDash Exporter).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Around 500,000 WordPress websites could be at risk from crucial plugin security flaw — here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/around-500-000-wordpress-websites-could-be-at-risk-from-crucial-plugin-security-flaw-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Hackers can read arbitrary files, including those containing passwords, with this newly discovered WordPress flaw. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Qeprkxwu22jKmkPcmTNT9D</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Mar 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Smart Slider 3 WordPress plugin (used on 800,000 sites) carried Arbitrary File Read flaw enabling access to sensitive server files</strong></li><li><strong>Vulnerability allowed even low-privileged accounts to exfiltrate credentials and configuration data via AJAX export functions</strong></li><li><strong>Patch released in version 3.5.1.34, but nearly 500K sites remain exposed; users urged to update immediately</strong></li></ul><p>A popular <a href="https://www.techradar.com/best/best-wordpress-plugins">WordPress plugin</a> used by hundreds of thousands of websites reportedly carried a vulnerability which allowed threat actors to steal sensitive information such as login credentials, experts have warned.</p><p>Smart Slider 3, which is currently active on more than 800,000 websites, allows users to create responsive, customizable sliders and visual content blocks without needing to code. </p><p>However Versions 3.5.1.33 and older were all vulnerable to an Arbitrary File Read flaw, which allows authenticated threat actors to access and read files on the server.</p><h2 id="patching-and-securing-websites">Patching and securing websites</h2><p>The vulnerability in Smart Slider 3 stems from missing permission checks in its AJAX export functions. Although a security token (nonce) exists, authenticated users can obtain it, allowing even low-privileged accounts (like subscribers) to trigger the export process. </p><p>The actionExportAll() function ultimately packages files into a downloadable .ZIP file using file_get_contents() without validating file type or source, and as a result, the attackers can include even arbitrary server files, such as sensitive configuration files (for example, wp-config.php). This lack of restrictions enables authenticated attackers to read confidential data stored on the server.</p><p>Since some of the files contain sensitive information, such as <a href="https://www.techradar.com/best/password-manager" target="_blank">credentials</a>, keys, or salt data, the vulnerability can be rather disruptive. But because the threat actors need to be authenticated to be able to pull off the attack, the vulnerability was given a medium severity score. However, some are saying that memberships and subscription options are “common” on many platforms these days, suggesting that the risk is greater than what the vulnerability’s severity score shows. </p><p>The bug was first spotted by security researcher Dmitrii Ignatyev in late February 2026, and <a href="https://www.wordfence.com/blog/2026/03/800000-wordpress-sites-affected-by-arbitrary-file-read-vulnerability-in-smart-slider-3-wordpress-plugin/" target="_blank">reported</a> to Wordfence in early March. He received a $2,200 bounty for his findings.</p><p>Nextendweb, the maintainers of Smart Slider 3, have released a patch with version 3.5.1.34, and at the time of writing, the latest version was downloaded exactly 308,575 times - meaning just under 500,000 websites are still vulnerable. </p><p>Currently, there are no reports of the bug being exploited in the wild, but users are advised to update their plugin as soon as possible to avoid being targeted.</p><h2 id="protecting-wordpress-websites">Protecting WordPress websites</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5472px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xwpEUtGigAH5K4krGZFy5K" name="blogging-2620148.jpg" alt="Person editing a WordPress site" src="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K.jpg" mos="" align="middle" fullscreen="" width="5472" height="3078" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">WordPress is a major website building platform </span><span class="credit" itemprop="copyrightHolder">(Image credit: Pixabay)</span></figcaption></figure><p>As a platform, WordPress is generally considered safe and without known major vulnerabilities. However, it operates a vast repository of third-party, user-built themes and plugins, split into free and premium categories. The latter ones usually come with a dedicated maintenance and development team and as such are regularly updated and hardened against attacks.</p><p>The free ones, on the other hand, are often built by enthusiasts, small teams, and freelance developers. Many of them are abandoned, unmaintained, or otherwise poorly managed, despite being popular among the users. As such, they create a huge security risk on one end, and attack opportunity on the other.</p><p>As a general rule of thumb, security researchers advise <a href="https://www.techradar.com/news/best-wordpress-hosting-providers" target="_blank">WordPress</a> users to keep their platform, themes, and plugins updated at all times. Furthermore, they suggest users only keep installed those themes and plugins they actively use and make sure to replace any default security and privacy settings.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/file-read-flaw-in-smart-slider-plugin-impacts-500k-wordpress-sites/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Premium WordPress plugin and theme have been compromised – here's how to check your website hasn't been infected ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-premium-wordpress-plugin-and-theme-have-been-compromised-heres-how-to-check-your-website-hasnt-been-infected</link>
                                                                            <description>
                            <![CDATA[ BuddyBoss had its update server compromised and used to push a poisoned update. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2Z2hamrdMYa3w3CfMpazUN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Mar 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ongoing cyberattack compromises BuddyBoss update system </strong></li><li><strong>Malicious updates steal admin credentials, Stripe keys, and databases</strong></li><li><strong>Hundreds of sites already hit; thousands more at risk, admins urged to disable auto-updates and rotate credentials</strong></li></ul><p>A major cyberattack against websites running the BuddyBoss <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> is currently ongoing, and users are urged to secure their assets or risk complete compromise and website takeover. </p><p>BuddyBoss is a WordPress platform and theme people can use to create online communities, membership sites, and e-learning platforms. It apparently has 50,000 customers, including 27,000 BuddyBoss Platform and BuddyBoss Theme package users. </p><p>According to Cybernews, an unidentified French-speaking threat actor somehow broke into the system that delivers software updates for BuddyBoss. There, they used Claude to help write malicious code and figure out how to push it to the update server. </p><h2 id="hundreds-of-compromised-sites">Hundreds of compromised sites</h2><p>Popular <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> such as Claude have strict guardrails that prevent this kind of abuse, but the attackers managed to trick it (likely by pretending it’s a harmless hacking challenge). </p><p>After managing to insert malware into the updates, they simply waited for users to install them, compromising their websites in the process. This attack was first spotted on March 19, it was said. The malware was designed to steal admin passwords and API keys, copy entire databases, and open a backdoor to grant remote control access. </p><p>According to Cybernews, some of the data already stolen in the campaign includes Stripe payment keys, making this campaign particularly worrisome. </p><p>Compromised versions are BuddyBoss Platform 2.20.3, and BuddyBoss Theme 2.19.2. All website admins using any of these are urged to temporarily disable automatic updates, revert to server backups made before updating to these versions, and then analyze their server logs for potential indicators of compromise. Finally, all passwords, API tokens, and other credentials, should be rotated as soon as possible.</p><p>Cybernews says “hundreds of websites” have already been compromised, with “thousands” more remaining in danger. At press time, at least 309 websites have had their credentials and databases exfiltrated.</p><p><em>Via </em><a href="https://cybernews.com/security/buddyboss-hack-compromises-hundreds-of-websites/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another worrying WordPress plugin security flaw could put 250,000 websites at risk ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/another-worrying-wordpress-plugin-security-flaw-could-put-250-000-websites-at-risk</link>
                                                                            <description>
                            <![CDATA[ WordPress plugin Ally was carrying an SQL injection flaw that allowed data exfiltration. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2apcdvQmSUP2MrKVxhm6Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Mar 2026 15:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ally WordPress plugin carried SQL injection flaw (CVE-2026-2413) </strong></li><li><strong>Vulnerability left ~246,600 sites exposed to data theft</strong></li><li><strong>Fixed in version 4.1.0; WordPress urges immediate updates</strong></li></ul><p>A popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> with hundreds of thousands of active installations carried a high-severity vulnerability that allowed malicious actors to steal sensitive data from websites, experts have warned.</p><p>Ally is a web accessibility tool from Elementor, released in November 2025 as a tool that not just identifies accessibility issues but also offers solutions and walks web admins through the process of applying them. </p><p>But according to security researcher Drew Webber from Acquia, Ally was carrying an SQL injection vulnerability that allows unauthenticated attackers to submit data to the SQL database without proper sanitation.</p><h2 id="thousands-of-vulnerable-websites">Thousands of vulnerable websites</h2><p>“This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database via time-based blind SQL injection techniques,” Webber noted.</p><p>The bug is tracked as CVE-2026-2413, and was given a severity score of 7.5/10 (high). It affects all versions up to 4.0.3, and was fixed on February 23, through the version 4.1.0. </p><p>Looking at the WordPress.org website, there are more than 400,000 active installations right now, with 38.4% (153,600) running the latest version. That leaves roughly 246,600 vulnerable websites. </p><p>WordPress is generally considered a safe <a href="https://www.techradar.com/pro/best-ai-website-builder">website builder</a> platform, with the majority of vulnerabilities coming from third-party plugins and themes. That is why most security professionals advise users only keep those plugins and themes that they’re using and make sure they’re updated at all times.</p><p>Besides upgrading Ally, users should also upgrade the platform itself, since it recently released the latest security update, with WordPress 6.9.2 fixing 10 vulnerabilities, including a cross-site request (XSS) flaw, an authorization bypass vulnerability, and a server-side forgery request (SSRF) bug. </p><p>WordPress urges its customers to install the latest version “immediately.”</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/sqli-flaw-in-elementor-ally-plugin-impacts-250k-plus-wordpress-sites/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'It’s a WordPress that stays with you': WordPress can now run within your browser, letting you build private websites not on the public web ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/its-a-wordpress-that-stays-with-you-wordpress-can-now-run-within-your-browser-letting-you-build-private-websites-not-on-the-public-web</link>
                                                                            <description>
                            <![CDATA[ You can now build your fully private, local website with WordPress that's stored directly within your browser. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KkKf5QZrbVMzv86umEHsyH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dj437MMN4qEc4aVRGxmnE9-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Mar 2026 12:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/dj437MMN4qEc4aVRGxmnE9-1280-80.png">
                                                            <media:credit><![CDATA[WordPress]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on light blue background]]></media:description>                                                            <media:text><![CDATA[WordPress logo on light blue background]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on light blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dj437MMN4qEc4aVRGxmnE9-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress Playground lets you build fully local, non-published websites</strong></li><li><strong>Sites are limited to 100MB and are stored locally, per-device</strong></li><li><strong>You can still use WordPress plugins</strong></li></ul><p>WordPress has announced the launch of my.WordPress.net – a new service that lets the <a href="https://www.techradar.com/pro/best-ai-website-builder">website builder</a> run entirely within a web browser, meaning you can create a totally private website-style interface without it ever appearing on the public internet.</p><p>It's build on WordPress Playground, a project that lets WordPress run locally, so users won't need to choose a <a href="https://www.techradar.com/best/eu-web-hosting">hosting provider</a> or register a domain.</p><p>Because these new types of site run locally within the <a href="https://www.techradar.com/best/browser">browser</a> storage, they'll be device-specific and cannot be accessible from your other devices.</p><h2 id="wordpress-lets-you-create-a-local-website-within-your-browser">WordPress lets you create a local website within your browser</h2><p>However, is users end up so impressed by their own work that they want to make it public, they can shift it to a WordPress host if they want to publish it on the internet, because the site itself will have already been built using the familiar WordPress tools.</p><p>The local sites are primarily designed for personal workspaces, though, covering tasks like journalling, researching or prototyping. </p><p>They're also ideal for learning how to WordPress without committing to hosting expenses. "It offers a fast, commitment-free way to explore, learn, and build, whether the result is a long-term personal project or something that eventually moves elsewhere," WordPress wrote in an <a href="https://wordpress.org/news/2026/03/announcing-my-wordpress/ " target="_blank">announcement</a>.</p><p>WordPress even detailed how users can connect with extra plugins to use all of the same tools you'd usually get with WordPress, but on a local scale.</p><p>There are some limitations though, including local storage, which starts at around 100MB. First launch also takes longer while WordPress downloads into the browser, and because it's not stored with a hosting provider, it's recommended that users backup their sites regularly.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers hijack WordPress sites to spread malware using fake CAPTCHA ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-hijack-wordpress-sites-to-spread-malware-using-fake-captcha</link>
                                                                            <description>
                            <![CDATA[ A ClickFix attack can come in all shapes and sizes, including through compromised WordPress websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dWsfrzjcxwuKC9w8fAgsQh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Mar 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Rapid7 uncovers large-scale WordPress hijacking campaign </strong></li><li><strong>Fake Cloudflare CAPTCHA tricks visitors into running malware</strong></li><li><strong>More than 250 sites compromised, including a US Senate candidate’s page</strong></li></ul><p>Cybercriminals are hijacking vulnerable WordPress websites left and right and turning them into launchpads for <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> deployment, experts have warned.</p><p>Security researchers Rapid7 claim to have spotted an ongoing, automated, large-scale campaign that even affected an unnamed US Senate candidate.</p><p>As per the researchers, the crooks first scan the web for vulnerable WordPress websites. There can be a myriad of things, from default or poor admin login credentials to unpatched themes and <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugins</a> with widely available exploit solutions, that are being used to gain initial access.</p><h2 id="deploying-an-infostealer">Deploying an infostealer</h2><p>The campaign likely started in December 2025 and has so far affected more than 250 websites around the world.</p><p>Once inside, the crooks would do their best not to raise any alarms. Nothing on the site actually gets changed - the only thing they do is add a fake Cloudflare CAPTCHA at first visit. This is such a common, usual practice these days that most people don’t think twice about it, they just complete the puzzle, confirm they’re not a robot, and go about their day.</p><p>But the manner in which users are asked to solve the CAPTCHA should be a huge red flag. Instead of clicking a box or sliding a slider, they are asked to copy and paste a command into Windows Run, in classic ClickFix fashion.</p><p>So, instead of proving they’re human, the visitors end up downloading and running malware themselves. In this case, an infostealer designed to exfiltrate login credentials, authentication cookies, cryptocurrency wallet information, and other sensitive data. </p><p>Rapid7 says the campaign is likely highly automated and doesn’t target any specific industry. Regional media outlets, small business websites, and even a US Senate candidate’s official webpage, were among the confirmed cases. </p><p>"The large-scale execution of the compromise across completely unrelated WordPress instances suggests a high level of automation by the threat actor and is likely part of an organized long-term criminal effort," Rapid7 said in its report. </p><p><em>Via </em><a href="https://www.theregister.com/2026/03/10/crooks_hijack_wordpress_sites/" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers exploiting WordPress membership plugin bug to create admin accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-exploiting-wordpress-membership-plugin-bug-to-create-admin-accounts</link>
                                                                            <description>
                            <![CDATA[ A popular WordPress plugin can be abused to take over websites - with thousands of sites reportedly  vulnerable. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2yFPKdZLEC2aBnFC7qncb7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Mar 2026 17:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Critical flaw found in WordPress plugin allowing attackers to register admin accounts unauthenticated</strong></li><li><strong>Over 37,000 sites currently exposed</strong></li></ul><p>Tens of thousands of <a href="https://www.techradar.com/news/best-wordpress-theme">WordPress</a> websites are vulnerable to full site takeover, thanks to a critical-severity vulnerability just discovered in a popular plugin.</p><p>Security researchers at Defiant reported finding a bug in User Registration & Membership, a <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> which helps admins create subscription plans, control user access, and accept payments. The bug is due to the plugin accepting user-supplied roles during membership registration, without properly enforcing a server-side allowlist. </p><p>As a result, unauthenticated attackers can create admin accounts by supplying a role value at registration.</p><h2 id="actively-abused">Actively abused</h2><p>The bug is described as “improper privilege management” and is now tracked as CVE- 2026-1492. It has a severity score of 9.8/10 (critical) and affects all versions of the plugin up to, and including, 5.1.2. It was fixed in version 5.1.3 which is now available for download.</p><p>The researchers said they saw more than 200 attempts to exploit this vulnerability in just 24 hours, suggesting that cybercriminals are well aware of the flaw and are actively looking for exposed websites. </p><p>The attack surface is rather large, too, as according to the official WordPress repository, User Registration & Membership is installed on more than 60,000 active websites, and the vast majority (62.7%) are running versions 4.4 and older. </p><p>That means at least 37,000 websites are currently susceptible to the improper privilege management bug.</p><p>To make matters worse, the plugin page does not differentiate between versions 5.1.2 and 5.1.3, so it is quite possible that the actual number of vulnerable websites is even greater. </p><p>With an admin account, threat actors can wreak all sorts of havoc, from exfiltrating sensitive data, to using the website as a host for malware. They can also redirect legitimate traffic to malicious websites ridden with ads, can trick users into sharing login credentials, and more. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/wordpress-membership-plugin-bug-exploited-to-create-admin-accounts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WordPress has a new AI assistant to help you build your dream website ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/wordpress-has-a-new-ai-assistant-to-help-you-build-your-dream-website</link>
                                                                            <description>
                            <![CDATA[ WordPress AI Assistant will generate and edit text and images, but it will also make site changes far easier. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">B7QR8CdgzQny8ACNtR2AAU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/67cyf8naXSw7J5oGS6by5P-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Feb 2026 10:40:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/67cyf8naXSw7J5oGS6by5P-1280-80.png">
                                                            <media:credit><![CDATA[Automattic/WordPress.com]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress AI Assistant]]></media:description>                                                            <media:text><![CDATA[WordPress AI Assistant]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress AI Assistant]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/67cyf8naXSw7J5oGS6by5P-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress.com now uses AI to make site layout changes with natural language prompts</strong></li><li><strong>Nano Banana image generation and editing is integrated with the media library</strong></li><li><strong>It's available to use now, but you need to turn it on in settings</strong></li></ul><p>Set against a background of other AI-powered <a href="https://www.techradar.com/news/the-best-website-builder">website builders</a>, WordPress.com has launched its own AI Assistant, and it covers more than just generating copy.</p><p>The company explains its new assistant will be able to understand a site's content and layout, therefore users can make more complex changes with simple natural language prompts.</p><p>"No copy-pasting, no prompt engineering, and no code to figure out what to do with," Head of AI Ronnie Burt wrote in a <a href="https://wordpress.com/blog/2026/02/17/wordpress-ai-assistant/" target="_blank">blog post</a>.</p><h2 id="wordpress-com-launches-its-own-ai-assistant">WordPress.com launches its own AI Assistant</h2><p>WordPress.com highlighted three key areas where its AI Assistant can help: creating and editing content with context, generating and tweaking images, and colleague-style collaboration. Some of the changes handled include adjusting layouts, styles, colors, fonts and page structure, as well as other copy-related tasks like generating and translating text.</p><p>On the page editor front, WordPress.com shows examples of the AI Assistant making changes based on pretty loose, unspecific commands, such as 'Make this section feel more modern and spacious'.</p><p>Besides generating text, AI Assistant can also generate and edit images using Google's Nano Banana models directly within the media library without having to use third-party platforms.</p><p>Burt also pointed to the new block notes editor that launched with WordPress 6.9, which provides colleagues with a space to collaborate and share comments. Unsurprisingly, the AI Assistant also plays a role here, where it can do things like fact-check or make edit suggestions.</p><p>WordPress AI Assistant is now generally available, but users must opt in via Sites > Settings > AI tools. Sites already built using the AI website builder option will have AI Assistant enabled by default.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nearly a million WordPress websites could be at risk from this serious plugin security flaw ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/nearly-a-million-wordpress-websites-could-be-at-risk-from-this-serious-plugin-security-flaw</link>
