📋 TL;DR WordPress 7.0.3, released on August 6, fixes CVE-2026-64638: a high-severity (CVSS 8.9) cross-site scripting (XSS) flaw on the login screen that needs no authentication to trigger and can be chained into remote code execution. Every WordPress version from...
Under Attack Mode (UAM) is available now in WebShield, the Imunify360 layer that filters traffic in front of your web server. It is a switch you throw when one domain comes under an automated flood. The domain, or just the paths you choose, goes behind a lightweight...
CloudLinux is introducing updates to the pricing model for ImunifyAV+. These changes align ImunifyAV+ with the tiered structure already used by Imunify360 and support continued investment in malware detection, protection technologies, and product development. The...
Imunify360 can now throttle AI crawlers instead of forcing a choice between letting them run unchecked and blocking them outright. AI Bot Management, a new feature delivered through the Imunify Security plugin for WordPress, classifies incoming bot traffic, verifies...
A WordPress security hole doesn’t wait for business hours. When a maximum-severity, no-login-required takeover bug landed in WordPress core, the race was on: the fix was already public, and attackers were reverse-engineering it to find sites that hadn’t...
A single hidden file on one WordPress site can quietly take over an entire server, and the trigger is a command your team might run without thinking. Running WP-CLI as root with –allow-root isn’t standard practice, but as recent telemetry shows, it does...
Recent Comments