THEVOS
Rekomendasi Keamanan

The plugins you installed to stay safe are the ones opening the door — backup and anti-spam plugins hit in the same week (late July 2026)

Oleh THEVOS 編集部· 2026-08-02 ·4 menit baca ·28
The plugins you installed to stay safe are the ones opening the door — backup and anti-spam plugins hit in the same week (late July 2026)

Our previous article covered wp2shell, the unauthenticated remote code execution chain in WordPress core. That event was large enough to overshadow something else that was quietly piling up at the same time: plugin vulnerabilities.

In the single week of 23–29 July 2026, 26 were reported — and that is after filtering for "100,000+ installations and Japanese language support". Reading through the list, one thing stands out.

1. The things installed for protection break first

Among the high-severity entries that week:

  • BackWPup (backup) — CVSS 7.2, stored cross-site scripting. Fixed in 5.7.5
  • CleanTalk Anti-Spam (spam and bot protection) — CVSS 7.2, stored cross-site scripting. Fixed in 6.83

Both are plugins you install to protect a site. Backup so you can roll back after an incident; anti-spam so bad requests never land. Both received vulnerability reports in the same week.

In both cases an unauthenticated attacker could plant arbitrary script into a page. That script then runs in the browser of whoever opens the page — and if an administrator opens it, it runs with administrator privileges.

2. Money is not exempt either

The most directly damaging item that week involved payments.

  • Payment Plugins for Stripe WooCommerce — where the webhook signature is not configured, an authorisation bypass allows an unauthenticated attacker to mark arbitrary orders as paid. Two separate issues were reported in this one plugin

This is the kind you discover after the goods have shipped. A single missing setting — the webhook signature — and payment appears to have gone through.

3. Sometimes one plugin produces three

Kirki, a theme customiser framework, accounted for three reports in that week alone. One of them allowed an unauthenticated reader to retrieve the full content of private and draft posts via the context parameter.

An unpublished announcement, a price list still being prepared, an internal memo left as a draft — all readable.

4. Other names you will recognise

  • GTM4WP (Google Tag Manager) — CVSS 7.2, script injection through WooCommerce billing fields
  • Fluent Forms and Ninja Forms (contact forms)
  • GiveWP (donations) — CVSS 7.2, two issues
  • Yoast SEO and All in One SEO
  • Polylang (multilingual) and MailPoet (email)
  • The Events Calendar, WP Go Maps, Tutor LMS, Advanced Ads, WP Activity Log and others

An SEO plugin, a multilingual plugin, a form plugin, a map plugin — roughly the set that ends up on any ordinary business website.

5. What the list is really saying

It is not that these plugins are bad. Most are long-running, well-maintained and popular, and fixes appeared within days.

What the list shows is structure.

A plugin is not a feature you added. It is surface area you gained.

Every plugin brings another company's code onto your site. You do not control its quality, the speed of its fixes, or whether its author will still be maintaining it next year.

A site running twenty plugins is a site hoping that twenty separate development teams each avoid a mistake. That is how a backup plugin ends up being the vulnerable one.

6. What to do about it

  • Delete plugins you do not use. Deactivating leaves the files on the server, vulnerable code included
  • Check for overlap. Two form plugins, or two SEO plugins, is a common sight
  • For payment, membership and personal-data plugins, review the configuration too. The Stripe case above was triggered by a missing setting, not by faulty code
  • Review vulnerability listings weekly. Filtered feeds by installation count and language make it practical to see only what applies to you

A note on how we work

This is why THEVOS built and uses its own CMS, VosCMS. Features are built as in-house modules inside the core rather than bolted on as third-party plugins, so when something needs fixing we do not wait for someone else's release.

WordPress can absolutely be run safely. Doing so, however, requires someone who reviews the list every week, decides, and updates. That is rarely something a business owner can take on personally. Our next article looks at the numbers that appear when nobody is doing it.

Sources — weekly summary based on Wordfence data (23–29 July 2026, published 31 July 2026); IPA advisory (22 July 2026)

Bagikan LINE X Facebook

Komentar (0)

Belum ada komentar. Jadilah yang pertama berkomentar.

Artikel terkait

THEVOS
Beranda Beranda Layanan Pembuatan Situs Web Web Hosting Layanan Email Layanan Domain Solusi Solusi VosCMS Layanan TMS AI Hanes Solusi Reservasi Solusi Pencocokan Bisnis Malam Komunitas Pengumuman Forum Bebas Tanya Jawab FAQ Galeri Blog Kontak Kami
Masuk Daftar