                                                                            <description>
                            <![CDATA[ WPvivid Backup & Migration plugin allows for arbitrary file upload which can lead to remote code execution. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x7CP6FrzEFJp89AfNp9TLA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Feb 2026 18:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WPvivid Backup & Migration plugin vulnerable to critical RCE flaw CVE-2026-1357 </strong></li><li><strong>Exploitation requires “receive backup from another site” option enabled, with 24-hour attack window</strong></li><li><strong>Patch released in version 0.9.123 (Jan 28); users urged to upgrade immediately</strong></li></ul><p>WPvivid Backup & Migration, a <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> with almost a million installs, is vulnerable to a critical-severity flaw that allows threat actors to run malicious code remotely. </p><p>Although it sounds ominous, the bug has a few limitations that make exploitation somewhat difficult.</p><p>The affected WordPress plugin lets users create site backups, restore them, and migrate sites to new domains or hosts. The core features are available for free, with optional premium upgrades for more advanced functions. It currently counts more than 900,000 active installations and more than 20,000 customers. </p><h2 id="exploiting-and-patching">Exploiting and patching</h2><p>However security researchers Defiant found the plugin suffers from improper error handling in the RSA decryption process, combined with a lack of path sanitization. As a result, threat actors could upload arbitrary files to the server without authentication, achieving remote code execution (RCE).</p><p>The bug is tracked as CVE-2026-1357 and has a severity score of 9.8/10 (critical). It affects all versions up to 0.9.123, which was released on January 28.</p><p>While all users are advised to upgrade to a safe version as soon as possible, exploiting this vulnerability is not as easy as it sounds. Only sites that have “receive backup from another site” option enabled are vulnerable, and this feature is not turned on by default.</p><p>What’s more, the miscreants only have 24 hours to attack, given that the key the other sites need to send backup files expires after a day. </p><p>Unfortunately, there is no way to tell exactly how many, of the 900,000 active installations, are vulnerable. The official WordPress plugin website only shows installations of version 0.9, without further segmentation. It does state that since January 28, the day of the patch, up until today, the plugin was downloaded roughly 200,000 times.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/wordpress-plugin-with-900k-installs-vulnerable-to-critical-rce-flaw/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WP Engine-Automattic feud resurfaces with new claims of royalty fees and contract threats ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/wp-engine-automattic-feud-resurfaces-with-new-claims-of-royalty-fees-and-contract-threats</link>
                                                                            <description>
                            <![CDATA[ WP Engine just updated its legal claim against Automattic, but CEO Matt Mullenweg isn't concerned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GaXNdd632XzTwVkk5iUkxD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jShHytzgXpisqwvcR5wiDo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Feb 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jShHytzgXpisqwvcR5wiDo-1280-80.jpg">
                                                            <media:credit><![CDATA[WP Engine]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WP Engine logo on a blue background]]></media:description>                                                            <media:text><![CDATA[WP Engine logo on a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[WP Engine logo on a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jShHytzgXpisqwvcR5wiDo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WP Engine says Automattic went after 10 other companies for royalties</strong></li><li><strong>Stripe was approached to end its WP Engine contract, the hosting platform alleges</strong></li><li><strong>Automattic says this is just an attempt to revive old complaints that have been dismissed</strong></li></ul><p>WP Engine has filed a <a href="https://wpengine.com/wp-content/uploads/2026/02/WPE-TAC.pdf?__hstc=18273766.cda06320b2bd5cc7dc5c04280f5283b1.1770978531855.1770978531855.1770978531855.1&__hssc=18273766.2.1770978531855&__hsfp=45e3d3d5b362918c2a2c7ba5107d967c&_gl=1*u5vcm4*_gcl_au*NTkyODcyMDMwLjE3NzA5Nzg1MzA.*_ga*MzIxNjEzNTE2LjE3NzA5Nzg1MzE.*_ga_QQ5FN8NX8W*czE3NzA5Nzg1MzAkbzEkZzEkdDE3NzA5Nzg1NDMkajQ3JGwwJGg3NTMzNzQ1MjA." target="_blank">third update</a> to its complaint against Automattic and CEO Matt Mullenweg, focusing on the WordPress trademark and whether WP Engine contributes enough to the open source platform.</p><p>Mullenweg had previously demanded 8% of WP Engine's monthly gross revenue as a royalty to use the WordPress brand on the basis that it wasn't giving enough to the <a href="https://www.techradar.com/best/best-open-source-software">open source</a> platform, but WP Engine sued with allegations of abuse of power.</p><p>The latest update claims Mullenweg had also planned to target 10 other <a href="https://www.techradar.com/web-hosting/best-free-web-hosting">hosting</a> companies with similar royalty demands.</p><h2 id="wp-engine-updates-its-complaint-against-automattic">WP Engine updates its complaint against Automattic</h2><p>"WP Engine’s Third Amended Complaint contains newly unredacted information uncovered during discovery which had been previously sealed at the request of the Defendants," the hosting company wrote in a <a href="https://wpengine.co.uk/blog/ensuring-stability-and-security/" target="_blank">blog update</a>.</p><p>The complaint says that Newfold Digital is already paying Automattic for trademark use – names of the other companies were redacted.</p><p>WP Engine even alleges that Mullenweg had tried to pressure Stripe into cancelling WP Engine's payment processing contract after the lawsuit was filed.</p><p>In response, Automattic says the renewed filing is just an attempt to repackage old allegations, and that it's confident the courts will reject them. "There is nothing new here. This is the same narrative WP Engine has been pushing for over a year, and the Court has already dismissed many of its central claims," an Automattic spokesperson added.</p><p>In November 2025, WP Engine filed to dismiss counterclaims issued by Automattic, Matt Mullenweg, the WordPress Foundation and WooCommerce.</p><p>Previous updates include "new facts uncovered during discovery" in a second amendment and antitrust claims in a first amendment.</p><p>"The Court’s Motion to Dismiss ruling permits the majority of WP Engine’s claims, including the intentional interference, unfair competition, and defamation claims, to proceed," WP Engine added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 40,000 WordPress sites affected by new malware flaw - find out if you're affected ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/more-than-40-000-wordpress-sites-affected-by-new-malware-flaw-find-out-if-youre-affected</link>
                                                                            <description>
                            <![CDATA[ A popular WordPress quiz plugin can be abused to mount SQL injection attacks, but a patch is available. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7iNKYKMiBizGKW2JcZz85M</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Feb 2026 18:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>An SQL injection flaw in QSM plugin versions 10.3.1 and below was found </strong></li><li><strong>Vulnerability allows logged-in users (Subscriber or higher) to extract sensitive database data</strong></li><li><strong>WordPress admins urged to update QSM to v10.3.2 or newer to mitigate risk</strong></li></ul><p>If your website is running the Quiz and Survey Master <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a>, you might want to update it to the latest version, or risk a possible cyberattack.</p><p>QSM lets users create quizzes, surveys, and forms without coding, with more than 40,000 websites actively using it - but recently, it was discovered versions 10.3.1 and older were vulnerable to an SQL injection flaw which allowed any logged-in user to inject commands into the database.</p><p>A security advisory from Patchstack noted this means any user with a “subscriber” account, or one with higher privileges, could perform a wide array of unwanted actions on vulnerable websites, including data exfiltration. </p><h2 id="how-many-websites-are-vulnerable">How many websites are vulnerable?</h2><p>Users are advised to update to this, or any newer version, as soon as possible. As per data on the official WordPress.org website, the newest version is 10.3.5.</p><p>Unfortunately, there is no way of telling exactly how many websites are patched, and how many remain vulnerable. Official numbers are showing that a slim majority - 52.1% - are running version 10.3, which means that at least 47.9% - which equals 19,160 websites - are definitely vulnerable. Of the remaining 39,980, at least some are running the vulnerable version 10.3.1.</p><p>Right now, there is no evidence of the flaw being abused in the wild, but given its popularity, it is safe to assume that threat actors will now start scanning for websites using QSM. The bug is now tracked as CVE-2025-67987 and was fixed in version 10.3.2. </p><p>As a general rule of thumb, WordPress users should always keep their <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website builder</a> platforms updated, as well as any plugins and themes they are using. Security professionals also advise that all plugins and themes that are not actively being used be deleted from the servers entirely. </p><p><em>Via </em><a href="https://www.infosecurity-magazine.com/news/wordpress-sql-injection-flaw-40000/" target="_blank"><em>Infosecurity Magazine</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 50,000 WordPress site affected in major plugin security flaw - here's how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/50-000-wordpress-site-affected-in-major-plugin-security-flaw-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A popular WordPress plugin has a worrying flaw which could allow website takeover. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hJmPDMi2qe3dnoe4cYigFZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 21 Jan 2026 19:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Critical bug in ACF: Extended WordPress plugin allows arbitrary role escalation to administrator</strong></li><li><strong>About 50,000 WordPress sites are vulnerable despite patch in version 0.9.2.2</strong></li><li><strong>No exploitation reported yet, but attackers likely to probe exposed sites soon</strong></li></ul><p>Around 50,000 <a href="https://www.techradar.com/pro/what-is-wordpress">WordPress</a> websites are currently at risk of full site takeover, due to a critical-severity vulnerability that was recently discovered in a popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">plugin</a>.</p><p>In mid-December 2025, Wordfence was notified by security researcher Andrea Bocchetti of a vulnerability in Advanced Custom Fields: Extended, a plugin which adds more features to the Advanced Custom Fields (ACF) plugin.</p><p>ACF also lets users add custom fields to posts and pages, and it is currently being actively used by around 100,000 WordPress websites.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Bocchetti said that the bug stems from role restrictions not being enforced properly during form-based user creation, or updates.</p><p>"In the vulnerable version, there are no restrictions for form fields, so the user's role can be set arbitrarily, even to 'administrator', regardless of the field settings, if there is a role field added to the form," Wordfence explained in its advisory.</p><p>"As with any privilege escalation vulnerability, this can be used for complete site compromise.”</p><p>In other words, any unauthenticated user can set themselves as admins for a WordPress site, essentially taking over the site.</p><p>The vulnerability was discovered in versions 0.9.2.1 and earlier and is now being tracked as CVE-2025-14533. It was given a severity score of 9.8/10 (critical). </p><p>The silver lining is that it cannot be exploited easily. The sites need to use a ‘Create User’ or ‘Update User’ form with a role field mapped. </p><p>The bug was remedied in version 0.9.2.2. According to WordPress’ official stats, approximately 50,000 websites have already updated to the newest version, leaving roughly the same number of those that are still vulnerable. </p><p>At press time, there was no evidence of the flaw being abused in the wild, but now that the news is out there, it is safe to assume that cybercriminals will start at least probing for vulnerabilities.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/acf-plugin-bug-gives-hackers-admin-on-50-000-wordpress-sites/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers exploit WordPress plugin security flaw exposing 40,000 websites to complete takeover risk - here's how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-exploit-wordpress-plugin-security-flaw-exposing-40-000-websites-to-complete-takeover-risk-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Critical WordPress plugin flaw exposed some 40,000 users to risk of a complete website takeover. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SavbrrsknCdjhTFevdo4ea</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Jan 2026 11:24:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Patchstack found critical Modular DS flaw (CVE-2026-23550) allowing admin bypass</strong></li><li><strong>Vulnerability scored 10/10 and is already being exploited in the wild</strong></li><li><strong>Vendor released fix in version 2.5.2; users urged to upgrade immediately</strong></li></ul><p>If your <a href="https://www.techradar.com/news/best-wordpress-hosting-providers" target="_blank">WordPress</a> website is running the Modular DS plugin, you might want to update to the latest version as soon as possible.</p><p>Modular DS is a popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> used by more than 40,000 websites which allows website admins manage multiple WordPress sites from a single dashboard.</p><p>However security researchers Patchstack recently discovered its versions 2.5.1 and older carried design and implementation vulnerabilities which exposed multiple sensitive routes and activated an automatic login fallback mechanism. </p><h2 id="evidence-of-attacks">Evidence of attacks</h2><p>These vulnerabilities include direct route selection, bypassing of authentication mechanisms, and auto-login as admin, the researchers explained. As a result, malicious actors could have bypassed all authentication mechanisms remotely and access the compromised websites with an administrator account. </p><p>“As soon as the site has already been connected to Modular (tokens present/renewable), anyone can pass the auth middleware: there is no cryptographic link between the incoming request and Modular itself,” Patchstacak explained. </p><p>“This exposes several routes [...] which allow various actions to be performed, ranging from remote login to obtaining sensitive system or user data.”</p><p>The vulnerability is now tracked as CVE-2026-23550 and was given a severity score of 10/10 (critical). </p><p>In its write-up, Patchstack said the flaw is already being exploited in the wild, and that first attacks were detected on January 13, 2026, citing WP.one Support Engineer’s team. The Modular DS vendor was notified on January 14 (a day after the first attacks were confirmed), and it came back with a fix “only a few hours later.”</p><p>The fix brought Modular DS to version 2.5.2, and users are now advised to upgrade without delay. </p><p>“We strongly recommend that all Modular DS installations ensure they are running this version as soon as possible and complete the following actions,” Modular DS said in a security advisory. </p><p>The actions advised include reviewing potential indicators of compromise (which can be found <a href="https://help.modulards.com/en/article/modular-ds-security-release-modular-connector-252-dm3mv0/" target="_blank"><u>here</u></a>), regenerating WordPress salts, regenerating OAuth credentials, and scanning the site for malicious plugins or files. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-modular-ds-wordpress-plugin-flaw-for-admin-access/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Year, new site: how to launch on a budget this weekend ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/website-hosting/new-year-new-site-how-to-launch-on-a-budget-this-weekend</link>
                                                                            <description>
                            <![CDATA[ How to create a website on a budget before the end of the first weekend of 2026. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">L3c2UzE2s6VcdVW8zQAbET</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ofbpPnV7UobAzV72bimDUR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Jan 2026 18:30:00 +0000</pubDate>                                                                                                                                <updated>Mon, 05 Jan 2026 09:21:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Website Hosting]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Capell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/h2jxs4impEB7K2rxEpTRy4.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ofbpPnV7UobAzV72bimDUR-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a 2026 to do list that includes website, domain name, and web hosting]]></media:description>                                                            <media:text><![CDATA[An image of a 2026 to do list that includes website, domain name, and web hosting]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a 2026 to do list that includes website, domain name, and web hosting]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ofbpPnV7UobAzV72bimDUR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>2026 is here, and with it - new business ideas, which all need a home online. </p><p>You've got two main options: hosting a website yourself with one of the <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">best web hosting providers</a> or using one of the <a href="https://www.techradar.com/news/the-best-website-builder">best website builders</a> around today.</p><p>The best website builders are platforms that help you build a website and include a bunch of business tools to help you manage your business. The best web hosting providers give you server space and the freedom to install the tools that you want to make your website and manage your business.</p><p>Website builders give you everything you need pre-configured and integrated but they're more expensive and less flexible. Web hosting is cheaper and gives you more choice - but what is the use of choice if you don't understand the options? In this article I'll unpack them to make it simple and easy to host your own site.</p><h3 class="article-body__section" id="section-web-hosting-providers"><span>Web hosting providers</span></h3><p>The first choice is which web hosting provider to use - and for this article, I've narrowed this down to three providers. <a href="https://www.techradar.com/reviews/hostinger">Hostinger</a>, <a href="https://www.techradar.com/reviews/bluehost">Bluehost</a>, and <a href="https://www.techradar.com/reviews/namecheap">Namecheap</a>.</p><p>Hostinger has one of the most complete web hosting packages that makes it comparable to a website builder and they have their own website builder too. It has very low starter prices but renewal prices are high compared to other hosting options.</p><p>Bluehost has, in my opinion, one of the best WordPress page builders on the market making created WordPress sites super easy. The hosting packages are less complete, starter prices are also low but renewal and add-ons do increase the price later on.</p><p>Namecheap, as the name would suggest, is cheap and has everything you need but the user experience is not as friendly as the above options.</p><p>After going over the pros and cons of these three providers I'll throw in a website builder comparison.</p><h3 class="article-body__section" id="section-hostinger"><span>Hostinger</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1512px;"><p class="vanilla-image-block" style="padding-top:55.89%;"><img id="N3ZG7t3zoTLpMjEtqhd793" name="Hostinger hPanel" alt="An image of Hostinger's control panel" src="https://cdn.mos.cms.futurecdn.net/N3ZG7t3zoTLpMjEtqhd793.jpg" mos="" align="middle" fullscreen="" width="1512" height="845" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><h2 id="what-you-get">What you get</h2><p>On the most basic Premium plan ($1.99/mo for 48 months, then $12.99/mo), Hostinger should give you everything you need for a weekend launch. </p><p>Other plans give you more features, support more website, and provide more performance, but the Premium plan should be fine, as it includes:</p><p><strong>A free domain for one year -</strong> When you use the domain from Hostinger you don't need to configure or do anything other than find a domain name that's available. When it comes to the subsequent years, using the domain from Hostinger is slightly more costly than using one of the <a href="https://www.techradar.com/news/best-domain-registrars">best domain registrars</a> to manage your domain name but you will need to configure it yourself (easy if you want to).</p><p><strong>20 GB of storage</strong> - This should be plenty of storage for most websites.</p><p><strong>2 mail boxes per website</strong> - Be aware that these are only free for one year.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1472px;"><p class="vanilla-image-block" style="padding-top:55.64%;"><img id="mmyR44CEeMvQg2Fqahf5PT" name="Hostinger set up questions" alt="Hostinger set up questions" src="https://cdn.mos.cms.futurecdn.net/mmyR44CEeMvQg2Fqahf5PT.jpg" mos="" align="middle" fullscreen="" width="1472" height="819" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p><strong>Website building options - </strong>You can use an AI website builder for WordPress - just WordPress, or Hostinger's Website Builder. I'd recommend the AI website builder for WordPress, or just WordPress because you have more flexibility. </p><p>All of these options can be installed easily with one click and don't require any additional configurations. </p><p>You can check out a step by step process on how to create a site with Hostinger in my <a href="https://www.techradar.com/pro/website-hosting/hostinger-in-60-minutes-learn-from-these-rookie-mistakes">60 Minutes with Hostinger</a> article.</p><div class="product"><a data-dimension112="65b29e60-da6d-46ca-812b-b9e5c9073cc0" data-action="Deal Block" data-label="Premium: $1.99/mo for 48 months. Then $12.99/moBusiness: $2.99/mo for 48 months. Then $18.99/moCloud Startup: $6.99/mo for 48 months. Then $27.99/mo" data-dimension48="Premium: $1.99/mo for 48 months. Then $12.99/moBusiness: $2.99/mo for 48 months. Then $18.99/moCloud Startup: $6.99/mo for 48 months. Then $27.99/mo" data-dimension25="$" href="https://www.hostinger.com/pricing" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:400px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="9yibz3G6ywPZXmbmQkLvBb" name="pSjdfVRf_400x400.jpeg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/9yibz3G6ywPZXmbmQkLvBb.jpeg" mos="" align="middle" fullscreen="" width="400" height="400" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong>Premium</strong>: $1.99/mo for 48 months. Then $12.99/mo<br><strong>Business</strong>: $2.99/mo for 48 months. Then $18.99/mo<br><strong>Cloud Startup</strong>: $6.99/mo for 48 months. Then $27.99/mo<a class="view-deal button" href="https://www.hostinger.com/pricing" target="_blank" rel="nofollow" data-dimension112="65b29e60-da6d-46ca-812b-b9e5c9073cc0" data-action="Deal Block" data-label="Premium: $1.99/mo for 48 months. Then $12.99/moBusiness: $2.99/mo for 48 months. Then $18.99/moCloud Startup: $6.99/mo for 48 months. Then $27.99/mo" data-dimension48="Premium: $1.99/mo for 48 months. Then $12.99/moBusiness: $2.99/mo for 48 months. Then $18.99/moCloud Startup: $6.99/mo for 48 months. Then $27.99/mo" data-dimension25="$">View Deal</a></p></div><h3 class="article-body__section" id="section-bluehost"><span>Bluehost</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1483px;"><p class="vanilla-image-block" style="padding-top:68.31%;"><img id="mhkhwBhGCQZgsiPeKdfYtB" name="bluehost-dashboard-home" alt="Bluehost control panel home" src="https://cdn.mos.cms.futurecdn.net/mhkhwBhGCQZgsiPeKdfYtB.jpg" mos="" align="middle" fullscreen="" width="1483" height="1013" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><h2 id="what-you-get-2">What you get</h2><p>On Bluehost's Starter plan ($3.99/mo for 36 months, then $9.99/mo), you also get everything you should need for a straightforward launch.</p><p><strong>A free domain for one year -</strong> As with Hostinger, it is easy enough to use this free domain for a year - but you might want to check out other options at a later date.</p><p><strong>10GB of storage - </strong>Less than Hostinger, but still plenty of storage for most websites.</p><p><strong>Pro Email - </strong>Only free for a year, and then an additional $2.99/mo after.