<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
        <title>Andris Veliks - WPSec</title>
        <link>http://veliks.mozello.lv/wwww/wpsec-1/</link>
        <description>Andris Veliks - WPSec</description>
                    <item>
                <title>WPSec June 2026 Update: Introducing Attack Surface</title>
                <link>http://veliks.mozello.lv/wwww/wpsec-1/params/post/5266373/wpsec-june-2026-update-introducing-attack-surface</link>
                <pubDate>Fri, 12 Jun 2026 19:38:00 +0000</pubDate>
                <description>&lt;div style=&quot;font-weight: 400; font-style: normal;&quot; class=&quot;moze-start&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot;&gt;&lt;table role=&quot;presentation&quot; class=&quot;m_8437754732885314590body-wrap&quot; width=&quot;100%&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td align=&quot;center&quot;&gt;&lt;table role=&quot;presentation&quot; class=&quot;m_8437754732885314590container&quot; width=&quot;600&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590header-td&quot; style=&quot;text-align: center&quot;&gt;&lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/P2iTQOOjHJ763CFRtTUco1763w/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/P2iTQOOjHJ763CFRtTUco1763w/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw1yiO2OBcrZhkrKZZJSmxrL&quot;&gt;&lt;img src=&quot;https://ci3.googleusercontent.com/meips/ADKq_NZjYpchE9svUQAon5qR4XHWVxykezhehVovUmeMuGGHlSStKmORZ5-S5m4u-DACM3qvCtEXe5I6FpLrzmEg=s0-d-e1-ft#https://wpsec.com/images/wpsec_white.png&quot; alt=&quot;WPSec&quot; width=&quot;180&quot; style=&quot;text-decoration: none; width: 180px; height: auto&quot;&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590hero-td&quot; style=&quot;text-align: center&quot;&gt;&lt;b&gt;&lt;h1 class=&quot;m_8437754732885314590hero-title&quot; style=&quot;font-weight: 700&quot;&gt;June 2026 Update&lt;/h1&gt;&lt;/b&gt;&lt;p class=&quot;m_8437754732885314590hero-sub&quot;&gt;Introducing Attack Surface — see where your sites are exposed&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590content-td&quot;&gt;&lt;p class=&quot;m_8437754732885314590section-body&quot;&gt;Hi Andris Veliks,&lt;/p&gt;&lt;p class=&quot;m_8437754732885314590section-body&quot;&gt;This month we’re launching the biggest addition to WPSec in a while: &lt;strong&gt;Attack Surface&lt;/strong&gt; — a per-plugin security risk analysis for every WordPress site you scan. Plugins are where most WordPress sites get compromised, and Attack Surface gives you the clearest picture yet of where yours are exposed.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590content-td&quot;&gt;&lt;table role=&quot;presentation&quot; width=&quot;100%&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table role=&quot;presentation&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center&quot;&gt;&lt;img data-emoji=&quot;🎯&quot; class=&quot;an1&quot; alt=&quot;🎯&quot; aria-label=&quot;🎯&quot; draggable=&quot;false&quot; src=&quot;https://fonts.gstatic.com/s/e/notoemoji/17.0/1f3af/32.png&quot; loading=&quot;lazy&quot; style=&quot;text-decoration: none; width: 1.2em; height: auto&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;&lt;h2 class=&quot;m_8437754732885314590section-title&quot; style=&quot;font-weight: 700&quot;&gt;Introducing Attack Surface&lt;/h2&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p class=&quot;m_8437754732885314590section-body&quot;&gt;Every plugin you install adds code that can be attacked. Attack Surface analyzes every plugin WPSec detects across your sites and rates each one — so you can see your real exposure at a glance.&lt;/p&gt;&lt;div class=&quot;m_8437754732885314590section-body&quot;&gt;&lt;ul&gt;&lt;li&gt;A risk level for every plugin — Critical, High, Medium, Low, or Minimal&lt;/li&gt;&lt;li&gt;A 0–100 risk score, so you can compare plugins directly&lt;/li&gt;&lt;li&gt;Outdated plugins flagged with exactly how many releases behind they are&lt;/li&gt;&lt;li&gt;Plugins removed from WordPress.org flagged automatically — a common warning sign&lt;/li&gt;&lt;li&gt;Every site on your account, in one place&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;table role=&quot;presentation&quot; width=&quot;100%&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/5OzJ0AE892AX2QpDstyS2Lhg/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/5OzJ0AE892AX2QpDstyS2Lhg/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw2O2iOeeuBFNsLsqSrt39dx&quot;&gt;&lt;img src=&quot;https://ci3.googleusercontent.com/meips/ADKq_NYprxxWQHRhvcxxnWD-VSP-o00Z-L9JI1aSKg2iZpJrt8wN98OYC0ZGugrEwR3YYKQp_WiGAfwhezqnp9dFEZaMsT8mswE0nO5TG5VTKv5ZHjwe=s0-d-e1-ft#https://wpsec.com/images/newsletter/attacksurface-2026-06.png&quot; alt=&quot;Attack