WordPress 7.1.2 Fixes a Critical Flaw Attackers Are Already Using
A core WordPress bug let attackers load PHP files without logging in. Attacks began within hours of the fix, and CISA now lists it as exploited.
Web hosting, domains, email and websites for local business
Author
A core WordPress bug let attackers load PHP files without logging in. Attacks began within hours of the fix, and CISA now lists it as exploited.
The update applies to all languages and may take up to two weeks. Here is how to tell if your site was hit, and what not to panic about.
A Financial Times report says Gen Digital made an early approach to buy GoDaddy. Neither company has confirmed it, and nothing changes for customers yet.
A researcher found that Cloudflare Containers could hand one customer old disk data left by another. Cloudflare fixed it the same day and says no action is needed.
New Workspace admins can pull past email from any IMAP provider while they set up. It covers one user, which fits a lot of small businesses.
Some US Shopify sellers learned by email that buyers can now check out inside Google AI Mode and Gemini. Here is what it changes and how to turn it off.
The 2026 round of new top level domains moves forward, and the full list of requested endings should be public by October 14.
The new Chrome release patches 108 security bugs, 11 of them rated critical. Restart your browsers, and give your website a quick test.
Squarespace's September update rebuilds its Blueprint AI site maker, adds an AI image tool and brings text message marketing into the platform.
Google's automation tool for Workspace can now react to events in other apps, call webhooks and connect to eight outside services in beta.
Wordfence says it blocked more than 440,000 attempts to abuse file upload bugs in Super Forms and Elementor Pro. Both have fixes.
Verisign is ending names like john.smith.name and the email forwarding that came with them. The cutoff is February 2027, even for names paid past it.
A flaw in All-in-One WP Migration and Backup could be set off when an owner restores a backup. Version 7.110 fixes it.