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1831px;"><p class="vanilla-image-block" style="padding-top:45.11%;"><img id="5eqnPvFsaP8noc7jgeWqWa" name="WonderBlocks" alt="An image of Bluehost's WonderBlocks UI" src="https://cdn.mos.cms.futurecdn.net/5eqnPvFsaP8noc7jgeWqWa.jpg" mos="" align="middle" fullscreen="" width="1831" height="826" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p><strong>Website building options - </strong>Bluehost just provides an AI builder for WordPress, and I think it's better than Hostinger's AI WordPress site building tool. </p><p>WonderBlocks makes it really easy to edit and modify WordPress sites - and you can read my <a href="https://www.techradar.com/pro/website-hosting/bluehost-in-60-minutes-making-wordpress-hosting-easier">60 Minutes with Bluehost</a> article to see how easy it is to build and manage a website with this option.</p><div class="product"><a data-dimension112="370ec411-eff3-4d7d-aef0-9f6f1090f4c1" data-action="Deal Block" data-label="Starter: $3.99/mo for 36 months. Then $9.99/moBusiness: $6.99/mo for 36 months. Then $13.99/moeCommerce Essentials: $14.99/mo for 36 months. Then $21.99/mo" data-dimension48="Starter: $3.99/mo for 36 months. Then $9.99/moBusiness: $6.99/mo for 36 months. Then $13.99/moeCommerce Essentials: $14.99/mo for 36 months. Then $21.99/mo" data-dimension25="$" href="https://www.bluehost.com/web-hosting" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YEReGg8S6U4kvhZWLWXxkA" name="bluehost new.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/YEReGg8S6U4kvhZWLWXxkA.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong>Starter</strong>: $3.99/mo for 36 months. Then $9.99/mo<br><strong>Business</strong>: $6.99/mo for 36 months. Then $13.99/mo<br><strong>eCommerce Essentials</strong>: $14.99/mo for 36 months. Then $21.99/mo<a class="view-deal button" href="https://www.bluehost.com/web-hosting" target="_blank" rel="nofollow" data-dimension112="370ec411-eff3-4d7d-aef0-9f6f1090f4c1" data-action="Deal Block" data-label="Starter: $3.99/mo for 36 months. Then $9.99/moBusiness: $6.99/mo for 36 months. Then $13.99/moeCommerce Essentials: $14.99/mo for 36 months. Then $21.99/mo" data-dimension48="Starter: $3.99/mo for 36 months. Then $9.99/moBusiness: $6.99/mo for 36 months. Then $13.99/moeCommerce Essentials: $14.99/mo for 36 months. Then $21.99/mo" data-dimension25="$">View Deal</a></p></div><h3 class="article-body__section" id="section-namecheap"><span>Namecheap</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1207px;"><p class="vanilla-image-block" style="padding-top:58.16%;"><img id="4KkCxvzjT6vbMJhuZtjhij" name="Namecheap dashboard" alt="An image of Namecheap's dashbaord" src="https://cdn.mos.cms.futurecdn.net/4KkCxvzjT6vbMJhuZtjhij.jpg" mos="" align="middle" fullscreen="" width="1207" height="702" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><h2 id="what-you-get-3">What you get</h2><p>Once again, you can find everything you need to start and manage a website with Namecheap's basic plan: Stellar ($1.98/mo for 12 months, then $4.88/mo).</p><p><strong>A free domain for one year -</strong> Namecheap has some of the lowest renewal prices for domains, so you won't need to search elsewhere after your year's free trial is up.</p><p><strong>20GB SSD storage - </strong>Par for the course, and should be all you need.</p><p><strong>30 Mailboxes- </strong>This is the real bonus, as our previous hosts require you to pay extra for email after one month or a year - but with Namecheap, email is included, and free forever.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:56.19%;"><img id="" name="WebsiteBuilder.BundledWithSharedHosting.jpg" alt="Namecheap website builder is bundled with shared hosting plan" src="https://cdn.mos.cms.futurecdn.net/7LYjzzo8FS4fH8wxfToMeD.jpg" mos="" align="middle" fullscreen="" width="970" height="545" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Bundled with shared hosting, Namecheap's no-code website builder allows you to easily create a website thanks to the inclusion of over 200 templates </span><span class="credit" itemprop="copyrightHolder">(Image credit: Namecheap)</span></figcaption></figure><p><strong>Website building options - </strong>You have a few options with Namecheap and it can be a bit overwhelming, so I'm just going to mention two: WordPress and the AI Website Builder. </p><p>The AI Website Builder is OK but it doesn't support ecommerce and doesn't have the same maturity and amount of options as WordPress. I'd stick with WordPress but you get less of a helping hand using the WordPress page builder.</p><div class="product"><a data-dimension112="8bf69637-c1fd-40ba-83a4-635ab4917d1d" data-action="Deal Block" data-label="Stellar: $1.98/mo for 12 months. Then $4.88/moStellar Plus: $2.98/mo for 12 months. Then $6.88/moStellar Business: $4.98/mo for 12 months. Then $9.88/mo" data-dimension48="Stellar: $1.98/mo for 12 months. Then $4.88/moStellar Plus: $2.98/mo for 12 months. Then $6.88/moStellar Business: $4.98/mo for 12 months. Then $9.88/mo" data-dimension25="$" href="https://www.namecheap.com" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1120px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="mhzzuompp9HwsFNRqEuEbC" name="thumbnail-sample-6_cr.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/mhzzuompp9HwsFNRqEuEbC.jpg" mos="" align="middle" fullscreen="" width="1120" height="630" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong>Stellar</strong>: $1.98/mo for 12 months. Then $4.88/mo<br><strong>Stellar Plus</strong>: $2.98/mo for 12 months. Then $6.88/mo<br><strong>Stellar Business</strong>: $4.98/mo for 12 months. Then $9.88/mo<a class="view-deal button" href="https://www.namecheap.com" target="_blank" rel="nofollow" data-dimension112="8bf69637-c1fd-40ba-83a4-635ab4917d1d" data-action="Deal Block" data-label="Stellar: $1.98/mo for 12 months. Then $4.88/moStellar Plus: $2.98/mo for 12 months. Then $6.88/moStellar Business: $4.98/mo for 12 months. Then $9.88/mo" data-dimension48="Stellar: $1.98/mo for 12 months. Then $4.88/moStellar Plus: $2.98/mo for 12 months. Then $6.88/moStellar Business: $4.98/mo for 12 months. Then $9.88/mo" data-dimension25="$">View Deal</a></p></div><h3 class="article-body__section" id="section-website-builder-option-wix"><span>Website Builder option: Wix</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:56.19%;"><img id="JPLDfY5XkD3UNHqKJbFud6" name="EditorOptions.jpg" alt="Screenshot of editor options on Wix" src="https://cdn.mos.cms.futurecdn.net/JPLDfY5XkD3UNHqKJbFud6.jpg" mos="" align="middle" fullscreen="" width="970" height="545" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Get started quickly with Wix's help, or take your time with a more bespoke design </span><span class="credit" itemprop="copyrightHolder">(Image credit: Wix)</span></figcaption></figure><h2 id="what-you-get-4">What you get</h2><p>Wix's cheapest plan is $17/mo from the starting block, and you don't get much for it.</p><p><strong>A free domain for one year -</strong> The first year is free and the 'starting' price is stated but the renewal cost is hidden.</p><p><strong>2GB storage - </strong>This isn't much compared to some other options, but should be manageable for most users.</p><p><strong>Email - </strong>What email? None is provided.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:56.19%;"><img id="yyZ6KDDY8QGukL8kBz8Z96" name="Editor.QuickEdit.jpg" alt="screenshot of website being edited by Wix editor" src="https://cdn.mos.cms.futurecdn.net/yyZ6KDDY8QGukL8kBz8Z96.jpg" mos="" align="middle" fullscreen="" width="970" height="545" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">Wix offers great freedom in your design, but not so much that it is easy to mess up your site.  </span><span class="credit" itemprop="copyrightHolder">(Image credit: Wix)</span></figcaption></figure><p><strong>Website building options - </strong>The upside to Wix is that it has a very user friendly page builder, but you don't get free add-ons like you do with WordPress - and if you wanted to leave Wix, you'll need to re-build your page from scratch.</p><div class="product"><a data-dimension112="4221074c-8446-49da-a1d0-c88926f8ce43" data-action="Deal Block" data-label="Lite: $17/moCore: $29/moBusiness: $36/mo" data-dimension48="Lite: $17/moCore: $29/moBusiness: $36/mo" data-dimension25="$" href="https://wix.com" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:349px;"><p class="vanilla-image-block" style="padding-top:68.48%;"><img id="PZVkJSP7sYa5EcCe9fWVCM" name="logo wix white" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/PZVkJSP7sYa5EcCe9fWVCM.jpg" mos="" align="middle" fullscreen="" width="349" height="239" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong>Lite</strong>: $17/mo<br><strong>Core</strong>: $29/mo<br><strong>Business</strong>: $36/mo<a class="view-deal button" href="https://wix.com" target="_blank" rel="nofollow" data-dimension112="4221074c-8446-49da-a1d0-c88926f8ce43" data-action="Deal Block" data-label="Lite: $17/moCore: $29/moBusiness: $36/mo" data-dimension48="Lite: $17/moCore: $29/moBusiness: $36/mo" data-dimension25="$">View Deal</a></p></div><h3 class="article-body__section" id="section-web-hosting-summary"><span>Web hosting summary</span></h3><p>Our tests show that there isn't much between the hosts when it comes to performance so the choice is entirely down to budget and how much of a helping hand you want with WordPress.</p><div ><table><tbody><tr><td class="firstcol " ><p>Host</p></td><td  ><p>Pro</p></td><td  ><p>Con</p></td><td  ><p>Price</p></td></tr><tr><td class="firstcol " ><p>Hostinger</p></td><td  ><p>Lots of features and low starter price</p></td><td  ><p>No free email and high renewal prices</p></td><td  ><p>$1.99/mo then $12.99/mo</p></td></tr><tr><td class="firstcol " ><p>Bluehost</p></td><td  ><p>Excellent page building tools</p></td><td  ><p>No free email and high renewal prices</p></td><td  ><p>$3.99/mo then $9.99/mo</p></td></tr><tr><td class="firstcol " ><p>Namecheap</p></td><td  ><p>Low price comparable performance </p></td><td  ><p>Less helpful tools</p></td><td  ><p>$1.98/mo then $4.98/mo</p></td></tr><tr><td class="firstcol " ><p>Wix</p></td><td  ><p>Easy to use page  builder</p></td><td  ><p>Expensive, vendor lock-in, lacks email</p></td><td  ><p>$17/mo</p></td></tr></tbody></table></div><p>If I was on a budget and had more time to play with WordPress then I'd pick Namecheap. </p><p>If I could stretch my budget and needed help page building with WordPress I'd use Bluehost.</p><p>If I could extend my budget and in return get AI website management tools like Kodee and more features like email marketing, I'd go with Hostinger.</p><h2 class="article-body__section" id="section-faqs"><span>FAQs</span></h2><section class="article__schema-question"><h3>How easy is it to make a website with a web host?</h3><article class="article__schema-answer"><p>It can definitely be as easy to make a site with a web host as it is with a website builder. Some hosts have their own website builder, and some have tools for WordPress. They all have templates, they all have drag-and-drop page editors, they are all easy to use.</p><p>The only caveat is that WordPress's drag-and-drop builder is not as-easy-to-use but there are plenty of tutorials. If you're having difficulties it's worth persevering. </p></article></section><section class="article__schema-question"><h3>What is WordPress and why do I need it?</h3><article class="article__schema-answer"><p>When you use a website builder you are given a section of <a href="https://www.techradar.com/features/confused-by-cryptic-web-hosting-terms-weve-got-the-explanations-you-need#section-s">server</a> with the website builder software installed that is used to build and manage you site. It's all behind lock-and-key. When you use a web host you just rent the server. You need to install software on it to build and manage a site. This is where WordPress comes in. It's free and open-source. Installation is easy as you just need to click one button and the host does all the technical things for you.</p></article></section><section class="article__schema-question"><h3>What about ecommerce stores?</h3><article class="article__schema-answer"><p>As these recommendations are all based on WordPress being used as the CMS all you need to do is install the WooCommerce plug-in. You likely won't be able to host an ecommerce store on the basic plans because they won't be powerful enough but you can use one of the higher spec plans,. The recommendations are the same. My advice is to speak to the hosting provider and tell them your idea, they can recommend a suitable plan for you.</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sneeit WordPress RCE flaw allows hackers to add themselves as admin - here's how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/sneeit-wordpress-rce-flaw-allows-hackers-to-add-themselves-as-admin-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A critical flaw in a WordPress add-on was recently patched, which allows crooks to add a rogue admin account to the site. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EJFE9NfzrmkDqifScjHVfY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Dec 2025 17:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordFence disclosed critical RCE flaw (CVE-2025-6389) in Sneeit Framework plugin, affecting versions ≤8.3</strong></li><li><strong>Exploitation allows attackers to create admin accounts, install malicious plugins, and hijack WordPress sites</strong></li><li><strong>Users urged to update to v8.4, monitor for rogue admins, suspicious PHP files, and malicious AJAX activity</strong></li></ul><p>Security researchers from WordFence have warned about a critical-severity vulnerability in a popular plugin which allows threat actors to add themselves as admins on WordPress sites.</p><p>In a security advisory published last week, WordFence said it found a remote code execution (RCE) bug in Sneeit Framework, a backend toolkit WordPress admins use to manage theme options, layouts, and custom features. The bug is tracked as CVE-2025-6389, was given a severity score 9.8/10 (critical) and affects all versions of the plugin prior to, and including, 8.3. </p><p>Version 8.4, released in early August 2025, is not affected. According to The Hacker News, the plugin currently has more than 1,700 active installations. </p><div class="product"><a data-dimension112="51beaad0-6460-4d93-8df1-c04e6561c155" data-action="Deal Block" data-label="Catch the price drop- Get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop- Get 30% OFF for Enterprise and Business plans" href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:456px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="g9c6kVWTLaJEKDW8cRnGT5" name="NordPass" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/g9c6kVWTLaJEKDW8cRnGT5.jpg" mos="" align="middle" fullscreen="" width="456" height="456" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="nofollow" data-dimension112="51beaad0-6460-4d93-8df1-c04e6561c155" data-action="Deal Block" data-label="Catch the price drop- Get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop- Get 30% OFF for Enterprise and Business plans" data-dimension25=""><strong>Catch the price drop- Get 30% OFF for Enterprise and Business plans</strong></a></p><p>The Black Friday campaign offers 30% off for Enterprise and Business plans for a 1- or 2-year subscription. It’s valid until December 10th, 2025. Customers must enter the promo code <strong>BLACKB2B-30</strong> at checkout to redeem the offer.<a class="view-deal button" href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="nofollow" data-dimension112="51beaad0-6460-4d93-8df1-c04e6561c155" data-action="Deal Block" data-label="Catch the price drop- Get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop- Get 30% OFF for Enterprise and Business plans" data-dimension25="">View Deal</a></p></div><h2 id="how-to-stay-safe-2">How to stay safe</h2><p>Explaining how the vulnerability works, WordFence said that malicious actors could call an arbitrary PHP function and have it create a new admin user, which the attackers can then use to take full control over the target website. After that, they can easily install malicious plugins, add data scrapers, redirect victims to other sites, introduce phishing landing pages, and more.</p><p>Criminals reportedly started exploiting the flaw the moment it was publicly announced. The very first day, WordFence blocked more than 131,000 attacks, and even today, the number of daily attacks hovers at around 15,000. </p><p>The best way to remain safe from this vulnerability is to update the plugin to version 8.4. Users are also advised to keep their WordPress platform, as well as all other plugins and themes, updated at all times. Furthermore, all elements that are not in use should be deleted from the platform.</p><p>There are also indicators of compromise that webmasters should look out for - such as the appearance of a new, unauthorized WordPress admin account, created through the vulnerable AJAX callback. </p><p>Another red flag is the presence of malicious PHP files uploaded to the server, including webshells named xL.php, Canonical.php, .a.php, simple.php, or up_sf.php, as well as suspicious .htaccess files designed to allow execution of dangerous file types.</p><p>Compromised sites may also contain files like finderdata.txt or goodfinderdata.txt, generated by the attacker’s shell-finder tool. Log files showing successful AJAX requests from known attacking IPs — such as 185.125.50.59, 182.8.226.51, 89.187.175.80, and others listed in the report are another strong indicator that the vulnerability was used to access the site.</p><p><em>Via </em><a href="https://thehackernews.com/2025/12/sneeit-wordpress-rce-exploited-in-wild.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WordPress plugin with over a million installs may have a worrying security flaw - here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/wordpress-plugin-with-over-a-million-installs-may-have-a-worrying-security-flaw-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ A critical WordPress plugin flaw allows threat actors to run arbitrary PHP commands, potentially taking over entire websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Z4uQgDzA6tyAK5Rg2NktKN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Nov 2025 16:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>W3 Total Cache plugin flaw CVE-2025-9501 enables unauthenticated PHP command injection</strong></li><li><strong>Affects all versions before 2.8.13; ~327,000+ sites remain at risk</strong></li><li><strong>WPScan PoC exploit set for Nov 24, raising mass exploitation concerns</strong></li></ul><p>W3 Total Cache (W3TC), a <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> with more than a million users, carries a critical-severity vulnerability that allows threat actors to fully take over compromised websites, experts have warned.</p><p>The bug is described as a command injection flaw that works by submitting a comment with a malicious payload to a post. The attacker does not need to be authenticated on the website in order to inject PHP commands this way.</p><p>The vulnerability is now tracked as CVE-2025-9501, and with a severity score of 9.0/10 (critical), it affects all versions of the plugin before 2.8.13. </p><h2 id="november-24-deadline">November 24 deadline</h2><p>To patch the flaw, users should update their plugin to version 2.8.13, which was released on October 20. </p><p>Looking at the data from the Wordpress.org site, it says that 67.3% of pages have updated to version 2.8, while the remaining 32.7% are on older versions. That would put at least 327,000 websites at risk. </p><p>However, it doesn’t mean that all 67.3% are running version 2.8.13, so the actual number of vulnerable websites is likely a lot bigger.</p><p>In their security advisory, researchers from WPScan, a security scanner built specifically for the WordPress <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website builder</a>, said they developed a Proof-of-Concept (PoC) exploit for the flaw, and set a deadline for November 24 to publish it. Before that, they expect the majority of websites to have updated their plugins to the secured version. </p><p>In many instances, mass exploitation starts the moment a PoC is released, since many threat actors can’t be bothered to develop one themselves, and will simply pick up on whatever is already out there. Therefore, it is crucial for WordPress site owners and admins to update before the deadline. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/w3-total-cache-wordpress-plugin-vulnerable-to-php-command-injection/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WordPress users beware - GootLoader strikes again, using font hack to spread malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/gootloader-strikes-again-using-font-hack-to-spread-malware-on-wordpress-sites</link>
                                                                            <description>
                            <![CDATA[ In some cases the attackers reached domain controllers within hours. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Fei2qbjECXSVvbC5X2BaRH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Nov 2025 16:03:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Gootloader malware resurfaced in late October 2025 after a nine-month hiatus, used to stage ransomware attacks</strong></li><li><strong>Delivered via malicious JavaScript hidden in custom web fonts, enabling stealthy remote access and reconnaissance</strong></li><li><strong>Linked to Storm-0494 and Vice Society; attackers reached domain controllers in under an hour in some cases</strong></li></ul><p>After a nine-month sabbatical, the <a href="https://www.techradar.com/best/best-malware-removal">malware</a> known as Gootloader is truly back, possibly being used as a stepping stone towards ransomware infections.</p><p>A report from cybersecurity researchers Huntress observed “multiple infections” from October 27 and into early November, 2025. Before that, the last time Gootloader was seen was in March, 2025.</p><p>In the new campaign, Gootloader was most likely leveraged by a group known as Storm-0494, as well as its downstream operator, Vanilla Tempest (also known as Vice Society), a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group first observed in mid-2021, primarily targeting the education and healthcare sectors, with occasional excursions into manufacturing.</p><h2 id="hiding-malware-in-custom-fonts">Hiding malware in custom fonts</h2><p>Gootloader was used to deliver malicious JavaScript from compromised websites, the researchers explained. The script installs tools that give attackers remote access to corporate Windows machines, and enable follow-on actions, such as account takeover, or ransomware deployment. </p><p>Gootloader hid malicious filenames and download instructions inside a custom web font (WOFF2) so the page looked normal in a browser but showed meaningless text in the raw HTML. When a victim opened the compromised page, the browser used the font to swap invisible or scrambled characters for readable ones, revealing the real download link and filename only when rendered.</p><p>The purpose of the campaign is to gain reliable initial access, quickly map and control target networks, and then hand the access over to ransomware operators. The entire process is done as fast as possible, mostly through automated reconnaissance and remote-control tools that help identify high-value targets, create privileged accounts, and prepare for ransomware. </p><p>In some cases, Huntress added, the attackers reached domain controllers within hours. Initial automated reconnaissance often begins within 10-20 minutes after the malicious JavaScript runs, and in several incidents, operators achieved domain controller access in as little as 17 hours. In at least one environment they reached a domain controller in under one hour.</p><p>To defend against Gootloader, Huntress advises watching for early signs such as unexpected downloads from <a href="https://www.techradar.com/best/browser" target="_blank">web browsers</a>, unfamiliar shortcuts in startup locations, sudden PowerShell or script activity coming from the browser, and unusual outbound proxy-like connections. </p><p><em>Via </em><a href="https://thehackernews.com/2025/11/gootloader-is-back-using-new-font-trick.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another major WordPress add-on security flaw could affect 10,000 sites - find out if you're affected ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/another-major-wordpress-add-on-security-flaw-could-affect-10-000-sites-find-out-if-youre-affected</link>
                                                                            <description>