Surface dashboard showing per-plugin risk levels and scores&quot; width=&quot;520&quot; style=&quot;text-decoration: none; width: 520px; height: auto&quot;&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table role=&quot;presentation&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590btn-td&quot;&gt;&lt;a class=&quot;m_8437754732885314590btn&quot; href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/5OzJ0AE892AX2QpDstyS2Lhg/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/5OzJ0AE892AX2QpDstyS2Lhg/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw2O2iOeeuBFNsLsqSrt39dx&quot; style=&quot;text-decoration: none; font-weight: 600&quot;&gt;Open Attack Surface&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;hr style=&quot;border-width: 1px medium medium; border-style: solid none none; border-color: rgb(229, 234, 240) currentcolor currentcolor; border-image: initial; margin: 0px;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590content-td&quot;&gt;&lt;table role=&quot;presentation&quot; width=&quot;100%&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table role=&quot;presentation&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center&quot;&gt;&lt;img data-emoji=&quot;📊&quot; class=&quot;an1&quot; alt=&quot;📊&quot; aria-label=&quot;📊&quot; draggable=&quot;false&quot; src=&quot;https://fonts.gstatic.com/s/e/notoemoji/17.0/1f4ca/32.png&quot; loading=&quot;lazy&quot; style=&quot;text-decoration: none; width: 1.2em; height: auto&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;&lt;h2 class=&quot;m_8437754732885314590section-title&quot; style=&quot;font-weight: 700&quot;&gt;See exactly what’s exposed&lt;/h2&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p class=&quot;m_8437754732885314590section-body&quot;&gt;For every plugin, Attack Surface breaks down what actually makes up its attack surface:&lt;/p&gt;&lt;div class=&quot;m_8437754732885314590section-body&quot;&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;REST API endpoints&lt;/strong&gt; the plugin registers — each one is a way in&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Input parameters&lt;/strong&gt; it accepts — every one is a potential injection point&lt;/li&gt;&lt;li&gt;&lt;strong&gt;File upload points&lt;/strong&gt; — among the highest-risk vectors on any site&lt;/li&gt;&lt;li&gt;&lt;strong&gt;WordPress hooks&lt;/strong&gt; that handle user input, such as AJAX handlers&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Security issues&lt;/strong&gt; surfaced by static analysis, mapped to their OWASP category&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;hr style=&quot;border-width: 1px medium medium; border-style: solid none none; border-color: rgb(229, 234, 240) currentcolor currentcolor; border-image: initial; margin: 0px;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590content-td&quot;&gt;&lt;table role=&quot;presentation&quot; width=&quot;100%&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table role=&quot;presentation&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center&quot;&gt;&lt;img data-emoji=&quot;🔍&quot; class=&quot;an1&quot; alt=&quot;🔍&quot; aria-label=&quot;🔍&quot; draggable=&quot;false&quot; src=&quot;https://fonts.gstatic.com/s/e/notoemoji/17.0/1f50d/32.png&quot; loading=&quot;lazy&quot; style=&quot;text-decoration: none; width: 1.2em; height: auto&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;&lt;h2 class=&quot;m_8437754732885314590section-title&quot; style=&quot;font-weight: 700&quot;&gt;Two views, built for fixing things&lt;/h2&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p class=&quot;m_8437754732885314590section-body&quot;&gt;Look at your plugins whichever way helps you act:&lt;/p&gt;&lt;div class=&quot;m_8437754732885314590section-body&quot;&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;By Website&lt;/strong&gt; — the full risk profile of a single site&lt;/li&gt;&lt;li&gt;&lt;strong&gt;By Severity&lt;/strong&gt; — every plugin across all your sites, ranked worst-first, so you tackle the most dangerous things first&lt;/li&gt;&lt;li&gt;Hide plugins whose risk you’ve accepted, report false positives, or manually add plugins a scan didn’t catch&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;hr style=&quot;border-width: 1px medium medium; border-style: solid none none; border-color: rgb(229, 234, 240) currentcolor currentcolor; border-image: initial; margin: 0px;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590content-td&quot;&gt;&lt;table role=&quot;presentation&quot; width=&quot;100%&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table role=&quot;presentation&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center&quot;&gt;&lt;img data-emoji=&quot;📄&quot; class=&quot;an1&quot; alt=&quot;📄&quot; aria-label=&quot;📄&quot; draggable=&quot;false&quot; src=&quot;https://fonts.gstatic.com/s/e/notoemoji/17.0/1f4c4/32.png&quot; loading=&quot;lazy&quot; style=&quot;text-decoration: none; width: 1.2em; height: auto&quot;&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;&lt;h2 class=&quot;m_8437754732885314590section-title&quot; style=&quot;font-weight: 700&quot;&gt;Share it as a PDF&lt;/h2&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p class=&quot;m_8437754732885314590section-body&quot;&gt;Need to hand the findings to a client or a colleague? Download a complete Attack Surface report as a PDF — a clean summary of every site and every plugin, ready to send or file.