Slider Revolution v7.1.2 - Responsive WordPress Plugin
Make your WordPress website stand out with Slider Revolutionβs cinematic effects and powerful capabilities. Slider Revolution may be best known as a WordPress slider plugin. But thereβs so much more you can create with this fast, easy to use, and responsive page builder and design tool.
#Plugin
Make your WordPress website stand out with Slider Revolutionβs cinematic effects and powerful capabilities. Slider Revolution may be best known as a WordPress slider plugin. But thereβs so much more you can create with this fast, easy to use, and responsive page builder and design tool.
#Plugin
π4
Advanced Custom Fields Pro v6.8.5
Supercharge your website with powerful functionality! Purchase ACF PRO and unlock the repeater field, flexible content field, gallery field and options page features!
#Plugin
Supercharge your website with powerful functionality! Purchase ACF PRO and unlock the repeater field, flexible content field, gallery field and options page features!
#Plugin
π6
Divi 5.9.0 - The All-New Divi Built From The Ground Up
Divi 5 is a complete, ground-up rewrite of the legendary WordPress page builder by Elegant Themes, trading a decade of technical debt for a lightning-fast, modern architecture. It officially exited its public beta phase in early 2026, marking the most significant evolution in the platform's history.
#Plugin
Divi 5 is a complete, ground-up rewrite of the legendary WordPress page builder by Elegant Themes, trading a decade of technical debt for a lightning-fast, modern architecture. It officially exited its public beta phase in early 2026, marking the most significant evolution in the platform's history.
#Plugin
π3
Recovery guide for sites affected by the WordPress REST Batch API (wp2shell) vulnerability:
The WordPress REST Batch API (wp2shell) vulnerability allowed unauthenticated remote code execution (RCE), enabling attackers to fully compromise websites.
1. Always Backup First: Create a full backup of all files and the database before executing any cleanup steps.
2. Delete Malicious Web Shells: Inspect cache folders (like /wp-content/cache/) via FTP/SSH and delete suspicious PHP files created by the exploit.
3. Remove Rogue Plugins: Check /wp-content/mu-plugins/ and /wp-content/plugins/ to remove persistent backdoor files disguised as security patches (e.g., galex_patch.php).
4. Update Core Immediately: Upgrade WordPress core to patched versions (6.9.5 or 7.0.2) to close the underlying Batch API vulnerability.
5. Disable File Modifications: Block future file edits and plugin installations by adding define( 'DISALLOW_FILE_EDIT', true ); and define( 'DISALLOW_FILE_MODS', true ); to wp-config.php.
6. Reset All Credentials: Change passwords for all users (especially admins) and update the MySQL database user password.
7. Force Global Logout: Invalidate all active sessions and log out potential attackers by replacing the salt keys in wp-config.php using the official WordPress key generator.
Force Global Logout: Invalidate all active sessions and log out potential attackers by replacing the salt keys in wp-config.php using the official WordPress key generator.
8. Audit User Accounts: Inspect the Users section in the WordPress dashboard and delete any unauthorized administrator accounts.
9. Clean the Database: Run SQL queries on wp_posts and wp_postmeta to delete fake changesets, spoofed menu items (often dated 2020-01-01), and malicious example.invalid payload metadata.
10. Revoke Database File Privileges: Prevent database-to-disk file writes by running REVOKE FILE ON *.* FROM 'wp_user_name'@'localhost'; on the MySQL server.
Reddit
The WordPress REST Batch API (wp2shell) vulnerability allowed unauthenticated remote code execution (RCE), enabling attackers to fully compromise websites.
1. Always Backup First: Create a full backup of all files and the database before executing any cleanup steps.
2. Delete Malicious Web Shells: Inspect cache folders (like /wp-content/cache/) via FTP/SSH and delete suspicious PHP files created by the exploit.
3. Remove Rogue Plugins: Check /wp-content/mu-plugins/ and /wp-content/plugins/ to remove persistent backdoor files disguised as security patches (e.g., galex_patch.php).
4. Update Core Immediately: Upgrade WordPress core to patched versions (6.9.5 or 7.0.2) to close the underlying Batch API vulnerability.
5. Disable File Modifications: Block future file edits and plugin installations by adding define( 'DISALLOW_FILE_EDIT', true ); and define( 'DISALLOW_FILE_MODS', true ); to wp-config.php.
6. Reset All Credentials: Change passwords for all users (especially admins) and update the MySQL database user password.
7. Force Global Logout: Invalidate all active sessions and log out potential attackers by replacing the salt keys in wp-config.php using the official WordPress key generator.
Force Global Logout: Invalidate all active sessions and log out potential attackers by replacing the salt keys in wp-config.php using the official WordPress key generator.
8. Audit User Accounts: Inspect the Users section in the WordPress dashboard and delete any unauthorized administrator accounts.
9. Clean the Database: Run SQL queries on wp_posts and wp_postmeta to delete fake changesets, spoofed menu items (often dated 2020-01-01), and malicious example.invalid payload metadata.
10. Revoke Database File Privileges: Prevent database-to-disk file writes by running REVOKE FILE ON *.* FROM 'wp_user_name'@'localhost'; on the MySQL server.
Reddit
[Guide] Complete cleanup and securing of WordPress after REST Batch API (wp2shell) attack
Explore this post and more from the Wordpress community
π6
Elementor Pro v4.1.3 - The Most Advanced Website Builder Plugin
Improve Every Aspect of Your WordPress Design: Live, Easy and Fun. Goodbye backend! Design all your forms live, right from the Elementor editor. Choose your fields, increase spacing, set columns and layout... Control everything, all without ever leaving the editor.
#Plugin
Improve Every Aspect of Your WordPress Design: Live, Easy and Fun. Goodbye backend! Design all your forms live, right from the Elementor editor. Choose your fields, increase spacing, set columns and layout... Control everything, all without ever leaving the editor.
#Plugin
π1
Divi Plus v2.0.1 - 50+ Powerful Modules for Divi Theme
Divi Plus is a premium multipurpose plugin that comes with multiple exceptional modules. Using these unique and powerful modules, youβll be able to create different web page elements that would increase your siteβs functionality as well as appearance.
#Plugin
Divi Plus is a premium multipurpose plugin that comes with multiple exceptional modules. Using these unique and powerful modules, youβll be able to create different web page elements that would increase your siteβs functionality as well as appearance.
#Plugin
π1
Divi Essential v5.6.1 - Divi Extension
This whole set of Essential Modules is an all-in-one solution to web development and these are all you need to design your perfectly well-organized and sleek-looking professional website.
#Plugin
This whole set of Essential Modules is an all-in-one solution to web development and these are all you need to design your perfectly well-organized and sleek-looking professional website.
#Plugin
π2
Divi Supreme Pro v4.9.97.43
Take Divi to the next level. Divi Supreme is a stunning Divi plugin packed with everything you need to build amazing websites with ease.
#Plugin
Take Divi to the next level. Divi Supreme is a stunning Divi plugin packed with everything you need to build amazing websites with ease.
#Plugin
π2