                            <![CDATA[ King Addons for Elementor allowed full WordPress website takeover through two critical-level vulnerabilities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jkTr7wPvLPGGYr8Ac6NZf8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 01 Nov 2025 16:31:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>King Addons plugin had two critical flaws enabling full WordPress site takeover</strong></li><li><strong>Bugs allowed unauthenticated file uploads and privilege escalation via registration endpoint</strong></li><li><strong>Users must update to version 51.1.37 to patch both vulnerabilities</strong></li></ul><p>King Addons for Elementor, a commercial <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> that extends the Elementor page builder with extra <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website builder</a> widgets, templates, and design features, carried two critical-level vulnerabilities that allowed threat actors to fully take over vulnerable websites, experts have warned.</p><p>In a new security advisory, Patchstack detailed two bugs: an unauthenticated arbitrary file upload flaw (CVE-2025-6327), and a privilege escalation via registration endpoint flaw (CVE-2025-6325). The former has a severity score of 10/10 (critical), while the latter 9.8/10 (also critical).</p><p>Both bugs let a threat actor turn a vulnerable WordPress website into a beachhead. They can get code, or accounts, onto the site, and use them to execute actions that lead to full site compromise, or data theft.</p><h2 id="patching-the-bugs">Patching the bugs</h2><p>Site admins using the “King Addons Login | Register Form” widgets should make sure to update the plugin to version 51.1.37 as soon as possible, since this patch fixes both vulnerabilities and mitigates potential site takeover risks. </p><p>“Both vulnerabilities are trivially exploitable under common configurations and require no authentication,” Patchstack warned. “Immediate patching is strongly recommended.”</p><p><a href="https://www.infosecurity-magazine.com/news/critical-flaws-elementor-king/" target="_blank"><em>Infosecurity Magazine</em></a> says the vendor addressed the vulnerabilities across two versions, by introducing a role allowlist and input sanitization, as well as an upload handler that now requires proper permission and enforces strict file type validation. </p><p>King Addons for Elementor is a popular plugin with more than 10,000 active users. It provides more than 70 widgets, more than 650 templates, and more than 4,000 page sections, helping users build their websites without extensive coding knowledge. </p><p>Discovering critical vulnerabilities in WordPress add-ons and themes is nothing new. </p><p>Third-party extensions to the platform are the most common ways cybercriminals compromise and take over WordPress websites, which is why users are always advised to only keep the add-ons they use, and to make sure they are always updated to the latest versions.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This popular WordPress security plugin has a worrying flaw which exposed user data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-popular-wordpress-security-plugin-has-a-worrying-flaw-which-exposed-user-data</link>
                                                                            <description>
                            <![CDATA[ An authenticated WordPress user could read almost any file on the server, including wp-config.php. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YJT7HWzoSdLjYEzVSkjNtP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Oct 2025 13:02:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress plugin flaw let low-privileged users access sensitive server files and credentials</strong></li><li><strong>CVE-2025-11705 affects plugin versions 4.23.81 and earlier; patch released October 15</strong></li><li><strong>About 50,000 sites remain vulnerable; admins urged to update immediately</strong></li></ul><p>A popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> with more than 100,000 active installations carried a bug that allowed threat actors to read any file on the server - including people’s emails and in some cases, passwords, too.</p><p>Security researchers at Wordfence reported a vulnerability in the Anti-Malware Security and Brute-Force Firewall plugin for <a href="https://www.techradar.com/news/best-wordpress-hosting-providers" target="_blank">WordPress</a>. As the name suggests, this plugin allows site owners to scan for malware, protect their sites against brute-force attacks, defend against known flaws, and more.</p><p>However, the plugin was missing capability checks in one of its functions, which allowed low-privileged users to read arbitrary files on the server, including sensitive files such as wp-config.php that stores different credentials.</p><h2 id="patch-available">Patch available</h2><p>In theory, malicious actors could this way obtain people’s email addresses, hashed or plaintext passwords (depending on what’s stored), and other private data. </p><p>The bug is now tracked as CVE-2025-11705 and has a severity score of 6.8/10 (medium) - a relatively low severity score, since attackers need to be authenticated in order to abuse it, but sites with any kind of membership or subscription, running the Anti-Malware Security and Brute-Force Firewall plugin, are considered vulnerable.</p><p>Versions 4.23.81 and earlier of the plugin are affected, it was said. </p><p>The researchers reported their findings to the vendor on October 14, and a patch was issued a day later, on October 15. Version 2.23.83 addresses the bug by adding a proper user capability check via a new function. Since the release of the patch, roughly half of the users (around 50,000) installed it, meaning there are still around 50,000 vulnerable websites. </p><p>At press time, there was no word of exploitation in the wild, but vulnerabilities like this one often get exploited months after the patch. Therefore, website admins are recommended to apply the fix as soon as possible.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/wordpress-security-plugin-exposes-private-data-to-site-subscribers/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of attacks hit WordPress websites - here's how to make sure you stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/millions-of-attacks-hit-wordpress-websites-heres-how-to-make-sure-you-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Three old WordPress vulnerabilities are being leveraged to establish persistence and steal files. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4WEC25xJeXYntBcG3UxqSi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Oct 2025 14:03:00 +0000</pubDate>                                                                                                                                <updated>Wed, 29 Oct 2025 09:24:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Person editing a WordPress site]]></media:text>
                                <media:title type="plain"><![CDATA[Person editing a WordPress site]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Unpatched GutenKit and Hunk Companion plugins exploited in mass WordPress attacks</strong></li><li><strong>Attackers use ‘up’ plugin to gain admin access and deploy malware</strong></li><li><strong>Wordfence blocked 8.7 million attempts in 48 hours; updates remain critical</strong></li></ul><p>Three critical-severity vulnerabilities, found in two <a href="https://www.techradar.com/best/best-wordpress-plugins">WordPress plugins</a> and fixed more than a year ago, are now being exploited in mass attacks against websites which still haven’t patched the issues.</p><p>WordPress security experts Wordfence said it blocked more than 8.7 million attack attempts over the course of roughly 48 hours utilizing GutenKit and Hunk Companion. </p><p>The former extends Gutenberg by adding dozens of extra blocks, templates, and layout tools, while the latter is a “helper” plugin for ThemeHunk themes that adds sections like “team”, “services”, “portfolio”, “sliders”, and more.</p><div class="product star-deal"><a data-dimension112="ee8b0561-994d-46b5-950c-9792b3d85138" data-action="Star Deal Block" data-label="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension48="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" href="https://www.identityforce.com/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:56.19%;"><img id="ULqD5YbZCsnKCfjNPVVtvf" name="identityforce-NEW-border.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ULqD5YbZCsnKCfjNPVVtvf.jpg" mos="" align="middle" fullscreen="" width="970" height="545" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.identityforce.com/" target="_blank" rel="nofollow" data-dimension112="ee8b0561-994d-46b5-950c-9792b3d85138" data-action="Star Deal Block" data-label="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension48="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension25=""><strong>Official IdentityForce® | Identity Theft Protection - save up to 68% annually </strong></a></p><p>Many people don’t know how to protect their ID. Get your ID Action Plan here. Get a personalized step-by-step Action Plan & ID Safety Score based on YOUR dark web hits.<a class="view-deal button" href="https://www.identityforce.com/" target="_blank" rel="nofollow" data-dimension112="ee8b0561-994d-46b5-950c-9792b3d85138" data-action="Star Deal Block" data-label="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension48="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension25="">View Deal</a></p></div><h2 id="malicious-payload-on-github">Malicious payload on GitHub</h2><p>Between October and December 2024, three flaws were found - and patched - in the plugins: CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972. All three were rated critical (9.8/10), and allow threat actors to install arbitrary plugins and run malicious code on vulnerable sites.</p><p>Now, threat actors are taking advantage of the fact that many sites are not that diligent when it comes to applying fixes. </p><p>Wordfence says the hackers are using the vulnerabilities to install a malicious plugin called ‘up’, that’s being hosted as a .ZIP archive on GitHub. </p><p>The plugin allows the threat actors to upload, download, or delete files from the site, as well as to tamper with the site’s permissions. It also allows the threat actor to automatically log into the vulnerable website as an administrator. </p><p>Wordfence also says that between other things, the attackers are using ‘up’ to set up persistence, steal information, and drop additional malware. </p><p>Being the one  of the <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">best website builder</a> platforms, WordPress is a popular target among cybercriminals. However, since it is generally considered safe, the attackers usually go for themes and plugins, since these are often vulnerable, or lose support. </p><p>The best way to mitigate the risk is to only keep the plugins and themes you are actually using, and to make sure they are updated at all times. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/hackers-launch-mass-attacks-exploiting-outdated-wordpress-plugins/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of web pages abused by hackers to spread malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/thousands-of-web-pages-abused-by-hackers-to-spread-malware</link>
                                                                            <description>
                            <![CDATA[ More than 14,000 websites were seen distributing malware with the help of blockchain technology. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ls7r6vikXm4AnHcQfcN4FP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Oct 2025 15:28:00 +0000</pubDate>                                                                                                                                <updated>Tue, 28 Oct 2025 10:20:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UNC5142 hacked 14,000+ WordPress sites to distribute malware</strong></li><li><strong>Malware payloads were fetched from blockchain, boosting resilience and hindering takedowns</strong></li><li><strong>ClickFix lures tricked users into running malicious commands </strong></li></ul><p>More than 14,000 WordPress websites were hacked and used as launchpads for malware distribution, <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc5142-etherhiding-distribute-malware" target="_blank">Google’s Threat Intelligence Group</a> (GTIG) said in a recent report.</p><p>Discussing the campaign in-depth, GTIG said that it is the work of UNC5142, a relatively new threat actor that emerged in late 2023 and stopped operations in late July 2025. </p><p>It is not yet known if the pause is temporary, permanent, or if the group simply pivoted to different techniques. Given their previous success compromising websites and deploying malware, Google believes that the group just improved their obfuscation techniques and still operates in the wild.</p><div class="product star-deal"><a data-dimension112="b684aac7-5ee6-47f1-b9bb-794e6a38c29f" data-action="Star Deal Block" data-label="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension48="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" href="https://www.identityforce.com/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:56.19%;"><img id="ULqD5YbZCsnKCfjNPVVtvf" name="identityforce-NEW-border.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ULqD5YbZCsnKCfjNPVVtvf.jpg" mos="" align="middle" fullscreen="" width="970" height="545" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.identityforce.com/" target="_blank" rel="nofollow" data-dimension112="b684aac7-5ee6-47f1-b9bb-794e6a38c29f" data-action="Star Deal Block" data-label="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension48="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension25=""><strong>Official IdentityForce® | Identity Theft Protection - save up to 68% annually </strong></a></p><p>Many people don’t know how to protect their ID. Get your ID Action Plan here. Get a personalized step-by-step Action Plan & ID Safety Score based on YOUR dark web hits.<a class="view-deal button" href="https://www.identityforce.com/" target="_blank" rel="nofollow" data-dimension112="b684aac7-5ee6-47f1-b9bb-794e6a38c29f" data-action="Star Deal Block" data-label="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension48="Official IdentityForce® | Identity Theft Protection - save up to 68% annually" data-dimension25="">View Deal</a></p></div><h2 id="blockchain-and-clickfix">Blockchain and ClickFix</h2><p>In the campaign, UNC5142 would “indiscriminately” target vulnerable WordPress sites - those with flawed plugins, theme files, and in some cases - the WordPress database itself. </p><p>These sites would be given a multi-stage JavaScript downloader dubbed CLEARSHOT, that enabled malware distribution. This downloader fetched the stage-two payload from the public blockchain, often using BNB chain. </p><p>The use of blockchain is interesting, the researchers found, as it improves resiliency and makes takedowns more difficult: </p><p>“The use of blockchain technology for large parts of UNC5142’s infrastructure and operation increases their resiliency in the face of detection and takedown efforts,” the report says. </p><p>“Network based protection mechanisms are more difficult to implement for Web3 traffic compared to traditional web traffic given the lack of use of traditional URLs. Seizure and takedown operations are also hindered given the immutability of the blockchain.”</p><p>From the public blockchain, the malware would pull a CLEARSHORT landing page from an external server. This landing page would serve the ClickFix social engineering tactic - prompting users to copy and paste a command into the Run program on Windows (or the Terminal app on a Mac) which ultimately downloads the malware.</p><p>The landing pages were typically hosted on a Cloudflare .dev page, it was said, and retrieved in an encrypted format. </p><p><em>Via </em><a href="https://thehackernews.com/2025/10/hackers-abuse-blockchain-smart.html" target="_blank"><em>The Hacker News</em></a></p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/pro/security/devious-new-clickfix-malware-variant-targets-macos-android-and-ios-using-browser-based-redirections" target="_blank">Devious new ClickFix malware variant targets macOS, Android, and iOS using browser-based redirections</a></li><li>Take a look at our guide to the <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">best authenticator app</a></li><li>We've rounded up the <a href="https://www.techradar.com/best/password-manager" target="_blank">best password managers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A popular WordPress theme has a worrying security flaw which could allow full site takeover - here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-popular-wordpress-theme-has-a-worrying-security-flaw-which-could-allow-full-site-takeover</link>
                                                                            <description>
                            <![CDATA[ Install the patch as soon as you can to prevent losing your site to hackers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">trQC4acMWWcdfNcrPmRsQL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Oct 2025 12:04:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CVE-2025-5947 allows unauthenticated admin access in Service Finder WordPress theme versions ≤ 6.0</strong></li><li><strong>Over 13,800 exploit attempts observed since August; attackers actively target vulnerable sites</strong></li><li><strong>Patching is critical; blocking five known IPs may help but won’t stop future attacks</strong></li></ul><p>Websites running the popular Service Finder Bookings <a href="https://www.techradar.com/best/wordpress-website-builder" target="_blank">WordPress</a> theme are being actively targeted following the discovery of a critical severity vulnerability. </p><p>On July 17, Aonetheme released version 6.1 of Service Finder, which included a fix for an authentication bypass flaw that affected all versions up to, and including, 6.0. Since the plugin did not properly validate a user’s cookie value prior to logging them in, it was possible for unauthenticated attackers to log in as any user - including admin. </p><p>The vulnerability is tracked as CVE-2025-5947, and was given a severity score of 9.8/10 (critical), since it allowed full website takeover, data exfiltration, <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> deployment, and more.</p><h2 id="thousands-of-attacks">Thousands of attacks</h2><p>The theme can be purchased on the Envato Market which shows it was acquired more than 6,000 times already. According to <em>BleepingComputer</em>, most sites that buy the theme are actively using it, so the attack surface could be rather large. </p><p>In addition, WordPress security company Wordfence says that since August 1, it observed more than 13,800 attempts to exploit this vulnerability, meaning threat actors are well aware of it and are actively hunting for victims. At press time, WordFence said it saw more than 200 attacks in the last 24 hours, alone.</p><p>Such a large number would suggest hundreds of attackers, but it seems that the majority of attack requests came from just five IP addresses. </p><p>This could make things easier for the defenders, since simply blocking them would be enough to prevent intrusions. However, the attackers could always switch to new ones, so patching the vulnerable product is still the best way to address the rising risk. </p><p>Also, those who are worried about being targeted should review their logs for suspicious or otherwise unexpected login activity, or accounts that threat actors may have created to establish persistence. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-in-service-finder-wordpress-theme/" target="_blank"><em>BleepingComputer</em></a></p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/pro/security/wordpress-users-beware-this-popular-plugin-has-been-hijacked-to-push-potential-malware" target="_blank">WordPress users beware - this popular plugin has been hijacked to push potential malware</a></li><li>Take a look at our guide to the <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">best authenticator app</a></li><li>We've rounded up the <a href="https://www.techradar.com/best/password-manager" target="_blank">best password managers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Paid WordPress users beware - worrying security flaw puts accounts and info at risk ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/paid-wordpress-users-beware-worrying-security-flaw-puts-accounts-and-info-at-risk</link>
                                                                            <description>
                            <![CDATA[ A high vulnerability flaw was found in a popular WordPress theme enabling subscriptions and paying users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4YDa4noJ53U7fpG6vaP7xC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Sep 2025 16:06:00 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Sep 2025 09:24:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>An improper neutralization flaw was found in the WordPress Paid Membership Subscriptions plugin</strong></li><li><strong>This plugin is used by more than 10,000 sites, enabling memberships and paying user accounts</strong></li><li><strong>A patch is now available, so users should update immediately</strong></li></ul><p>A high-severity vulnerability has been discovered in a popular premium <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a>, allowing threat actors to access, or exfiltrate, sensitive data without authentication.</p><p>Security researcher ChuongVN from the Patchstack Alliance recently found an “improper neutralization of special elements used in an SQL command” flaw, affecting the WordPress Paid Membership Subscriptions plugin. </p><p>Paid Member Subscriptions is a plugin helping site owners create and manage membership-based websites. It lets admins restrict content, create subscription plans, accept recurring payments, and control user access based on membership level. It is rather popular, being used by more than 10,000 websites.</p><h2 id="extracting-emails-or-hashed-passwords">Extracting emails or hashed passwords</h2><p>Among the plugin's standout features is its integration with popular <a href="https://www.techradar.com/best/best-payment-gateways">payment gateways</a> like PayPal and Stripe, but this is also where the problem stems from. </p><p>The plugin’s handling of PayPal Instant Payment Notifications (IPN) was problematic, as when a transaction was processed, the plugin extracted a payment ID directly from user-supplied data and inserted it into a database query without proper validation.</p><p>By manipulating this input, attackers could gain unauthorized access to sensitive information or modify stored records.</p><p>In a real-life scenario, an attacker could inject malicious queries into the site’s database, allowing them to extract email addresses or hashed passwords of paying members. This information could then be used to launch phishing attacks against subscribers, or credential-stuffing attacks on other platforms where the same login details are used. </p><p>The bug is now tracked as CVE-2025-49870, and carries a severity score of 7.5/10 (high). It was fixed in version 2.15.2, and users are now advised to upgrade their plugins as soon as possible.  </p><p>WordPress is the world’s <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">best website builder</a> platforms, powering more than half of all websites in existence. As such, its plugins and themes are a popular target among cybercriminals looking for an easy way into websites, their content, and their users’ data.</p><p><em>Via </em><a href="https://www.infosecurity-magazine.com/news/sqli-threat-wordpress-memberships/" target="_blank"><em>Infosecurity Magazine</em></a></p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/pro/security/dangerous-wordpress-plugin-puts-over-160-000-sites-at-risk-heres-what-we-know" target="_blank">Dangerous WordPress plugin puts over 160,000 sites at risk - here's what we know</a></li><li>Take a look at our guide to the <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">best authenticator app</a></li><li>We've rounded up the <a href="https://www.techradar.com/best/password-manager" target="_blank">best password managers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bluehost in 60 minutes: making WordPress hosting easier ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/website-hosting/bluehost-in-60-minutes-making-wordpress-hosting-easier</link>
                                                                            <description>