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center&quot;&gt;&lt;hr style=&quot;border-width: 1px medium medium; border-style: solid none none; border-color: rgb(229, 234, 240) currentcolor currentcolor; border-image: initial; margin: 0px 0px 28px;&quot;&gt;&lt;p&gt;Attack Surface is part of WPSec Premium. Log in to open it from your dashboard.&lt;/p&gt;&lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/5OzJ0AE892AX2QpDstyS2Lhg/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/5OzJ0AE892AX2QpDstyS2Lhg/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw2O2iOeeuBFNsLsqSrt39dx&quot; style=&quot;text-decoration: none; font-weight: 600&quot;&gt;Open Attack Surface&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;m_8437754732885314590footer-td&quot; style=&quot;text-align: center&quot;&gt;&lt;p&gt;&lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/uYdymyM8R86opfeSZYmVPw/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/uYdymyM8R86opfeSZYmVPw/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw1x0EkdMdw8a4V1UgAPeAzM&quot; style=&quot;text-decoration: none&quot;&gt;X&lt;/a&gt; · &lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/cinsufYw1RHboR4sIo3c6A/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/cinsufYw1RHboR4sIo3c6A/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw1tA92kn7eLejY0Xd9gQr2_&quot; style=&quot;text-decoration: none&quot;&gt;LinkedIn&lt;/a&gt; · &lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/cqW53pUfY9POsemMNfQzSA/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/cqW53pUfY9POsemMNfQzSA/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw04NcfcjpIwhUC59p0ZO3wT&quot; style=&quot;text-decoration: none&quot;&gt;Instagram&lt;/a&gt; · &lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/2CWeL763UB6auuy9eHJZEgOw/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/2CWeL763UB6auuy9eHJZEgOw/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw0KwjPMAoNUAuLY7suxGaFD&quot; style=&quot;text-decoration: none&quot;&gt;Facebook&lt;/a&gt;&lt;/p&gt;&lt;p&gt;WPSec - WordPress Security Scanning&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://list.wpsec.com/unsubscribe/djN3xwDguKXX5riBD48j1yNow2AXjRunXgEAgG63yyU/jG6UCOd7rlzK0Krq5emSnQ/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/unsubscribe/djN3xwDguKXX5riBD48j1yNow2AXjRunXgEAgG63yyU/jG6UCOd7rlzK0Krq5emSnQ/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw2696QW_4Otvn1MwnE-_xNH&quot; style=&quot;text-decoration: underline&quot;&gt;Unsubscribe&lt;/a&gt; · &lt;a href=&quot;https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/SKEqEFOES892aolsabIOp8ew/nPAPGDZ892SW6ZnFYJxZp08A&quot; target=&quot;_blank&quot; data-saferedirecturl=&quot;https://www.google.com/url?q=https://list.wpsec.com/l/6w67634iw3XVouXbQF763zwnkQ/SKEqEFOES892aolsabIOp8ew/nPAPGDZ892SW6ZnFYJxZp08A&amp;amp;source=gmail&amp;amp;ust=1781377289994000&amp;amp;usg=AOvVaw1-k0KaEd3q6s3Qgw4Mroo7&quot; style=&quot;text-decoration: underline&quot;&gt;Privacy Policy&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;img src=&quot;https://ci3.googleusercontent.com/meips/ADKq_Na5ad5rKlMdLUQkpamCpYvKESC4bo8R30Cr71ulf1fdi1pUwMy_ddDN26M85jP_XrVmoddcJjWesmV2f83GvxJ7OUMKnyzB8goMhqKSqj-DqD4NCFGquVwXTuZpKxugm02_=s0-d-e1-ft#https://list.wpsec.com/t/nPAPGDZ892SW6ZnFYJxZp08A/6w67634iw3XVouXbQF763zwnkQ&quot; alt=&quot;&quot; style=&quot;text-align: start; text-decoration: none; font-weight: 400; font-style: normal; width: 1px; height: 1px&quot;&gt;</description>
            </item>
                    <item>
                <title>WPSEC</title>
                <link>http://veliks.mozello.lv/wwww/wpsec-1/params/post/5266367/wpsec</link>
                <pubDate>Fri, 12 Jun 2026 19:36:00 +0000</pubDate>
                <description>&lt;img src=&quot;https://site-92547.mozfiles.com/files/92547/base64img_8f2028bc561ee4daf42b2c7333b59d4d.png&quot; alt=&quot;Online WordPress Security Scanner for Vulnerabilities | WPSec.com&quot; class=&quot;&quot; style=&quot;&quot;&gt;</description>
            </item>
            </channel>
</rss>