<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Segurium Blog</title><description>Segurium&apos;s writing on WordPress malware patterns, cleanup playbooks, and engineering deep-dives.</description><link>https://segurium.com/</link><language>en-us</language><item><title>Events Manager takeover and four other critical plugin patches</title><link>https://segurium.com/blog/2026-08-13-events-manager-takeover-and-four-other-critical-plugin-patches/</link><guid isPermaLink="true">https://segurium.com/blog/2026-08-13-events-manager-takeover-and-four-other-critical-plugin-patches/</guid><description>A capability-mapping bug in Events Manager lets an unauthenticated visitor take over any admin account whose user ID matches one of the plugin&apos;s records, and four other WordPress plugins shipped critical fixes for RCE and payment-bypass holes.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>plugin</category><category>cve</category><author>press@segurium.com (Segurium)</author></item><item><title>A WordPress core RCE hiding inside a PNG upload</title><link>https://segurium.com/blog/2026-08-12-a-wordpress-core-rce-hiding-inside-a-png-upload/</link><guid isPermaLink="true">https://segurium.com/blog/2026-08-12-a-wordpress-core-rce-hiding-inside-a-png-upload/</guid><description>WordPress 7.0.4 patches an author-level Imagick RCE that smuggles its payload inside a PNG, and five plugin criticals land on NVD — most of them pre-auth.</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>plugin</category><category>cve</category><author>press@segurium.com (Segurium)</author></item><item><title>BdThemes ecosystem hit by a poisoned API response</title><link>https://segurium.com/blog/2026-08-09-bdthemes-ecosystem-hit-by-a-poisoned-api-response/</link><guid isPermaLink="true">https://segurium.com/blog/2026-08-09-bdthemes-ecosystem-hit-by-a-poisoned-api-response/</guid><description>A supply-chain compromise in the BdThemes plugin ecosystem is pushing malicious payloads through a poisoned update API response, reaching sites that never installed anything new.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>plugin</category><category>supply-chain</category><category>malware</category><author>press@segurium.com (Segurium)</author></item><item><title>A login-screen XSS in WordPress 7.0.3 and a plugin backdoor</title><link>https://segurium.com/blog/2026-08-08-a-login-screen-xss-in-wordpress-7-0-3-and-a-plugin-backdoor/</link><guid isPermaLink="true">https://segurium.com/blog/2026-08-08-a-login-screen-xss-in-wordpress-7-0-3-and-a-plugin-backdoor/</guid><description>WordPress 7.0.3 fixes a pre-authentication reflected XSS on the login screen. A hardcoded backdoor shipped in one Advanced Responsive Video Embedder release, and The Events Calendar patched an author-level file read.</description><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>cve</category><category>plugin</category><category>exploit</category><author>press@segurium.com (Segurium)</author></item><item><title>Segurium 1.0.0 is on WordPress.org</title><link>https://segurium.com/blog/2026-08-05-segurium-1-0-0-on-wordpress-org/</link><guid isPermaLink="true">https://segurium.com/blog/2026-08-05-segurium-1-0-0-on-wordpress-org/</guid><description>Segurium is live on the official WordPress.org plugin directory: malware detection, precise cleanup, and hardening for WordPress. Free to install — search for Segurium under Plugins → Add New. Requires WordPress 6.2+ and PHP 7.4+.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><category>release</category><category>plugin</category><author>press@segurium.com (Segurium)</author></item><item><title>Segurium 0.1.3 is available for direct download</title><link>https://segurium.com/blog/2026-05-28-segurium-0-1-3-direct-download/</link><guid isPermaLink="true">https://segurium.com/blog/2026-05-28-segurium-0-1-3-direct-download/</guid><description>Historical note: early Segurium builds were hosted on segurium.com while the WordPress.org review was in progress. The plugin is now live in the official directory — install it from wordpress.org/plugins/segurium.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>release</category><category>plugin</category><author>press@segurium.com (Segurium)</author></item><item><title>Looking for 100 WordPress admins to test Segurium — 1 year of Pro on us</title><link>https://segurium.com/blog/tester-program-100-pro-licenses/</link><guid isPermaLink="true">https://segurium.com/blog/tester-program-100-pro-licenses/</guid><description>We are opening a small tester program for Segurium. 100 WordPress admins get a 1-year Pro license in exchange for real-world feedback from staging or low-risk production sites.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>tester-program</category><author>press@segurium.com (Segurium)</author></item><item><title>Cleanup without breaking your site</title><link>https://segurium.com/blog/cleanup-without-breaking-your-site/</link><guid isPermaLink="true">https://segurium.com/blog/cleanup-without-breaking-your-site/</guid><description>How Segurium restores tampered WordPress core, plugin, and theme files to canonical upstream content — and why most cleanups don&apos;t have to be wipe-and-pray.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><category>product</category><category>cleanup</category><author>press@segurium.com (Segurium)</author></item></channel></rss>