                            <![CDATA[ One hour with Bluehost: 60 minutes with one of the best WordPress hosting providers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LkbpyvNFDnQqGcZ6X7U37F</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z4cGBRFNSonV29x8VViSZM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Aug 2025 22:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Website Hosting]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Capell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/h2jxs4impEB7K2rxEpTRy4.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z4cGBRFNSonV29x8VViSZM-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a clock next to the Bluehost logo]]></media:description>                                                            <media:text><![CDATA[An image of a clock next to the Bluehost logo]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a clock next to the Bluehost logo]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z4cGBRFNSonV29x8VViSZM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It's been a while since I used <a href="https://www.techradar.com/reviews/bluehost">Bluehost</a>, and the company has recently unveiled a host of new plans, as well as announcing a <a href="https://www.techradar.com/pro/website-hosting/whats-changed-with-bluehosts-latest-ecommerce-plans-i-spoke-with-newly-appointed-ceo-sachin-puri-to-find-out">new CEO</a>. </p><p>So, after <a href="https://www.techradar.com/pro/website-hosting/hostinger-in-60-minutes-learn-from-these-rookie-mistakes">Hostinger</a>,  <a href="https://www.techradar.com/pro/website-hosting/dreamhost-in-60-minutes-slow-servers-but-neat-business-features">DreamHost</a>, and <a href="https://www.techradar.com/pro/website-hosting/kinsta-in-60-minutes-is-this-host-a-good-choice-for-your-agency">Kinsta</a> I figured why not do Bluehost next in my <em>One Hour With</em> series.</p><p>I've only got 60 minutes, so lets crack on.</p><h2 class="article-body__section" id="section-start-the-clock-0-00"><span>Start the clock 0:00</span></h2><h3 class="article-body__section" id="section-signing-up"><span>Signing up</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:87.20%;"><img id="q7CKaXcL8jBxZCdyK3wJbZ" name="Bluehost payment redacted.JPG" alt="An image of the checkout cart for Bluehost" src="https://cdn.mos.cms.futurecdn.net/q7CKaXcL8jBxZCdyK3wJbZ.jpg" mos="" align="middle" fullscreen="" width="1000" height="872" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1907px;"><p class="vanilla-image-block" style="padding-top:47.09%;"><img id="CDPpRcY2eoYgyspv8ScJLf" name="Bluehost after purchase" alt="The control panel for Bluehost" src="https://cdn.mos.cms.futurecdn.net/CDPpRcY2eoYgyspv8ScJLf.jpg" mos="" align="middle" fullscreen="" width="1907" height="898" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Pretty easy and no surprises. I entered my payment details, and pretty much instantly I was directed to the panel with a message telling me WordPress was installing.</p><p>Before I had the chance to take screengrabs and read the messages from Bluehost in the pop-up box, WordPress had already been installed. I closed the box and was then asked how I wanted to build my WordPress site. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:809px;"><p class="vanilla-image-block" style="padding-top:87.64%;"><img id="hjJEmFtm7G9dgR9mntG4Bi" name="Bluehost Builder" alt="Bluehost asking how I would like to make my site" src="https://cdn.mos.cms.futurecdn.net/hjJEmFtm7G9dgR9mntG4Bi.jpg" mos="" align="middle" fullscreen="" width="809" height="709" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I was a little surprised to not see more options for templates here - but that's not a complaint, I quite like the simplicity. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:640px;"><p class="vanilla-image-block" style="padding-top:106.56%;"><img id="qPWDbY4nBMf8JVumAKbqvi" name="Bluehost website set up" alt="An image of the description of my site given to an AI website page builder" src="https://cdn.mos.cms.futurecdn.net/qPWDbY4nBMf8JVumAKbqvi.jpg" mos="" align="middle" fullscreen="" width="640" height="682" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>The idea for this site was to offer a plant watering and rental service. I described the site, and then was presented with help options.</p><h2 class="article-body__section" id="section-06-57"><span>06:57</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:541px;"><p class="vanilla-image-block" style="padding-top:103.70%;"><img id="59GQwr5baEREoTKKiMbkBK" name="Bluehost page builder expectations" alt="An image showing Bluehost web page builder choices based on experience." src="https://cdn.mos.cms.futurecdn.net/59GQwr5baEREoTKKiMbkBK.jpg" mos="" align="middle" fullscreen="" width="541" height="561" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I picked intermediate, but as always I struggled with WordPress, and later regretted not selecting beginner.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:989px;"><p class="vanilla-image-block" style="padding-top:52.78%;"><img id="PG2pkE9n5QXNPKMbzaNUXd" name="Bluehost web page selection" alt="An image of three templates for my site" src="https://cdn.mos.cms.futurecdn.net/PG2pkE9n5QXNPKMbzaNUXd.jpg" mos="" align="middle" fullscreen="" width="989" height="522" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I was then given three templates to choose from and picked the first.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1902px;"><p class="vanilla-image-block" style="padding-top:47.42%;"><img id="pErFFXzrVCtRrjBpZvhbr6" name="Bluehost web page" alt="An image of a home page built by the Bluehost page builder" src="https://cdn.mos.cms.futurecdn.net/pErFFXzrVCtRrjBpZvhbr6.jpg" mos="" align="middle" fullscreen="" width="1902" height="902" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Then, I started having the same WordPress page builder issues that I usually have. </p><p>It was easier for me this time because I have a little more experience with WordPress - but I still found it somewhat confusing and unintuitive trying to edit and change page elements.</p><p>I regretted selecting intermediate when I set up the site. I asked support if there was any way I could get it back but sadly, I would have had to start again from scratch. </p><h2 class="article-body__section" id="section-20-11"><span>20:11</span></h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:373px;"><p class="vanilla-image-block" style="padding-top:78.82%;"><img id="Nyp69WAsyzPm7z7VBg6rS4" name="Bluehost support" alt="An image of a chat between the author and support" src="https://cdn.mos.cms.futurecdn.net/Nyp69WAsyzPm7z7VBg6rS4.jpg" mos="" align="middle" fullscreen="" width="373" height="294" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I persevered and I managed to get roughly what I was looking for. I did think there would be a bit more help as standard and that I wouldn't be using the Gutenberg drag and drop page builder as much. There was WonderBlocks, a selection of template sections for your site.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1831px;"><p class="vanilla-image-block" style="padding-top:45.11%;"><img id="5eqnPvFsaP8noc7jgeWqWa" name="WonderBlocks" alt="An image of Bluehost's WonderBlocks UI" src="https://cdn.mos.cms.futurecdn.net/5eqnPvFsaP8noc7jgeWqWa.jpg" mos="" align="middle" fullscreen="" width="1831" height="826" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>WonderBlocks is neat tool that lives in the top left corner and contains loads of templates for things like headers, hero images, forms, galleries, testimonials, and a whole bunch of other stuff. </p><p>I actually have to praise Bluehost for this - I like this tool a lot. I think the overall user experience is still limited due to the WordPress page editor, but this helps out a lot.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1806px;"><p class="vanilla-image-block" style="padding-top:43.19%;"><img id="yyAbFBgjQem2viVdqaiiRS" name="WonderBlocks 2" alt="An image of the WonderBlocks UI" src="https://cdn.mos.cms.futurecdn.net/yyAbFBgjQem2viVdqaiiRS.jpg" mos="" align="middle" fullscreen="" width="1806" height="780" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>To use one of the templates, you just need to click the plus sign under the template an it adds it to your page. Then you can edit it and move it around.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1248px;"><p class="vanilla-image-block" style="padding-top:56.01%;"><img id="LiMbg9xY2q5d7MaVnKtbb6" name="Bluehost subscription plans" alt="The subscription plans for my site" src="https://cdn.mos.cms.futurecdn.net/LiMbg9xY2q5d7MaVnKtbb6.jpg" mos="" align="middle" fullscreen="" width="1248" height="699" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I used it to create a subscription plan section for my site. I saved a lot of time and frustration doing it this way. </p><p>Earlier, I criticised Bluehost for not having any templates and just offering the AI website builder but actually I think it's better this way. You get a very simple and workable layout from the AI page builder and then you get to customize it with template blocks.</p><h3 class="article-body__section" id="section-32-45"><span>32:45</span></h3><h2 id="that-s-enough-of-page-building">That's enough of page building</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1900px;"><p class="vanilla-image-block" style="padding-top:47.63%;"><img id="nXcDpWcciuBKoehawyhAS9" name="Bluehost control panel" alt="An image of Bluehost's control panel" src="https://cdn.mos.cms.futurecdn.net/nXcDpWcciuBKoehawyhAS9.jpg" mos="" align="middle" fullscreen="" width="1900" height="905" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>The control panel at Bluehost is very clean - the most technical things are all hidden from you, and a lot of the site management tools are integrated into the WordPress CMS rather than hosting panel.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1436px;"><p class="vanilla-image-block" style="padding-top:57.73%;"><img id="BGpMhNRbLxKQ77ogLAxtnV" name="Bluehost hosting stuff" alt="An image of the more technical Bluehost settings" src="https://cdn.mos.cms.futurecdn.net/BGpMhNRbLxKQ77ogLAxtnV.jpg" mos="" align="middle" fullscreen="" width="1436" height="829" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>While I was in there I did a quick speed test using a free tool from Google - you'd be foolish to use this as the main testing tool, but it's good for basic diagnostics and from Google itself. </p><p>I don't usually do speed tests when I do a <em>One Hour With </em>because I do more thorougher testing in the full review but I was curious and this took a second. It showed only moderate performance for Speed Index which could be because of what I call plug-in bloat.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1194px;"><p class="vanilla-image-block" style="padding-top:61.47%;"><img id="kMcNNgnZsuWwrDwgk4mBqA" name="Bluehost speed test" alt="An image of Bluehost's speed test" src="https://cdn.mos.cms.futurecdn.net/kMcNNgnZsuWwrDwgk4mBqA.jpg" mos="" align="middle" fullscreen="" width="1194" height="734" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>I followed Google's guidance on <a href="https://developer.chrome.com/docs/lighthouse/performance/speed-index/" target="_blank">how to improve Speed Index</a> and disabled 3rd party plugins, before running the speed test again and immediately seeing a jump in performance. </p><p>I think the tools are not necessary to have on all the time, as I don't think I need to monitor my SEO score constantly and there are ways to monitor website traffic with less overheads. For example, you can just paste a Google URL into your page that monitors traffic rather than using a plugin.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1168px;"><p class="vanilla-image-block" style="padding-top:62.50%;"><img id="WXwZ3CbkubqTfQzBxjaxHA" name="Bluehost optimization" alt="An image showing page optimization by disabling plugins" src="https://cdn.mos.cms.futurecdn.net/WXwZ3CbkubqTfQzBxjaxHA.jpg" mos="" align="middle" fullscreen="" width="1168" height="730" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1183px;"><p class="vanilla-image-block" style="padding-top:30.94%;"><img id="b2UKKeR56JRiyBEAoPYieA" name="Bluehost optimization" alt="An image showing page optimization by disabling plugins" src="https://cdn.mos.cms.futurecdn.net/b2UKKeR56JRiyBEAoPYieA.jpg" mos="" align="middle" fullscreen="" width="1183" height="366" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p> The Google Workspace integration took my interest for a while. Obviously, most of these Google tools are free and you can (like I have previously) integrate these things into your website without paying for it. </p><p>For example, if you want to take a booking you can use Google Calendar with a standard Gmail account but you will need to use the @gmail email address. There are some workarounds that include setting up your own email and then configuring the settings which could save you money.</p><p>I cannot make my mind up on what I would do. Obviously it's easier to just pay Bluehost every month and I don't think it's more expensive than paying for your own Google Workspace and then linking the account. In fact, you might get a discount at Bluehost. <a href="https://www.techradar.com/news/best-email-hosting-providers">Email hosting</a> is a bit cheaper but might not come with the same storage space.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1644px;"><p class="vanilla-image-block" style="padding-top:49.33%;"><img id="7AwwGN2oKx5u7LtjBxjKZ" name="Bluehost tools" alt="An image of Bluehost's tools" src="https://cdn.mos.cms.futurecdn.net/7AwwGN2oKx5u7LtjBxjKZ.jpg" mos="" align="middle" fullscreen="" width="1644" height="811" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>In the past I didn't use Google tools or features other than on simple sites I'd set up for recreational clubs. </p><p>For professional business websites, I just used email hosting from my hosting provider. This is something that I'm going to look into at a later date. If I was in a rush, I would just pay Bluehost. It's nothing that cannot be changed at a later date.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1910px;"><p class="vanilla-image-block" style="padding-top:46.07%;"><img id="8H6SAEKByh95r8pC4TRRc" name="Bluehost tools" alt="An image of Bluehost's tools" src="https://cdn.mos.cms.futurecdn.net/8H6SAEKByh95r8pC4TRRc.jpg" mos="" align="middle" fullscreen="" width="1910" height="880" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><h3 class="article-body__section" id="section-60-00"><span>60:00</span></h3><h3 class="article-body__section" id="section-overall-impressions"><span>Overall impressions</span></h3><p>My overall impression of Bluehost is good, and this little poke around has reinforced my belief that <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites#section-best-web-hosting-for-wordpress">Bluehost is best for WordPress</a> out of all the <a href="https://www.techradar.com/news/best-wordpress-hosting-providers">best WordPress hosting</a> options - at least for beginners.</p><p>Anyone who requires <a href="https://www.techradar.com/pro/website-hosting/best-hosting-for-agencies">WordPress hosting for an agency</a> or needs more performance like the <a href="https://www.techradar.com/web-hosting/best-small-business-web-hosting">best small business web hosting</a> would likely be better off with <a href="https://www.techradar.com/reviews/siteground">SiteGround</a>.</p><p>Bluehost is obviously all-in on WordPress, and so pretty much everything is geared towards the CMS. Overall, I liked the page building experience. I think the initial templates are a little bland but the WonderBlocks tool really helped add things to the pages with very little hassle, and the management tools were also very straightforward.</p><p>Lastly, even though I deliberated over whether I thought the Google Workspace tools were worth it, I do like that Bluehost leans on familiar tools which are in wide use, so people already know how to use them and there are already plenty of tutorials and helpful resources out there.</p><p>I managed to set up a site, make some speed optimizations, and get a good feel around Bluehost in an hour and that's the most I've managed to do with most hosts I've tried.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WordPress gets native GenAI support through 10Web ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/website-building/wordpress-gets-native-genai-support-through-10web</link>
                                                                            <description>
                            <![CDATA[ A fully white-labeled AI Website Builder solution is coming to WordPress in the form of a plugin. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BC5kThYhScQHE4FM7FyNCC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2UMvPDp3snEwaGbRuCivjE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Aug 2025 08:31:00 +0000</pubDate>                                                                                                                                <updated>Tue, 27 Jan 2026 16:55:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Website Building]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2UMvPDp3snEwaGbRuCivjE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Ryzhi]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An AI face in profile against a digital background.]]></media:description>                                                            <media:text><![CDATA[An AI face in profile against a digital background.]]></media:text>
                                <media:title type="plain"><![CDATA[An AI face in profile against a digital background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2UMvPDp3snEwaGbRuCivjE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>10Web announced a new WordPress plugin</strong></li><li><strong>It allows users to create fully white-labeled websites in minutes</strong></li><li><strong>Users can expect increased ARPU and reduced churn, 10Web says</strong></li></ul><p>You can now create a WordPress website in minutes, with the help of Generative AI (GenAI), without needing a third-party website builder or AI tool. Everything can be done in WordPress directly, through a chat interface, and without the website builder’s branding showing anywhere on the site.</p><p>This is all courtesy of one of the <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">best website builder</a> platforms <a href="https://www.techradar.com/computing/software/10web" target="_blank">10Web</a>, which just announced the launch of its fully white-labeled <a href="https://www.techradar.com/pro/website-building/i-tested-10-free-ai-website-builders-heres-what-i-found" target="_blank">AI website builder</a> solution. It comes in the form of a WordPress plugin, and allows users to create a website inside their hosting stack without relying on a separate builder platform. </p><p>In a press release shared with <em>TechRadar Pro</em> earlier this week, 10Web says the new offering should further increase ARPU, reduce churn, and differentiate through same-day AI website delivery. </p><p>“Hosting companies have been stuck selling blank WordPress installs,” said Arto Minasyan, Founder and CEO of 10Web. “With this solution, they can launch fully functional websites under their own brand in seconds. It’s the simplest way to deliver real customer value, without changing how they host or deploy WordPress.”</p><h2 id="woocommerce-included">WooCommerce included</h2><p>Usually, when a customer buys a hosting service, they get either a blank WordPress dashboard, or one bundled with themes and plugins. However, with the emergence of GenAI, expectations changed, and customers have gotten used to the “describe and build” experience, the company claims. </p><p>That being said, it claims “early tests” showed users being 30% more likely to publish their site compared to traditional WordPress onboarding flows. It didn’t say when the tests took place, who was tested, and against what, though. </p><p>In any case, 10Web says the plugin is built on its proprietary AI technology which leverages advanced models from OpenAI, Gemini, and Anthropic. The sites are mobile-friendly, fully structured, and based on a “simple business description”. </p><p>When users create a site, they will see a branded AI flow that generates the entire website, including WooCommerce integration, if needed. Finally, everything is white-labeled with the hosting provider’s name and logo, and includes a visual editor with AI Co-Pilot.</p><h3 class="article-body__section" id="section-more-from-techradar-pro"><span>More from TechRadar Pro</span></h3><ul><li><a href="https://www.techradar.com/pro/10web-claims-its-new-ai-tool-can-help-you-build-an-online-store-in-just-10-minutes" target="_blank">10Web claims its new AI tool can help you build an online store in just 10 minutes</a></li><li>Check out our roundup of the <a href="https://www.techradar.com/pro/best-ai-website-builder">best AI website builders</a> on the market</li><li>Learn more about Wix with our full <a href="https://www.techradar.com/reviews/wix">Wix review</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wix vs WordPress: Which website builder is better for small business? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/website-building/wix-vs-wordpress-which-website-builder-is-better-for-small-business</link>
                                                                            <description>
                            <![CDATA[ Wix is easy to use but much less flexible. WordPress.com is powerful but way harder to learn. Here's how to tell which no-code website builder is good for you. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">38rGFABaCGKMPmX43NApXV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pBcdRzPWMtBQvfXCu83Stk-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 Aug 2025 11:00:31 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Sep 2025 14:43:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Website Building]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ ritoban@nutgraf.agency (Ritoban Mukherjee) ]]></author>                    <dc:creator><![CDATA[ Ritoban Mukherjee ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/cD9joj4H54xYmooW8re3vU.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/pBcdRzPWMtBQvfXCu83Stk-1280-80.png">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wix vs WordPress]]></media:description>                                                            <media:text><![CDATA[Wix vs WordPress]]></media:text>
                                <media:title type="plain"><![CDATA[Wix vs WordPress]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pBcdRzPWMtBQvfXCu83Stk-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <div class="featured_product_block featured_block_versus" data-id="5a7e6286-6ad1-4d4a-b329-3883956b7970">            <div class='product-image-widthsetter'><p class='vanilla-image-block' data-bordeaux-image-check style='padding-top:68.48%';><img style="width: 100%" class="featured_image" src="https://cdn.mos.cms.futurecdn.net/PZVkJSP7sYa5EcCe9fWVCM.jpg" alt="white logo wix black background"></p></div>            <div class="featured_product_details_wrapper">                <div class="featured_product_title_wrapper">                                                                                <div class="featured__title">Wix</div>                                    </div>                <div class="subtitle__description">                                <div class="stars__reviews"><span itemprop="reviewRating" itemscope itemtype="http://schema.org/Rating" class="chunk rating"><span class="icon icon-star"> </span><span class="icon icon-star"> </span><span class="icon icon-star"> </span><span class="icon icon-star"> </span><span class="icon icon-star half"></span><meta itemprop="bestRating" content="100.0" /><meta itemprop="worstRating" content="0.0" /><meta itemprop="ratingValue" content="90" /></span></div>                                        <p><p>Wix is designed for beginners and small businesses. You get an easy drag-and-drop editor, loads of templates, and built-in tools for selling online. We love how simple it feels, but power users will notice some limits.</p></p>                </div>                <div class="pro-con"><div class="list-pros-wrapper"><h4 class="list-pros-label">Pros</h4><ul class="list-pros"><li class='list-item list-item-pros'>Drag-and-drop interface</li><li class='list-item list-item-pros'>2,000+ templates available</li><li class='list-item list-item-pros'>AI-powered design tools</li><li class='list-item list-item-pros'>Personalized SEO features</li><li class='list-item list-item-pros'>24/7 support</li></ul></div><div class="list-cons-wrapper"><h4 class="list-cons-label">Cons</h4><ul class="list-cons"><li class='list-item list-item-cons'>Many features to learn</li><li class='list-item list-item-cons'>No template swapping</li><li class='list-item list-item-cons'>Higher costs for upgrades</li><li class='list-item list-item-cons'>Slow loading times</li><li class='list-item list-item-cons'>Ads on free plan</li></ul></div></div>            </div>        </div>        <div class="featured_product_block featured_block_versus" data-id="c2d549e1-a4b1-4601-80bf-b877dac8198f">            <div class='product-image-widthsetter'><p class='vanilla-image-block' data-bordeaux-image-check style='padding-top:56.27%';><img style="width: 100%" class="featured_image" src="https://cdn.mos.cms.futurecdn.net/GR6CXmhULFpUQbqm7oFL3U.jpg" alt="WordPress logo"></p></div>            <div class="featured_product_details_wrapper">                <div class="featured_product_title_wrapper">                                                                                <div class="featured__title">WordPress.com</div>                                    </div>                <div class="subtitle__description">                                <div class="stars__reviews"><span itemprop="reviewRating" itemscope itemtype="http://schema.org/Rating" class="chunk rating"><span class="icon icon-star"> </span><span class="icon icon-star"> </span><span class="icon icon-star"> </span><span class="icon icon-star half"></span><meta itemprop="bestRating" content="100.0" /><meta itemprop="worstRating" content="0.0" /><meta itemprop="ratingValue" content="70" /></span></div>                                        <p><p>WordPress.com keeps things versatile for those looking for more options. Its new AI website builder creates sites lightning-fast, but settings can get complex. Still, it's a favorite for serious bloggers and growing businesses.</p></p>                </div>                <div class="pro-con"><div class="list-pros-wrapper"><h4 class="list-pros-label">Pros</h4><ul class="list-pros"><li class='list-item list-item-pros'>AI website builder</li><li class='list-item list-item-pros'>WordPress plugin ecosystem</li><li class='list-item list-item-pros'>Fast site generation</li><li class='list-item list-item-pros'>Solid SEO features</li><li class='list-item list-item-pros'>Huge community support</li></ul></div><div class="list-cons-wrapper"><h4 class="list-cons-label">Cons</h4><ul class="list-cons"><li class='list-item list-item-cons'>Some design limits</li><li class='list-item list-item-cons'>Redirect loops in free plan</li><li class='list-item list-item-cons'>Paid plan needed for plugins</li><li class='list-item list-item-cons'>Steeper learning curve</li><li class='list-item list-item-cons'>Complex for beginners</li></ul></div></div>            </div>        </div><p>When it comes to the <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">best website builder</a> platforms, there are countless choices. But, Wix and WordPress.com stand out. They’re the go-to website builders for people who don’t want to mess with code. </p><p>Wix focuses on drag-and-drop simplicity while WordPress.com brings more plugin options for power users. And in response to the AI boom, both have responded with sleek new features that offer personalized assistance for design and content.