DEV Community

WordPress

the world’s most popular website builder

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Review: Ally WordPress Plugin Unauthenticated SQL Injection (400k+ Sites) and a Repeatable Response Playbook for WordPress Teams

Review: Ally WordPress Plugin Unauthenticated SQL Injection (400k+ Sites) and a Repeatable Response Playbook for WordPress Teams

Comments
4 min read
SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

SA-CONTRIB-2026-018: SAML SSO Reflected XSS — Script Injection on Your Login Page

Comments
3 min read
SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

SA-CONTRIB-2026-017: Drupal Canvas SSRF + Info Disclosure — The Hidden Submodule Problem

Comments
3 min read
SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

SA-CONTRIB-2026-016: Islandora Arbitrary File Upload + XSS — A Dangerous Chain

Comments
3 min read
SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

SA-CONTRIB-2026-015: CAPTCHA Access Bypass — Token Reuse That Breaks Your Spam Gate

Comments
3 min read
SA-CONTRIB-2026-019: Responsive Favicons Persistent XSS — Admin Config as Attack Surface

SA-CONTRIB-2026-019: Responsive Favicons Persistent XSS — Admin Config as Attack Surface

Comments
3 min read
SA-CONTRIB-2026-012: Theme Negotiation by Rules CSRF — GET Requests That Mutate State

SA-CONTRIB-2026-012: Theme Negotiation by Rules CSRF — GET Requests That Mutate State

Comments
4 min read
AI Didn’t Replace Web Developers — It Made Good Ones Stronger

AI Didn’t Replace Web Developers — It Made Good Ones Stronger

Comments
3 min read
What I Learned About Enterprise WordPress Security

What I Learned About Enterprise WordPress Security

1
Comments 1
3 min read
Review: Real-Time Collaboration in the WordPress Block Editor and What Changes for Plugin and Block Developers

Review: Real-Time Collaboration in the WordPress Block Editor and What Changes for Plugin and Block Developers

Comments
4 min read
Drupal SA-CONTRIB-2026-011 through 019: Full Triage Map and Impact Assessment

Drupal SA-CONTRIB-2026-011 through 019: Full Triage Map and Impact Assessment

Comments
4 min read
I Tested 5 WooCommerce AI Search Plugins So You Don't Have To

I Tested 5 WooCommerce AI Search Plugins So You Don't Have To

1
Comments
4 min read
assertEqualHTML() in WordPress: Kill Your Brittle HTML Tests

assertEqualHTML() in WordPress: Kill Your Brittle HTML Tests

Comments
4 min read
I Built a WordPress Plugin That Calculates Snow Loads Per DIN EN 1991-1-3 – Using OpenRouteService for Elevation Data

I Built a WordPress Plugin That Calculates Snow Loads Per DIN EN 1991-1-3 – Using OpenRouteService for Elevation Data

Comments
5 min read
Deep Dive: Ensuring WordPress Plugin Quality with Plugin Check (PCP)

Deep Dive: Ensuring WordPress Plugin Quality with Plugin Check (PCP)

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.