WORDPRESS SECURITY

5 WordPress Security Steps To Take Right Now

600,000+ sites are exposed after September 2026's critical plugin flaws.

STEP 1

Update Every Event Or Calendar Plugin Today

Two critical bugs in The Events Calendar hit versions up to 6.17.4 — update to 6.17.4.1 or later now.

STEP 2

Turn Off Comments On Event Pages

Both flaws trigger through unauthenticated comments, so disabling them blocks the attack path instantly.

STEP 3

Audit Every Plugin For New CVEs

Check each active plugin's changelog this week — attackers scan for unpatched CVSS 9.8 bugs within days.

STEP 4

Turn On A Web Application Firewall

Wordfence and most host firewalls already block known exploit patterns for these flaws — enable one.

STEP 5

Check For Signs Of Compromise

Look for unfamiliar admin users, unknown files, or spam pages — the tell-tale signs of a takeover.