</p><p>If you're wondering if there's a clear winner, the answer's a bit complex. While we think that Wix does beat WordPress.com overall, there are at least some use cases that the latter is better suited for. Let's get into all of that now.</p><h2 class="article-body__section" id="section-wix-vs-wordpress-a-detailed-breakdown"><span>Wix vs WordPress: A detailed breakdown</span></h2><div ><table><thead><tr><th class="firstcol " ><p>Feature</p></th><th  ><p>Wix</p></th><th  ><p>WordPress.com</p></th></tr></thead><tbody><tr><td class="firstcol " ><p>Starting price: USD/month</p></td><td  ><p>$17</p></td><td  ><p>$4</p></td></tr><tr><td class="firstcol " ><p>Free plan</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td></tr><tr><td class="firstcol " ><p>Templates</p></td><td  ><p>2,000+ professional themes</p></td><td  ><p>1,000+ mobile-responsive designs</p></td></tr><tr><td class="firstcol " ><p>Editor type</p></td><td  ><p>Drag-and-drop, flexible</p></td><td  ><p>Block-based, AI-assisted</p></td></tr><tr><td class="firstcol " ><p>Design flexibility</p></td><td  ><p>High, with some limits</p></td><td  ><p>Standard patterns, customizable</p></td></tr><tr><td class="firstcol " ><p>SEO tools</p></td><td  ><p>Built-in, personalized</p></td><td  ><p>Basic included, plugins optional</p></td></tr><tr><td class="firstcol " ><p>Ecommerce capabilities</p></td><td  ><p>Built-in, paid plans</p></td><td  ><p>WooCommerce on business plan</p></td></tr><tr><td class="firstcol " ><p>Support</p></td><td  ><p>24/7 support available for paid users</p></td><td  ><p>DIY community and paid support</p></td></tr><tr><td class="firstcol " ><p>Loading speed</p></td><td  ><p>Can be slow sometimes</p></td><td  ><p>Generally faster than Wix</p></td></tr><tr><td class="firstcol " ><p>Plugin/app availability</p></td><td  ><p>500+ apps</p></td><td  ><p>50,000+ plugins</p></td></tr><tr><td class="firstcol " ><p>Customization</p></td><td  ><p>Customizable with restrictions</p></td><td  ><p>Highly customizable</p></td></tr><tr><td class="firstcol " ><p>Ads on free plan</p></td><td  ><p>Yes, Wix ads</p></td><td  ><p>Yes, WordPress.com branding</p></td></tr><tr><td class="firstcol " ><p>Mobile responsiveness</p></td><td  ><p>Responsive templates</p></td><td  ><p>Responsive themes</p></td></tr><tr><td class="firstcol " ><p>Hosting</p></td><td  ><p>Included</p></td><td  ><p>Included</p></td></tr><tr><td class="firstcol " ><p>Backup & Security</p></td><td  ><p>Managed by Wix</p></td><td  ><p>Managed by WordPress.com</p></td></tr></tbody></table></div><h2 class="article-body__section" id="section-wix-vs-wordpress-features"><span>Wix vs WordPress: Features</span></h2><p>Wix packs its builder with ready-to-use tools, live drag-and-drop editing, AI-powered layouts, and a huge template gallery covering almost any niche you can imagine. You get built-in ecommerce, booking systems, blog tools, and an App Market full of extra add-ons. Wix’s new AI features handle everything from social media posts to automated loyalty programs, all inside a slick dashboard designed for business growth.</p><p>WordPress.com, on the other hand, thrives on its extensibility. The platform starts simple, but its backbone is a library of thousands of themes and plugins. Need an online store, email integrations, SEO, advanced security, or custom workflows? There’s probably a plugin for that. The latest update introduces smarter AI design tools and performance boosters, like native caching, lazy loading, and automated design tweaks. This keeps WordPress.com fast and flexible, while new AI services make it easier to add tailored features as your business grows.</p><p>So which one's ultimately better? If you want turn-key features out of the box that can be customized easily, Wix is the best bet. WordPress.com is the better pick if you love tinkering and want to endlessly add or swap advanced tools as your needs change.</p><h2 class="article-body__section" id="section-wix-vs-wordpress-ease-of-use"><span>Wix vs WordPress: Ease of use</span></h2><p>Wix wins hearts for its speed and simplicity. From account setup to website launch, you’re always guided. Just pick a template or let the AI Builder do the heavy lifting by answering a few questions. Its visual editor is pure drag-and-drop, no coding needed. Menus, text, images, and even ecommerce features are all added in real-time, with instant previews. Updates, hosting, and security are handled behind the scenes, giving you more time to run your business.</p><p>WordPress.com has improved ease-of-use, but it still requires a more hands-on approach. You’ll need to choose a plan, pick a theme, and configure plugins for basic features. The Gutenberg editor gives you block-based visual editing with AI assistance, plus there are good setup wizards. But when it comes to deep customization or adding ecommerce, be prepared for extra reading and tweaking. Advanced features are robust, but they come with a steeper learning curve, especially for total beginners.</p><p>If you want a website up today with no headaches or homework, Wix is again the better choice. If you don’t mind digging in and want to learn as you build, WordPress.com pays off in flexibility and skills learned.</p><h2 class="article-body__section" id="section-wix-vs-wordpress-support"><span>Wix vs WordPress: Support</span></h2><p>Wix gives you 24/7 direct help for everyone, including free plan users. You get live chat, phone support, a big help center, video tutorials, and step-by-step guides. It’s direct, fast, and personal, great if you need help now or have urgent questions. You even get dedicated resources for new products like Wix Studio and App Builder.</p><p>WordPress.com divides support options by plan. Free users rely on extensive guides, community forums, and documentation. Paid users get access to human support, including live chat with company experts. They also offer AI-powered help for common issues now. But the WordPress ecosystem is huge, so the forums are always bustling.</p><p>In short, Wix makes it easier to get one-on-one help at any level. WordPress.com gives more flexibility for self-starters, but direct support is better on paid plans.</p><h2 class="article-body__section" id="section-wix-vs-wordpress-pricing-and-plans"><span>Wix vs WordPress: Pricing and plans</span></h2><p>Wix’s pricing is straightforward, if a bit higher upfront. The free plan lets you build with limited features and Wix ads. Paid plans start at $17/month for essentials, $36/month for small stores, and up to $159/month for advanced business needs. Each step unlocks extra features, from custom domain to greater storage, advanced analytics, and ecommerce tools. You can stay free as long as you want, but most growing businesses need a paid plan for full branding and upgrades.</p><div ><table><tbody><tr><td class="firstcol empty" ></td><td  ><p><strong>Free</strong></p></td><td  ><p><strong>Light</strong></p></td><td  ><p><strong>Core</strong></p></td><td  ><p><strong>Business</strong></p></td><td  ><p><strong>Business Elite</strong></p></td></tr><tr><td class="firstcol " ><p>Price (annual)</p></td><td  ><p>$0/month</p></td><td  ><p>$17/month</p></td><td  ><p>$29/month</p></td><td  ><p>$39/month</p></td><td  ><p>$159/month</p></td></tr><tr><td class="firstcol " ><p>Price (monthly)</p></td><td  ><p>$0/month</p></td><td  ><p>$29/month</p></td><td  ><p>$39/month</p></td><td  ><p>$46/month</p></td><td  ><p>$172/month</p></td></tr><tr><td class="firstcol " ><p>Collaborators</p></td><td  ><p>None</p></td><td  ><p>2</p></td><td  ><p>5</p></td><td  ><p>10</p></td><td  ><p>15</p></td></tr><tr><td class="firstcol " ><p>Storage Space</p></td><td  ><p>500MB</p></td><td  ><p>2GB</p></td><td  ><p>50GB</p></td><td  ><p>100GB</p></td><td  ><p>Unlimited</p></td></tr><tr><td class="firstcol " ><p>Custom Domain</p></td><td  ><p>Not included</p></td><td  ><p>Free 1st year</p></td><td  ><p>Free 1st year</p></td><td  ><p>Free 1st year</p></td><td  ><p>Free 1st year</p></td></tr><tr><td class="firstcol " ><p>Ecommerce</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>Basic</p></td><td  ><p>Standard</p></td><td  ><p>Advanced</p></td></tr><tr><td class="firstcol " ><p>Site Analytics</p></td><td  ><p>Basic</p></td><td  ><p>Basic</p></td><td  ><p>Basic</p></td><td  ><p>Standard</p></td><td  ><p>Advanced</p></td></tr><tr><td class="firstcol " ><p>Marketing Suite</p></td><td  ><p>Basic</p></td><td  ><p>Basic</p></td><td  ><p>Basic</p></td><td  ><p>Standard</p></td><td  ><p>Advanced</p></td></tr><tr><td class="firstcol " ><p>Dropshipping</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>25 products</p></td><td  ><p>250 products</p></td><td  ><p>Unlimited</p></td></tr><tr><td class="firstcol " ><p>Customer Reviews</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>3,000 reviews</p></td></tr><tr><td class="firstcol " ><p>Sales Tax Automation</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>None</p></td><td  ><p>500 transactions/month</p></td></tr><tr><td class="firstcol " ><p>Recommended For</p></td><td  ><p>Testing</p></td><td  ><p>Personal</p></td><td  ><p>Small stores</p></td><td  ><p>Established</p></td><td  ><p>Large brands</p></td></tr></tbody></table></div><p>WordPress.com starts lower, with a free plan and paid options from $4/month for personal use. The $8/month premium plan adds custom domains and themes. The $25/month business plan unlocks plugins, advanced SEO, and full design flexibility. This is followed by an ecommerce plan and a much pricier enterprise plan. Costs can rise if you add third-party plugins or premium themes, but you get more control of your spending for smaller budgets.</p><div ><table><tbody><tr><td class="firstcol empty" ></td><td  ><p><strong>Free</strong></p></td><td  ><p><strong>Personal</strong></p></td><td  ><p><strong>Premium</strong></p></td><td  ><p><strong>Business</strong></p></td><td  ><p><strong>Commerce</strong></p></td></tr><tr><td class="firstcol " ><p>Price (paid annually)</p></td><td  ><p>$0/month</p></td><td  ><p>$4/month</p></td><td  ><p>$8/month</p></td><td  ><p>$25/month</p></td><td  ><p>$45/month</p></td></tr><tr><td class="firstcol " ><p>Price (paid monthly)</p></td><td  ><p>$0/month</p></td><td  ><p>$5/month</p></td><td  ><p>$8/month</p></td><td  ><p>$30/month</p></td><td  ><p>$45/month</p></td></tr><tr><td class="firstcol " ><p>Storage</p></td><td  ><p>3GB</p></td><td  ><p>6GB</p></td><td  ><p>13GB</p></td><td  ><p>200GB</p></td><td  ><p>200GB</p></td></tr><tr><td class="firstcol " ><p>Custom domain</p></td><td  ><p>No</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td></tr><tr><td class="firstcol " ><p>Remove WordPress ads</p></td><td  ><p>No</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td></tr><tr><td class="firstcol " ><p>Support</p></td><td  ><p>Community forums</p></td><td  ><p>Email support</p></td><td  ><p>Live chat</p></td><td  ><p>Live chat & email</p></td><td  ><p>Live chat & email</p></td></tr><tr><td class="firstcol " ><p>Ecommerce capabilities</p></td><td  ><p>No</p></td><td  ><p>No</p></td><td  ><p>No</p></td><td  ><p>Yes (WooCommerce)</p></td><td  ><p>Yes (WooCommerce)</p></td></tr><tr><td class="firstcol " ><p>Themes selection</p></td><td  ><p>Limited</p></td><td  ><p>Standard</p></td><td  ><p>Standard</p></td><td  ><p>Premium</p></td><td  ><p>Premium</p></td></tr><tr><td class="firstcol " ><p>Plugins</p></td><td  ><p>No</p></td><td  ><p>No</p></td><td  ><p>No</p></td><td  ><p>Yes</p></td><td  ><p>Yes</p></td></tr></tbody></table></div><p>If you prefer one flat fee and lots of built-in tools, Wix has clearer pricing. WordPress.com offers better value when you're starting small and scaling over time.</p><h2 class="article-body__section" id="section-wix-vs-wordpress-final-verdict"><span>Wix vs WordPress: Final verdict</span></h2><p>So, which builder comes out on top? Wix is perfect if you want simplicity, fast setup, and loads of built-in features. You just drag, drop, and go. WordPress.com is better for those who want deeper customization and more control, especially if you don’t mind spending time learning and tweaking. You can start small and scale as your business grows. </p><p>In the end, it’s about your needs: choose Wix for ease and WordPress.com for flexibility. Either way, our guide should help you match specific features and pricing details to your current requirements.</p><h2 class="article-body__section" id="section-wix-vs-shopify-faqs"><span>Wix vs Shopify: FAQs</span></h2><section class="article__schema-question"><h3>Which is easier for beginners, Wix or WordPress.com?</h3><article class="article__schema-answer"><p>Wix is easier to get started with. You sign up, pick a template, and start editing right away. Its drag-and-drop system is very intuitive, so you won’t feel lost even if you’ve never built a website before. WordPress.com has a steeper learning curve and may require more setup, especially if you want extra features, like plugins or ecommerce.</p></article></section><section class="article__schema-question"><h3>Can you sell products with both platforms?</h3><article class="article__schema-answer"><p>Yes, both Wix and WordPress.com offer ecommerce tools. Wix includes store capabilities in higher-tier plans, makes adding products and managing payments straightforward, and is ideal for basic online stores. WordPress.com lets you use WooCommerce (on business plans), which is extremely customizable but needs more setup. Think about what you plan to sell before choosing.</p></article></section><section class="article__schema-question"><h3>Are there free plans with Wix or WordPress.com?</h3><article class="article__schema-answer"><p>Both platforms provide free plans. Wix’s free plan lets you build and publish but includes Wix ads. WordPress.com’s free version is more limited and shows WordPress branding. For serious business use, paid plans unlock custom domains, more storage, and extra features.</p></article></section><section class="article__schema-question"><h3>Which has better customer support?</h3><article class="article__schema-answer"><p>Wix edges out with  24/7 human support for everyone, even free users. You can get help fast via chat or phone. WordPress.com relies more on guides and forums if you’re on the free plan, but offers premium support to paying users. If access to personal help matters a lot to you, Wix takes the lead.</p></article></section><section class="article__schema-question"><h3>Can I customize my site more freely with WordPress.com or Wix?</h3><article class="article__schema-answer"><p>WordPress.com is best for deep customization, thanks to its plugin and theme ecosystem. You can add features, tweak code, and adjust almost everything (on paid plans). Wix is easier but limits your options, what you see is mostly what you get. If customization matters, WordPress.com is the better pick.</p></article></section>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thanks to Kodee your WordPress pains are over over! ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/thanks-to-kodee-your-wordpress-pains-are-over-over</link>
                                                                            <description>
                            <![CDATA[ WordPress is going to become so much easier to use: Thanks to Kodee ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Tc3SdyQzPhe8fBgT4dP56D</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EedKpUyVcrvJ842gPLXfLi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Aug 2025 13:58:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Capell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/h2jxs4impEB7K2rxEpTRy4.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EedKpUyVcrvJ842gPLXfLi-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kodee logo on a blue background]]></media:description>                                                            <media:text><![CDATA[Kodee logo on a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[Kodee logo on a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EedKpUyVcrvJ842gPLXfLi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Makes changes to your website using natural language</strong></li><li><strong>SEO optimize your site</strong></li><li><strong>Woo-commerce ready</strong></li></ul><p>I like WordPress. I do! What's not to like? It's free, it's used by basically everyone so there's so much help available, and it's supported by all the <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">best web hosting</a> providers. There is just one thing about it that I, and others, find incredibly frustrating. The page builder.</p><p>Now, thanks to <a href="https://www.techradar.com/reviews/hostinger">Hostinger</a>, those pains will hopefully be over because Kodee, Hostinger's AI management tool,  is going to be released with direct integration with your WordPress site.</p><h2 id="knock-knock-who-s-that-it-s-kodee-helping-you-with-wordpress">Knock Knock. Who's that? It's Kodee helping you with WordPress</h2><p>I've built WordPress sites before but I'm not a website building expert covering the <a href="https://www.techradar.com/news/the-best-website-builder">best website builders</a> like my colleague <a href="https://www.techradar.com/author/owain-williams">Owain Williams</a>. My area is more website infrastructure (hosting, domains, that sort of stuff) but I do occasionally have a dabble in WordPress because I want to know more about it when recommending the <a href="https://www.techradar.com/news/best-wordpress-hosting-providers">best WordPress hosting</a>. </p><p>In my most recent dives into WordPress for my one hour with series, covering what it's like to buy and set up a website with web hosting providers I encountered many beginner WordPress issues after I had purchased and set up a server.</p><ul><li><a href="https://www.techradar.com/pro/website-hosting/hostinger-in-60-minutes-learn-from-these-rookie-mistakes" target="_blank">Hostinger in 60 minutes: Learn from these rookie mistakes</a></li><li><a href="https://www.techradar.com/pro/website-hosting/dreamhost-in-60-minutes-slow-servers-but-neat-business-features" target="_blank">Dreamhost in 60 minutes: slow server installs but neat business features</a></li><li><a href="https://www.techradar.com/pro/website-hosting/kinsta-in-60-minutes-is-this-host-a-good-choice-for-your-agency" target="_blank">Kinsta in 60 minutes: Is this host good for your agency?</a></li></ul><p>The issue I mostly encountered was working my way around the WordPress block editor Gutenberg. Any time I wanted to remove a button from a template, modify a title, or change how a page element appeared I found myself spending 15 minutes trying to locate a button and then another ten undoing all the mess that pressing that button achieved.</p><p>Kodee promises to relieve users of these frustrations as soon WordPress users should be able to modify and edit a page just by asking Kodee to do it for them.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/l1yY4pV0Vxc" allowfullscreen></iframe></div></div><h2 id="kodee-is-not-quite-ready-yet">Kodee is not quite ready yet</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:341px;"><p class="vanilla-image-block" style="padding-top:122.29%;"><img id="GtkUjvDdpnrHVdmchFUUBf" name="Kodee is not live yet" alt="An image of an interaction with Kodee with Kodee explaining that it cannot help" src="https://cdn.mos.cms.futurecdn.net/GtkUjvDdpnrHVdmchFUUBf.jpg" mos="" align="middle" fullscreen="" width="341" height="417" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>Earlier in the year Kodee was released to be used as an <a href="https://www.techradar.com/pro/meet-vps-kodee-your-new-ai-sysadmin">AI sysadmin tool for VPS</a> servers helping users manage their environment with natural language. <strong>For WordPress management Kodee is expected to be released in August.</strong></p><p>When it is released Kodee will be able to add pages and posts, edit the text and layout of a page including adding new sections, replace images and content, plus manage settings, plugins, and many other site tasks.</p><h2 id="available-on-hostinger-business-and-cloud-hosting-plans">Available on Hostinger Business and Cloud hosting plans</h2><p>Kodee won't be available on Hostingers lower-end plans such as the single site plan (not available in all regions) and the Premium hosting plan. This means that you'll need to pay at least an extra 0.78$/mo for the first 38 months and then and extra 3$ a month after to use the tool if you didn't intend on buying one of the more powerful plans.</p><p>In my opinion, that's a worthy investment if like me, you're not very page builder savvy.</p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li>Read about my time at the <a href="https://www.techradar.com/pro/live/wordcamp-europe-2025-all-the-latest-news-and-updates-as-they-happen">WordCamp Europe</a> event</li><li>My list of the <a href="https://www.techradar.com/news/best-managed-wordpress-hosting">best managed WordPress hosting</a> providers</li><li><a href="https://www.techradar.com/news/what-is-wordpress-hosting">Learn more about WordPress hosting</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers target critical WordPress theme flaw - hundreds of sites at risk from potential takeover, find out if you're affected ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-target-critical-wordpress-theme-flaw-thousands-of-sites-at-risk-from-potential-takeover-find-out-if-youre-affected</link>
                                                                            <description>
                            <![CDATA[ A bug that allows for WordPress site takeover is being actively exploited in the wild, experts have warned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o6CRndjfQiCXL7WEQvXf2Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Jul 2025 18:33:00 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Sep 2025 15:39:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Alone – Charity Multipurpose Non-profit WordPress Theme has a 9.8/10 flaw</strong></li><li><strong>The bug allows crooks to create rogue admin accounts</strong></li><li><strong>More than 120,000 takeover attempts already blocked</strong></li></ul><p>The "Alone – Charity Multipurpose Non-profit WordPress Theme", a commercial theme used in many <a href="https://www.techradar.com/news/best-wordpress-hosting-providers" target="_blank">WordPress</a> websites, contained a critical vulnerability that allowed threat actors to completely take over the website, experts have warned.</p><p>The <a href="https://www.techradar.com/news/best-wordpress-theme" target="_blank">WordPress theme</a>, designed for charities, NGOs, and fundraising campaigns, features more than 40 ready-to-use demos, donation integration, and compatibility with Elementor and WPBakery. </p><p>According to Themetix, around 200 active WordPress sites are running this theme today.</p><h2 id="ongoing-attacks">Ongoing attacks</h2><p>Wordfence researchers claim exploitation started on July 12, two days before the vulnerability was publicly disclosed. So far, the company blocked more than 120,000 exploitation attempts from almost a dozen different IP addresses.</p><p>In the attacks, the threat actors try to upload a ZIP archive with a PHP-based backdoor that grants them remote code execution capabilities, as well as the ability to upload arbitrary files. Crooks also used the flaw to deliver backdoors that can create additional admin accounts. </p><p>All versions up to 7.8.3 contained a vulnerability that allowed threat actors to upload arbitrary files, including malware that can create admin accounts. That way, crooks can completely take over websites and use them to host other malware, redirect visitors to other malicious pages, serve phishing landing pages, and more. </p><p>The vulnerability is now tracked as CVE-2025-4394, and has a severity score of 9.8/10 (critical). It was addressed in version 7.8.5, which was released on June 16, 2025. If you are using this theme, it would be wise to update it as soon as possible, since the bug is being actively exploited in the wild.</p><p>WordPress is generally considered one of the <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">best website builder</a> platforms and a safe option, but third-party themes and plugins - not so much. That is why security pros advise WordPress users to only keep the plugins and themes they actively use, and to make sure they are always up to date. </p><p><em>Via </em><a href="https://thehackernews.com/2025/07/hackers-exploit-critical-wordpress.html" target="_blank"><em>The Hacker News</em></a></p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/pro/a-popular-wordpress-theme-has-been-hijacked-by-malware-heres-what-we-know" target="_blank">A popular WordPress theme has been hijacked by malware - here's what we know</a></li><li>Take a look at our guide to the <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">best authenticator app</a></li><li>We've rounded up the <a href="https://www.techradar.com/best/password-manager" target="_blank">best password managers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous WordPress plugin puts over 160,000 sites at risk - here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/dangerous-wordpress-plugin-puts-over-160-000-sites-at-risk-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ A popular WordPress plugin allowed crooks to reset admin accounts and take over a website. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ERk5umVgodbEhWfUueV7E8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 28 Jul 2025 13:05:00 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Sep 2025 09:08:30 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Person editing a WordPress site]]></media:text>
                                <media:title type="plain"><![CDATA[Person editing a WordPress site]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xwpEUtGigAH5K4krGZFy5K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Older versions of Post SMTP allowed hackers to read all emails</strong></li><li><strong>They could also reset the admin password and read the notification email, gaining access to the account</strong></li><li><strong>More than 160,000 WordPress sites are running the vulnerable version</strong></li></ul><p>A popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> with hundreds of thousands of active installations carried a vulnerability that allowed threat actors to take over compromised websites, experts have warned.</p><p>The plugin is called Post SMTP, a tool that replaces WordPress’s default email function with an authenticated SMTP method, and currently counts more than 400,000 active installations.</p><p>Security researchers PatchStack warned an access control mechanism in the plugin’s REST API endpoint was broken, only verifying if a user was logged in, and not checking whether they had permissions to do certain actions, or not. As a result, low-privileged users were allowed access to email logs with full email contents, meaning they were allowed to initiate a password reset for the admin account, view that email, and then log in as the admin, essentially taking over the site.</p><h2 id="patching-the-bug">Patching the bug</h2><p>The bug was first spotted on May 23, and by May 26, it was already assigned a CVE and a severity score - being tracked as CVE-2025-24000, with a medium severity score of 8.8/10. </p><p>Looking at the download statistics on <a href="http://wordpress.org" target="_blank" rel="nofollow">WordPress.org</a>, 59.8% of all Post SMTP installations are running versions 3.1 and newer, meaning 40.2% of sites are still vulnerable. </p><p>Since the plugin has more than 400,000 active installations, it means around 160,000 websites can still be taken over using this method. </p><p>WordPress is considered one of the <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">best website builder</a> platforms in the world, powering more than half of all sites on the internet and as such, is a popular target for cybercriminals. </p><p>However, since WordPress is generally considered a secure platform, crooks are focused on plugins and themes which don’t have the same level of security or support. </p><p>That is why most cybersecurity professionals recommend only keeping the plugins and themes that are in use, and always making sure they are up to date. </p><p>This issue was fixed in version 3.3.0, published on June 11, 2025, so users should update as soon as possible to ensure they stay protected.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/post-smtp-plugin-flaw-exposes-200k-wordpress-sites-to-hijacking-attacks/" target="_blank"><em>BleepingComputer</em></a></p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/pro/security/another-top-wordpress-plugin-hacked-to-allow-account-takeover-stay-safe-with-these-tips" target="_blank">Another top WordPress plugin hacked to allow account takeover - stay safe with these tips</a></li><li>Take a look at our guide to the <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">best authenticator app</a></li><li>We've rounded up the <a href="https://www.techradar.com/best/password-manager" target="_blank">best password managers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything you need to know about the new Agency Partnership Program at Cloudways ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/website-hosting/everything-you-need-to-know-about-the-new-agency-partnership-program-at-cloudways</link>
                                                                            <description>
                            <![CDATA[ Cloudways has revamped its Agency Partnership Program: Here's what's new ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YNtxxe3DReupgGancWF7Fg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZtJtYbk4sFXJtFpX7Yfmrb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Jul 2025 15:36:17 +0000</pubDate>                                                                                                                                <updated>Wed, 09 Jul 2025 13:35:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Website Hosting]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Capell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/h2jxs4impEB7K2rxEpTRy4.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZtJtYbk4sFXJtFpX7Yfmrb-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The text Cloudways Agency Partnership Program on a blue background]]></media:description>                                                            <media:text><![CDATA[The text Cloudways Agency Partnership Program on a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[The text Cloudways Agency Partnership Program on a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZtJtYbk4sFXJtFpX7Yfmrb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's a lot of buzz around agency hosting these days. It seemed that most of the <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">best web hosting</a> providers wanted to talk about their new agency hosting plans at <a href="https://www.techradar.com/pro/live/wordcamp-europe-2025-all-the-latest-news-and-updates-as-they-happen">WordCamp Europe</a> when I attended. It sparked me to write my new <a href="https://www.techradar.com/pro/website-hosting/best-hosting-for-agencies-in-2025">best hosting for agencies</a> guide, and when I started my research, I thought there was no better place to start than with Cloudways.</p><p><a href="https://www.techradar.com/reviews/cloudways">Cloudways</a> has had their Agency Partnership Program since 2021, and it has over 3000 users. It has recently been revamped and relaunched, so I spoke with Fatih Mehtap, VP Marketing, at Coudways about the changes to learn more about the program and what web agencies need from their hosting providers.</p><h2 id="what-drove-the-decision-to-refine-and-relaunch-the-agency-partnership-programme-now">What drove the decision to refine and relaunch the Agency Partnership Programme now?</h2><p>There were two core drivers behind the relaunch. First and foremost, customer feedback. We regularly run pulse surveys, focus groups, and cohort interviews to really understand how our partners feel about the program and where they see room for improvement. A common theme from our agency partners was for us to provide even more support and engagement. The feedback was fair and something we wanted to prioritise. </p><p>Relaunching the programme now with renewed vigor is about acknowledging the wants of our partners and recommitting to them with dedicated focus, staffing, and strategic direction.</p><h2 id="with-over-3-000-agencies-already-in-the-program-what-feedback-shaped-these-new-enhancements">With over 3,000 agencies already in the program, what feedback shaped these new enhancements?</h2><p>Our customers wanted more dedicated support, better onboarding, more proactive account engagement, and stronger tools to help them grow. </p><p>We’ve implemented dedicated partner onboarding liaisons, offer migration services handled by our engineers, including unlimited free migrations for higher tiers, and quarterly or biannual account reviews. These reviews not only give partners visibility into their tier progression but also uncover potential cost savings or unlock new benefits, like hosting credits and premium support. </p><h2 id="how-does-this-refined-programme-position-cloudways-compared-with-competitors">How does this refined programme position Cloudways compared with competitors?</h2><p>Our customers are the driving force behind why we innovate. Every company operates differently, but our focus is to create solutions aligned to our customer needs and wants. From this creation process, there are a few clear differentiators. </p><p>At the Gold and Platinum tiers of the programme, agencies get access to unlimited white-glove migrations, removing a major technical and financial barrier to switching and consolidating clients. Combined with a revamped Partner Hub, these features go beyond what most hosts provide, especially for agencies focused on growth. They help simplify operations, reduce overhead, and free up resources, allowing teams to focus more on scaling their business rather than dealing with infrastructure complexities.</p><h2 id="can-you-walk-us-through-the-15-000-learning-resources-package-what-specific-skills-and-trends-are-you-helping-agencies-master">Can you walk us through the $15,000+ learning resources package? What specific skills and trends are you helping agencies master?</h2><p>The learning content originated from UGURUS – a coaching content platform built specifically for agency owners. Before the relaunch, content was curated and sold in different tier packages, starting at around $2,000 per year. We’ve ungated all of this content for the benefit of programme partners.</p><p>The learning resources specifically provide a comprehensive range of content supporting agencies at various stages of growth and maturity. This includes guidance on starting and scaling an agency, improving sales techniques, building and maintaining client relationships, mastering outreach strategies and refining internal operations and business development practices. The resources are designed to meet the needs of solo entrepreneurs just beginning their journey, through to established agencies looking to optimise strategies.</p><h2 id="what-roi-can-agencies-expect-to-see-through-the-partnership-programme">What ROI can agencies expect to see through the partnership programme?</h2><p>Expected ROI from the partnership programme varies based on agency size, goals, and how actively they engage with the benefits. Many partners experience immediate cost reductions through hosting credits and access to premium support, which helps lower their operational expenses, whereas others benefit from long-term loyalty discounts and time-to-market savings. </p><p>Through referrals and affiliate commissions, every agency partner can benefit from generating passive income through recurring earnings, and the educational content provides a clear path to scaling up services and refining operations. </p><p>Ultimately, agencies can expect to get out what they put in. While some see measurable savings within a single quarter, others are leveraging the programme to unlock entirely new revenue streams, particularly through co-marketing opportunities and long-term client growth strategies. One of the favourite features of our program is the Agency Spotlight and case studies we publish on our website; those get thousands of views every month. Our agencies appreciate the brand visibility.</p><h2 id="can-you-tell-me-more-about-the-co-marketing-opportunities-that-come-with-the-programme">Can you tell me more about the co-marketing opportunities that come with the programme?</h2><p>Co-marketing is a key area of opportunity, especially for our top-tier partners. Cloudways is actively looking to collaborate with agencies on webinars, case studies, guest blog posts, and social promotions. If a partner is doing outstanding work powered by a Cloudways solution, we want to help amplify their story and provide visibility across our channels. </p><p>It’s about building a mutually beneficial spotlight. One that not only shows off the partnership’s great work, but also drives leads, credibility, and reach for both sides. </p><p>Over the course of the Calendar year, we run multiple virtual and in-person events, using these platforms to invite customers to take part and share their perspective on what’s happening in the industry.</p><h2 id="how-is-the-agency-hosting-landscape-evolving-and-where-do-you-see-the-biggest-opportunities">How is the agency hosting landscape evolving, and where do you see the biggest opportunities? </h2><p>Agencies are no longer just service providers; they’re becoming strategic digital partners to their clients. The shift means they need infrastructure that’s flexible, scalable, and backed by responsive, knowledgeable support. Many of our customers come to us because they want more control and accessibility to how they run their hosting. We help</p><p>them evolve their offering through greater choice, flexibility, and scalability, capabilities not every hosting provider can provide. </p><p>The opportunity for agency hosting lies in serving those evolving needs. That’s why we’re leaning into things like robust learning tools, premium service layers, and scalable partner incentives. Agencies want to grow, diversify, and build more sustainable income models, and we’re aligning our platform and programme to support that evolution.</p><h2 id="what-are-the-main-differences-between-the-support-levels">What are the main differences between the support levels?</h2><p>Support is structured in tiers, with each level offering increased access to premium services. </p><p>Bronze and Silver partners receive standard 24/7 support, including chat-based troubleshooting for day-to-day issues. As agencies move into the Gold and Platinum tiers, they unlock advanced and premium support features such as faster response times, dedicated squads, more proactive issue resolution and advanced troubleshooting assistance. </p><p>At the Platinum level, support becomes even more hands-on. It includes deeper technical involvement like multi-site performance optimisation and infrastructure tuning, often delivered through senior, tenured migration and onboarding specialists. </p><p>Ultimately, our aim is to remove any ambiguity. Partners know that we are a help desk inquiry away and that helps them build confidence to experiment on the platform. Partners always know exactly what level of support they’re receiving and how it aligns with the complexity of their operations.</p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/pro/website-hosting/kinsta-vs-wp-engine-whats-best-web-host-for-your-web-agency">WP Engine vs Kinsta</a>: Whats best for your agency?</li><li>One Hour with Kinsta</li><li>The <a href="https://www.techradar.com/news/best-cloud-hosting-providers">best cloud hosting</a> providers</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another top WordPress plugin hacked to allow account takeover - stay safe with these tips ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/another-top-wordpress-plugin-hacked-to-allow-account-takeover-stay-safe-with-these-tips</link>
                                                                            <description>
                            <![CDATA[ Another high-severity flaw was found in Forminator, a popular WordPress plugin. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k7u2kcLXP6QTRXML5yYimN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Jul 2025 17:02:00 +0000</pubDate>                                                                                                                                <updated>Mon, 28 Jul 2025 14:08:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[WordPress logo on mobile]]></media:description>                                                            <media:text><![CDATA[WordPress logo on mobile]]></media:text>
                                <media:title type="plain"><![CDATA[WordPress logo on mobile]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Experts find a way to trick Forminator into deleting a core WordPress file</strong></li><li><strong>This process would trigger the site's setup, where hackers can take it over</strong></li><li><strong>A patch is available, and users are advised to apply it </strong></li></ul><p>A popular <a href="https://www.techradar.com/best/best-wordpress-plugins" target="_blank">WordPress plugin</a> active on hundreds of thousands of websites was found to be carrying a high-severity vulnerability which could allow threat actors to fully take over compromised websites. </p><p>Forminator is a <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">website builder</a> plugin which allows WordPress operators to add custom contact, feedback, quizzes, surveys, polls, and payment forms. Everything is drag-and-drop and thus user-friendly, and plays well with many other plugins.</p><p>Recently, a security researcher with the alias ‘Phat RiO – BlueRock’ found the plugin had insufficient validation and sanitation of form field input vulnerability, as well as an unsafe file deletion logic. It could be abused to insert a custom file into any field, which would (after a few steps) force Forminator into deleting the core WordPress file. As a result, the entire website enters the “setup” stage, where the attacker can take it over. </p><div class="product"><a data-dimension112="643b79c4-9546-44e6-8c55-fe39da37c58a" data-action="Deal Block" data-label="Get 55% off Incogni's Data Removal service with code TECHRADAR" data-dimension48="Get 55% off Incogni's Data Removal service with code TECHRADAR" href="https://deal.incogni.io/aff_c?offer_id=3&amp;aff_id=1039&amp;url_id=6&amp;source=widget1" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1952px;"><p class="vanilla-image-block" style="padding-top:43.03%;"><img id="odcAYcHngBQcL58u46JXnU" name="Screenshot 2024-07-16 at 2.22.38 pm.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/odcAYcHngBQcL58u46JXnU.png" mos="" align="middle" fullscreen="" width="1952" height="840" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://deal.incogni.io/aff_c?offer_id=3&amp;aff_id=1039&amp;url_id=6&amp;source=widget1" target="_blank" rel="nofollow" data-dimension112="643b79c4-9546-44e6-8c55-fe39da37c58a" data-action="Deal Block" data-label="Get 55% off Incogni's Data Removal service with code TECHRADAR" data-dimension48="Get 55% off Incogni's Data Removal service with code TECHRADAR" data-dimension25=""><strong>Get 55% off Incogni's Data Removal service with code TECHRADAR</strong></a> </p><p>Wipe your personal data off the internet with the Incogni data removal service. Stop identity thieves<br>and protect your privacy from unwanted spam and scam calls.<a class="view-deal button" href="https://deal.incogni.io/aff_c?offer_id=3&aff_id=1039&url_id=6&source=widget1" target="_blank" rel="nofollow" data-dimension112="643b79c4-9546-44e6-8c55-fe39da37c58a" data-action="Deal Block" data-label="Get 55% off Incogni's Data Removal service with code TECHRADAR" data-dimension48="Get 55% off Incogni's Data Removal service with code TECHRADAR" data-dimension25="">View Deal</a></p></div><h2 id="how-to-stay-safe-3">How to stay safe</h2><p>“Deleting wp-config.php forces the site into a setup state, allowing an attacker to initiate a site takeover by connecting it to a database under their control,” noted experts at Wordfence, a WordPress security project.</p><p>The vulnerability is tracked as CVE-2025-6463, and has a severity score of 8.8/10 - high. All versions up to 1.44.2 are vulnerable. As per Wordpress.org data, there are more than 600,000 active websites using this plugin, making the attack surface rather large. </p><p>The first clean version is 1.44.3, and the plugin’s vendors, WPMU DEV, is urging all users to apply it as soon as possible. <a href="https://www.bleepingcomputer.com/news/security/forminator-plugin-flaw-exposes-wordpress-sites-to-takeover-attacks/" target="_blank"><em>BleepingComputer</em></a> says since the patch was released, the plugin was downloaded 200,000 times, “but it is unclear how many are currently vulnerable to exploitation”. </p><p>To mitigate the risk of attack, website admins should upgrade their Forminator plugin to the newest version, or disable and delete the plugin altogether. Generally speaking, WordPress as a platform is considered safe, with various plugins and themes being the weakest link in this security chain.</p><p>That being said, WordPress users are advised to only keep those plugins and themes that they’re using, ensuring these are updated regularly, while disabling and deleting all others.</p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li><a href="https://www.techradar.com/pro/security/a-critical-security-flaw-could-affect-thousands-of-wordpress-sites" target="_blank">A critical security flaw could affect thousands of WordPress sites</a></li><li>Take a look at our guide to the <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">best authenticator app</a></li><li>We've rounded up the <a href="https://www.techradar.com/best/password-manager" target="_blank">best password managers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Prepare for non-human visitors! ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/website-hosting/prepare-for-non-human-visitors</link>
                                                                            <description>
                            <![CDATA[ As more AI agents scan the web for content Saulius Lazaravičius, VP of product at Hostinger, explains how you can make your site more search friendly for the future. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZfV5xFWu6HKx4kR927QAFC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gmMZMeeJyrjSCQVsCXDimc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Jun 2025 22:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Website Hosting]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Capell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/h2jxs4impEB7K2rxEpTRy4.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gmMZMeeJyrjSCQVsCXDimc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The outline of a head in a futuristic style]]></media:description>                                                            <media:text><![CDATA[The outline of a head in a futuristic style]]></media:text>
                                <media:title type="plain"><![CDATA[The outline of a head in a futuristic style]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gmMZMeeJyrjSCQVsCXDimc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>So, non-human visitors are not exactly new. Bots have been scrolling the web since the 90s but search is changing and evolving and website owners now need to start preparing for AI agents visiting their site too.</p><p>Don't believe me? Jason Mayes, Web AI Lead at Google, recently spoke at <a href="https://www.techradar.com/pro/live/wordcamp-europe-2025-all-the-latest-news-and-updates-as-they-happen">WordCamp Europe </a>saying: "We're now entering the age where AI agents are growing in popularity". Hostinger, one of the <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">best web hosting</a> providers, believe it too and have recently launched a new tool to automatically create an LLMs.txt file for WordPress sites.</p><p>AI agents are powered by Large Language Models (LLMs) such as Google's Gemini, Anthropic's Claude, and OpenAI's ChatGPT. These models can seemingly read and understand text like a human but there are things we can do to help them understand websites better. Just like how robots.txt and sitemap.html help traditional search methods navigate and understand websites, LLMs.txt severs the purpose for AI agents.</p><p>To learn more about AI agents, LLMs, and how they're shaping search, I spoke to Saulius Lazaravičius, VP of product at <a href="https://www.techradar.com/reviews/hostinger">Hostinger</a>, about the new tool to create LLMs.txt files.</p><h2 id="so-what-is-llms-txt-and-how-is-it-related-to-search-and-site-visitors">So, what is LLMs.txt, and how is it related to search and site visitors? </h2><p>Traditionally, people find information online through search engines like Google, which rely on robots.txt and sitemap.xml files to navigate and index content. But with the rise of AI tools like ChatGPT and Claude, more users now get answers directly from large language models (LLMs), bypassing traditional search. </p><p>That’s where LLMs.txt file comes in. It serves as a map for AI systems, helping them identify and understand the most important parts of a website. LLMs.txt file provides: </p><ul><li>A clear, prioritized list of the site’s key pages</li><li>Concise summaries for page content</li><li>Links to more detailed, authoritative resources</li></ul><p>Placed alongside robots.txt and sitemap.xml, the LLMs.txt file improves how AI engines interpret complex site structures – potentially increasing a site's visibility in AI-generated answers.</p><h2 id="is-there-currently-any-data-that-shows-the-benefit-of-having-llms-txt-alongside-robots-txt-and-a-sitemap-xml">Is there currently any data that shows the benefit of having LLMs.txt alongside robots.txt and a sitemap.xml?</h2><p>Currently, adoption of LLMs.txt is still in its infancy, with fewer than 1% of the top one million websites using it as of early 2025. However, the share of traffic coming from AI platforms is constantly growing. For example, usage of AI-driven search among adults in the US is projected to more than double by 2028.</p><p>While hard data on LLMs.txt effectiveness is still emerging, the broader concept of "SEO for AI" – also known as generative engine optimization (GEO) – is gaining traction. Website owners are increasingly looking for ways to make their content more accessible and relevant to AI systems. LLMs.txt is an early, proactive step in that direction.</p><h2 id="what-makes-a-good-llms-txt-file-and-how-do-you-achieve-this-through-one-click">What makes a good LLMs.txt file, and how do you achieve this through one click? </h2><p>A well-structured LLMs.txt file is clean, simple, and focused on surfacing a site’s most valuable content for AI systems. It typically begins with the website’s main address, followed by selected pages that AI models should prioritize. Optional descriptions can be added to clarify the content structure or hierarchy.</p><p>The file is hosted at the root of the website (e.g. domain.tld/llms.txt) and is easy to set up – especially with automated tools like our one-click LLMs.txt file creator.</p><p>Importantly, implementing an LLMs.txt file has no negative impact on traditional SEO. It’s a forward-looking, proactive step that makes a site more accessible to AI tools – both now and in the future.</p><h2 id="how-soon-do-you-see-llms-txt-becoming-a-web-standard">How soon do you see LLMs.txt becoming a web standard? </h2><p>With AI playing a growing role in how people discover content, more businesses will need to optimize websites not just for search engines, but for AI systems as well. This adoption is expected to increase significantly in the next few months or years. </p><p>It’s still unclear whether LLMs.txt will become a long-term standard. It might evolve into something more sophisticated, like NLWeb or API-driven solutions. But the concept of making content easily digestible for AI is here to stay. </p><p>At Hostinger, we’re committed to giving our customers a competitive edge. That’s why we were among the first to offer automatic LLMs.txt file creation, and we’ll continue evolving our tools as the GEO landscape changes.</p><h2 id="are-there-any-other-things-website-owners-can-do-to-improve-their-site-visibility-to-ai">Are there any other things website owners can do to improve their site visibility to AI?</h2><p>Like traditional search engines, AI systems look for valuable, high-quality content. That means creating genuinely helpful information for people, ensuring the site is fast, mobile-friendly, and easy to navigate, and making the content technically accessible for crawling and indexing. </p><p>Each website owner should understand that AI-backed browsing is here and it’s growing. That means they must constantly check what’s new in the field of GEO and look for tools that expose their website content for LLMs. Today, LLMs.txt is a strong first step. </p><p>Looking ahead, we believe that websites may evolve toward Model Context Protocol (MCP) interfaces, where content isn’t just displayed for humans but served via MCP-compatible APIs, and AI agents will consume it on users’ behalf.</p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li>Looking for the <a href="https://www.techradar.com/news/best-wordpress-hosting-providers">best WordPress hosting</a>?</li><li>Or simply want to <a href="https://www.techradar.com/pro/what-is-wordpress">learn more about WordPress</a>?</li><li>There's also my round-up of the <a href="https://www.techradar.com/news/best-vps-hosting">best VPS hosting</a> providers</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What Is WordPress? Everything a beginner needs to know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/what-is-wordpress</link>
                                                                            <description>
                            <![CDATA[ Complete guide on understanding WordPress ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u97AdpewEkQmJF4xPdPQmV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7ehqrjkNyoaWQ9eN7A65sC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Jun 2025 12:15:30 +0000</pubDate>                                                                                                                                <updated>Fri, 08 Aug 2025 14:30:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Website Hosting]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ James Capell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/h2jxs4impEB7K2rxEpTRy4.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7ehqrjkNyoaWQ9eN7A65sC-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Person working on a WordPress post]]></media:text>
                                <media:title type="plain"><![CDATA[Person working on a WordPress post]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7ehqrjkNyoaWQ9eN7A65sC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites">best Web hosting</a> companies all support WordPress and there are even specialist hosts which pride themselves on providing the <a href="https://www.techradar.com/news/best-wordpress-hosting-providers">best WordPress hosting</a> but what even is WordPress? WordPress is a Content Management System (CMS) that helps people build and manage websites.</p><p>But hat might not necessarily answer your question. How does it do that? What's a CMS? What do I need to know when making a WordPress site? Fear not, all those questions are answered here.</p><div class="product star-deal"><a data-dimension112="51a3eecd-252b-4b19-978a-123cd1b476ba" data-action="Star Deal Block" data-label="Get an additional 10% discount with the code TECHRADAR on all annual plansGet Global Presence for $2.99/mo with Hostinger&rsquo;s Managed WordPress Hosting. Worldwide datacenters and advanced caching technology gives your WordPress site fast load times for users everywhere. Hostinger&rsquo;s managed hosting ensures top-tier performance, SEO-friendly speeds, a Free Domain, Easy Migration and AI Tools to grow your audience.&nbsp; Get an additional 10% discount with the code TECHRADAR on all annual plans" data-dimension48="Get an additional 10% discount with the code TECHRADAR on all annual plansGet Global Presence for $2.99/mo with Hostinger&rsquo;s Managed WordPress Hosting. Worldwide datacenters and advanced caching technology gives your WordPress site fast load times for users everywhere. Hostinger&rsquo;s managed hosting ensures top-tier performance, SEO-friendly speeds, a Free Domain, Easy Migration and AI Tools to grow your audience.&nbsp; Get an additional 10% discount with the code TECHRADAR on all annual plans" href="https://www.hostg.xyz/aff_c?offer_id=61&aff_id=1631&url_id=3744&aff_click_id=trdpro-gb-8537093211052696703" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1381px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="5sS4GYTH3eVRNWh5vM6bBL" name="Screenshot 2025-01-13 131511_cr.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/5sS4GYTH3eVRNWh5vM6bBL.jpg" mos="" align="middle" fullscreen="" width="1381" height="777" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong></strong><a href="https://www.hostg.xyz/aff_c?offer_id=61&aff_id=1631&url_id=3744&aff_click_id=trdpro-gb-8537093211052696703" data-dimension112="51a3eecd-252b-4b19-978a-123cd1b476ba" data-action="Star Deal Block" data-label="Get an additional 10% discount with the code TECHRADAR on all annual plansGet Global Presence for $2.99/mo with Hostinger&rsquo;s Managed WordPress Hosting. Worldwide datacenters and advanced caching technology gives your WordPress site fast load times for users everywhere. Hostinger&rsquo;s managed hosting ensures top-tier performance, SEO-friendly speeds, a Free Domain, Easy Migration and AI Tools to grow your audience.&nbsp; Get an additional 10% discount with the code TECHRADAR on all annual plans" data-dimension48="Get an additional 10% discount with the code TECHRADAR on all annual plansGet Global Presence for $2.99/mo with Hostinger&rsquo;s Managed WordPress Hosting. Worldwide datacenters and advanced caching technology gives your WordPress site fast load times for users everywhere. Hostinger&rsquo;s managed hosting ensures top-tier performance, SEO-friendly speeds, a Free Domain, Easy Migration and AI Tools to grow your audience.&nbsp; Get an additional 10% discount with the code TECHRADAR on all annual plans" data-dimension25=""><strong>Get an additional 10% discount with the code TECHRADAR on all annual plans</strong></a><br><br><strong>Get Global Presence for $2.99/mo with Hostinger’s Managed WordPress Hosting. </strong>Worldwide datacenters and advanced caching technology gives your WordPress site fast load times for users everywhere. Hostinger’s managed hosting ensures top-tier performance, SEO-friendly speeds, a Free Domain, Easy Migration and AI Tools to grow your audience. <a class="view-deal button" href="https://www.hostg.xyz/aff_c?offer_id=61&aff_id=1631&url_id=3744&aff_click_id=trdpro-gb-8537093211052696703" target="_blank" rel="nofollow" data-dimension112="51a3eecd-252b-4b19-978a-123cd1b476ba" data-action="Star Deal Block" data-label="Get an additional 10% discount with the code TECHRADAR on all annual plansGet Global Presence for $2.99/mo with Hostinger&rsquo;s Managed WordPress Hosting. Worldwide datacenters and advanced caching technology gives your WordPress site fast load times for users everywhere. Hostinger&rsquo;s managed hosting ensures top-tier performance, SEO-friendly speeds, a Free Domain, Easy Migration and AI Tools to grow your audience.&nbsp; Get an additional 10% discount with the code TECHRADAR on all annual plans" data-dimension48="Get an additional 10% discount with the code TECHRADAR on all annual plansGet Global Presence for $2.99/mo with Hostinger&rsquo;s Managed WordPress Hosting. Worldwide datacenters and advanced caching technology gives your WordPress site fast load times for users everywhere. Hostinger&rsquo;s managed hosting ensures top-tier performance, SEO-friendly speeds, a Free Domain, Easy Migration and AI Tools to grow your audience.&nbsp; Get an additional 10% discount with the code TECHRADAR on all annual plans" data-dimension25="">View Deal</a></p></div><h2 class="article-body__section" id="section-what-is-wordpress-explained-for-beginners"><span>What Is WordPress? Explained For Beginners</span></h2><p>WordPress is a popular and free content management system with a page builder that lets you build and manage websites with zero coding experience. WordPress powers approximately 40% of all websites on the internet, so you can rest assured that it’s reliable. </p><p>You get various building blocks, like text sections, image galleries, contact forms, and navigation menus, that you can arrange and customize to create your desired website. This simple approach makes website creation easier for people without coding or technical experience. </p><p>To understand it better, think about how you order furniture from IKEA, and when it gets delivered to your home, you read the manual and start assembling it as per the instructions. It’s the same for WordPress. You pick the pieces and assemble, and the final furniture is your website.</p><p><strong>Did you know:</strong> WordPress initially began as a tool to publish blogs, but later evolved to publish other web content too?</p><h2 class="article-body__section" id="section-types-of-websites-you-can-make-with-wordpress"><span>Types Of Websites You Can Make with WordPress</span></h2><p>You can create <em><strong>any type of website with WordPress</strong></em>, right from a personal blog, news, to even fully-fledged eCommerce stores. WordPress gives you 7,500+ themes to choose from with one-click installation and tons of blocks, so the possibility to design a website you desire is infinite. </p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1390px;"><p class="vanilla-image-block" style="padding-top:55.83%;"><img id="ExBVjevp4UYXQMSBRdcJJg" name="WordPress Themes" alt="WordPress Themes" src="https://cdn.mos.cms.futurecdn.net/ExBVjevp4UYXQMSBRdcJJg.png" mos="" align="middle" fullscreen="" width="1390" height="776" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><ul><li><strong>News and Magazine Sites:</strong> Publishing organizations appreciate WordPress's content management capabilities, editorial workflows, and multi-author support systems. You can use its built-in template and edit it to fit your brand guidelines.</li><li><strong>E-commerce Stores:</strong> Through the WooCommerce plugin, WordPress can be turned into a powerful e-commerce platform. You can sell physical products, digital downloads, or services directly through your website, complete with shopping cart functionality and payment processing.</li><li><strong>Personal and Professional Blogs: </strong>WordPress began as a blogging platform and continues to excel in this area. You can create blogs for sharing personal experiences, professional insights, or specialized knowledge in your field of expertise.</li><li><strong>Educational Websites:</strong> Schools, training organizations, and individual educators can create learning platforms using WordPress. These sites can include course materials, student resources, and interactive elements.</li><li><strong>Portfolio Websites:</strong> Creative professionals such as photographers, designers, and artists use WordPress to showcase their work. The platform offers numerous portfolio-focused themes that highlight visual content effectively.</li><li><strong>Business Websites: </strong>Service-based businesses, consultancies, and local companies use WordPress to establish their online presence. These sites typically include service descriptions, team information, testimonials, and contact details.</li></ul><p>The list of websites you can make with WordPress is endless, and we mean it. The templates you get are a starting point, and you can begin customization as per your requirements.</p><h2 class="article-body__section" id="section-wordpress-com-vs-wordpress-org"><span>WordPress.com vs WordPress.org</span></h2><p>If you’re new to the WordPress world, the confusion between <a href="http://wordpress.com/">WordPress.com</a> and <a href="http://wordpress.org/">WordPress.com</a> might make you think they’re the same. </p><p>WordPress is a CMS and is available for free at <a href="http://wordpress.org/">WordPress.org</a>. It is also usually pre-installed or available via a one-click installer on most shared hosting plans, where it is also free. You do not and never will need to pay for WordPress. However, you do need to pay for hosting, and maybe a page builder if you don’t get on with Gutenberg (the WordPress page builder), and may pay for some plugins. </p><p><a href="http://wordpress.com/">WordPress.com</a>, on the other hand,  is a hosting company that is owned by Automattic, the company behind WordPress. An important difference between the two to remember here is that using WordPress does not require WordPress.com. Many web hosting companies offer WordPress installation and support and provide better value and more flexibility than WordPress.com's hosting services.</p><h2 class="article-body__section" id="section-is-wordpress-easy-to-use-for-a-beginner"><span>Is WordPress easy to use for a beginner?</span></h2><p>Yes and no. Some get on with it right away. Others find the page builder hard to use. I personally have found the page builder hard to use, since I came from zero tech experience or knowledge. When I began building my site, I had to go through tons of tutorials, and there was a higher learning curve.</p><p>At the same time, it also depends on the template you use. Everyone’s experience is different with WordPress. For instance, someone with a tech background or a little bit of know-how can pick up WordPress easily with a bit of experimentation here and there. </p><p>So, labelling it easy or difficult would be unfair. More likely, we’d say, it depends on one user to another.  And let’s be real here. Most beginners can create a basic website within a few days to a week of dedicated learning. However, developing proficiency with advanced features typically requires several weeks or months of regular use.</p><p>It’s exactly like you’re building with Lego. Some people are so good and fast at it that it doesn’t take them long. While some people build it, it takes them days to finish it. The same is the case with using WordPress. </p><p>A bonus of WordPress being so popular is that there are tons of tutorials. So if you are struggling, you should be able to find help and figure out how to use WordPress on your own, with plenty of helpful guides out there.</p><figure class="van-image-figure " data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2880px;"><p class="vanilla-image-block" style="padding-top:57.29%;"><img id="TbsYNCuQepMqkkEiNEe4oL" name="WordPress support" alt="WordPress support" src="https://cdn.mos.cms.futurecdn.net/TbsYNCuQepMqkkEiNEe4oL.png" mos="" align="middle" fullscreen="" width="2880" height="1650" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><h2 class="article-body__section" id="section-how-much-is-wordpress"><span>How Much Is WordPress?</span></h2><p>WordPress is free to use. However, running a website does involve some costs, such as: </p><ul><li>Hosting</li><li>A domain</li><li>Plug-ins (optional)</li><li>Page builders (optional)</li></ul><p>Let’s break down this in a more detailed manner below: </p><h2 id="important-mandatory-expenses">Important/Mandatory Expenses</h2><p><strong>Web Hosting: $60-180 annually</strong></p><p>The best web hosting provides the server space where your website files are stored and accessed by visitors. Shared hosting plans typically cost $2-15 monthly, while more robust hosting options range higher. When I was building my site, I went with Hostinger, and it cost me $2.99/month for the Shared Hosting plan. In the initial stage, shared hosting is usually the best and economical option. The best WordPress hosting is often shared hosting with a hosting provider that has dedicated support for WordPress and servers optimized for WordPress too.</p><p><strong>Domain Name: $10-15 annually</strong></p><p>Your domain name serves as your website's address on the internet. This annual fee registers your chosen domain name and maintains your rights to use it. Domain names often come free with your hosting provider for one year but I always recommend shopping around the <a href="https://www.techradar.com/news/best-domain-registrars">best domain name registrars</a> for a better overall deal. </p><h2 id="optional-expenses">Optional Expenses</h2><p><strong>Premium Themes: $30-100 (one-time purchase)</strong></p><p>While free themes are available, premium themes often provide additional customization options, better support, and more sophisticated designs.</p><p><strong>Premium Plugins: $50-200+ annually</strong></p><p>If you want advanced features on your website, you’ll need premium plugins. These might include enhanced security features, advanced SEO tools, or specialized business applications.</p><p><strong>Professional Page Builders: $50-200 annually</strong></p><p>If you find the default WordPress editor challenging, third-party page builders like Elementor or Divi offer more intuitive design interfaces.</p><p><strong>Professional Services: Variable costs</strong></p><p>Some users invest in professional setup, design customization, or ongoing maintenance services. If you choose to opt for that, you can expect additional charges for these, depending on which services you go for. </p><h2 class="article-body__section" id="section-reasons-to-use-wordpress"><span>Reasons to Use WordPress</span></h2><ul><li>Free to use, so you don’t have to ever worry about paying separately</li><li>Can migrate anywhere without losing content or functionality</li><li>Provides excellent support & guidance from the vast global community</li><li>Exceptional scalability so you can scale your website as it grows</li><li>Regular updates for continuous development</li></ul><h3 class="article-body__section" id="section-disadvantages-of-wordpress"><span>Disadvantages of WordPress</span></h3><ul><li>There is an added level of management compared to page builders</li><li>The Gutenberg page builder could be easier to use</li><li>There are currently some legal battles going on that are disrupting the WordPress community</li><li>With thousands of available plugins, compatibility conflicts can occasionally occur</li><li>As a self-hosted solution, you're responsible for implementing security measures</li></ul><h2 class="article-body__section" id="section-final-words"><span>Final Words</span></h2><p>WordPress is a powerful CMS that provides extensive customization and blends affordability and scalability in one. While there is a learning curve, you can use this free CMS to build your website and learn through its strong community support. </p><p><strong>Choose WordPress If You Need: </strong></p><ul><li>A scalable website</li><li>A free CMS</li><li>Complete control over your website's design and functionality</li></ul><p>On the other hand, you might want to consider an alternative if you’re looking for something very easy to use with zero learning curve or minimal technical involvement in website management. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A popular WordPress theme has been hijacked by malware - here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/a-popular-wordpress-theme-has-been-hijacked-by-malware-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Widespread attacks and account takeover attempts observed with the 'Motors' theme, so patch now. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fjBFmKA4pvCbxZ7nt758gC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Jun 2025 15:27:00 +0000</pubDate>                                                                                                                                <updated>Tue, 24 Jun 2025 12:54:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>'Motors' WordPress theme vulnerability leaves accounts open to takeover attacks</strong></li><li><strong>Widespread attacks were observed from June 7 onwards</strong></li><li><strong>A patch is available in version 5.6.68, so update now</strong></li></ul><p>A popular premium <a href="https://www.techradar.com/news/best-wordpress-theme">WordPress theme</a>, has been exploited by hackers thanks to a critical privilege escalation flaw tracked as CVE-2025-4322.</p><p>Attackers are able to exploit the vulnerability in the 'Motors' theme to hijack administrator accounts, taking full control of sites to change details, inject false details and spread malicious payloads.</p><p>Developed by StylemixThemes and a popular pick among automotive websites, nearly 22,500 sales of the theme have been logged on EnvatoMarket.</p><div class="product"><a data-dimension112="d7d497f1-b747-4bd1-8155-4b2795ac5aa9" data-action="Deal Block" data-label="Get Keeper's Personal Password Manager plan  for just $1.67/month" data-dimension48="Get Keeper's Personal Password Manager plan  for just $1.67/month" href="https://www.keepersecurity.com/affiliate/personal-and-business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="XH4p3WteMmXXz9bMtmfxCb" name="keeper_logo_sq.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/XH4p3WteMmXXz9bMtmfxCb.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/affiliate/personal-and-business/" target="_blank" rel="nofollow" data-dimension112="d7d497f1-b747-4bd1-8155-4b2795ac5aa9" data-action="Deal Block" data-label="Get Keeper's Personal Password Manager plan  for just $1.67/month" data-dimension48="Get Keeper's Personal Password Manager plan  for just $1.67/month" data-dimension25=""><strong>Get Keeper's Personal Password Manager plan  for just $1.67/month</strong></a><br>Keeper is a password manager with top-notch security. It's fast, full-featured, and offers a robust web interface. The Personal Plan gets you unlimited password storage across all your devices, auto-login & autofill to save time, secure password sharing with trusted contacts, biometric login & 2FA for added security.<a class="view-deal button" href="https://www.keepersecurity.com/affiliate/personal-and-business/" target="_blank" rel="nofollow" data-dimension112="d7d497f1-b747-4bd1-8155-4b2795ac5aa9" data-action="Deal Block" data-label="Get Keeper's Personal Password Manager plan  for just $1.67/month" data-dimension48="Get Keeper's Personal Password Manager plan  for just $1.67/month" data-dimension25="">View Deal</a></p></div><h2 id="motors-wordpress-theme-has-been-hijacked">'Motors' WordPress theme has been hijacked</h2><p>The vulnerability had first been discovered on May 2, 2025, with a patch later released with version 5.6.68 on May 14, meaning that up-to-date accounts should be protected from potential account takeovers. Versions up to 5.6.67 are affected by the CVE, with Wordfence reporting on the details on May 19.</p><p>"This is due to the theme not properly validating a user's identity prior to updating their password," Wordfence explained. </p><p>"This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account."</p><p>Although the patch has already been released, accounts that are still running older versions are at risk of takeover, with attacks seen to have started on May 20. By June 7, researchers were observing wide-scale attacks – Wordfence has now blocked more than 23,000 attack attempts.</p><p>Wordfence also disclosed a number of key IP addresses seen to be attacking sites – many making thousands of attempts each.</p><p>"One obvious sign of infection is if a site’s administrator is unable to log in with the correct password as it may have been changed as a result of this vulnerability," the researchers explained.</p><p>The biggest change users of the 'Motors' theme can do is to update to version 5.6.68, closing the vulnerability to attackers and securing their accounts from takeovers.</p><p>Via <a href="https://www.bleepingcomputer.com/news/security/wordpress-motors-theme-flaw-mass-exploited-to-hijack-admin-accounts/" target="_blank"><em>BleepingComputer</em></a></p><h3 class="article-body__section" id="section-you-might-also-like"><span>You might also like</span></h3><ul><li>We've listed the <a href="https://www.techradar.com/best/firewall">best firewall software</a></li><li><a href="https://www.techradar.com/pro/security/critical-security-flaw-could-leave-over-100-000-wordpress-sites-at-risk">Critical security flaw could leave over 100,000 WordPress sites at risk</a></li><li>Keep track of your multi-factor authentication codes with the <a href="https://www.techradar.com/best/best-authenticator-apps">best authenticator apps</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>