
Work Here?
Patchstack provides an application security platform with threat intelligence, live protection, and patch management for websites built on content management systems. It continuously monitors CMS-based sites, blocks threats in real time, and automatically patches plugins and core CMS software. Agencies and developers can monitor multiple client sites from a single dashboard, receiving alerts and actionable insights. The goal is to prevent mass-hacking and vandalism by keeping CMS-powered websites up to date and protected.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series A
Total Funding
$6.9M
Headquarters
Pärnu linn, Estonia
Founded
2017
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$6.9M
Below
Industry Average
Funded Over
2 Rounds
Industry standards
Stock Options
Remote Work Options
Paid Vacation
Paid Holidays
Home Office Stipend
GiveWP needs an urgent update, plus 4 tech stories. August 29, 2026 A WordPress donation plugin used on more than 100,000 sites has a CVSS 10.0 vulnerability that can end in remote code execution, and the patch has already produced a wonderfully awkward second problem: an official support reply is telling some users to roll back because of a display bug. Please don't do that. Today's lead is less about the number 10.0 than about what version you should actually be running. GiveWP 4.16.7.2 fixes a critical takeover chain - and you should stay on it. Patchstack disclosed CVE-2026-82222 on Friday, a critical vulnerability in the GiveWP donation plugin for WordPress. On the versions where the full chain is reachable, an attacker does not need an account. A published donation form and an active payment gateway can be enough to get attacker-controlled data into the donation flow, abuse unsafe PHP object deserialization, and eventually execute code on the web server. That last phrase is the important one. Remote code execution means this can move beyond "the donation form acts weird" into somebody running commands in the context of the website. Patchstack says GiveWP 4.16.7.2, released August 27, breaks the exploit chain at several layers. If you run GiveWP, update to 4.16.7.2 now, take a current backup first, and then verify donations, receipts, recurring gifts, and any custom integrations afterward. There is a wrinkle. A GiveWP support reply on WordPress.org says 4.16.7.2 introduced a bug that can hide donor names in the Donor Wall and recommends rolling back to 4.16.7.1 until that display problem is fixed. I would not follow that recommendation on an internet-facing production site. Version 4.16.7.1 is specifically inside the vulnerable range Patchstack just told the world about. A broken donor-name display is annoying. Deliberately reinstalling a version with a public unauthenticated RCE chain is a different class of problem entirely. Keep the security update, accept the display bug if you hit it, and watch for the next maintenance release. This is also a good reminder that "latest version" is not the same thing as "everything is perfect." Sometimes the safest version has a regression. That's why backups, staging, monitoring, and post-update testing all exist. The goal is not zero bugs. The goal is to avoid solving the smaller bug by reopening the much larger hole. Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance - plus the assorted weirdness that accumulates on a site over time. The U.S. government corrected a much scarier hacking claim. The Justice Department has corrected its description of a Chinese state-sponsored hacking campaign after its original August 26 announcement made it sound as though every named federal agency had been breached. They hadn't. DOJ's updated release now says NASA, the Federal Reserve, the Senate, the Departments of Energy, Justice, and Health and Human Services, and the National Institutes of Health were among the group's targets. Reuters, after comparing the corrected release with the FBI affidavit, reports that confirmed intrusions included three Energy Department national laboratories, NIH, an HHS agency, and a U.S. security-device manufacturer in September 2024. An attempted NASA intrusion failed. Why did NASA's attempt fail? According to the affidavit, NASA had patched the software the attackers were trying to exploit. That is almost comically boring cybersecurity advice, which is why it's useful. The difference between "NASA was targeted" and "NASA was hacked" is not semantic hair-splitting; one describes an attacker trying the door, the other says the attacker got inside. And in this case, basic patching appears to have helped keep that door shut. DOJ added a note on August 28 saying it edited the release so it accurately reflects the allegations in the affidavit. Technical discovery & auditing. The public page doesn't tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve. Google Drive can now use Gemini to classify sensitive files. Google has opened a beta for Gemini-based data classification in Google Drive. An administrator can describe the kinds of information that belong under a classification label, and Gemini can apply those labels across Drive instead of requiring somebody to manually build a training set first. The labels can then feed data-loss-prevention rules, retention policies, and audit investigations. Google is also explicitly pitching this as an agent-security control: if a company knows which files contain sensitive information, it can make better decisions about what an automated agent is allowed to read or act on. This is an open beta, not a magic compliance button. Somebody still has to define sensible labels, test the results, and decide what those labels actually restrict. It's also limited to Enterprise Plus, Google AI Pro for Education, and Frontline Plus. But the direction is right. "The AI should know not to touch confidential stuff" is not an access-control policy. Classification gives you something concrete to attach the policy to. OpenAI plans to remove its models from Cursor in November. Yes, Cursor is back in the brief one day after yesterday's ransomware story, but for a completely different reason. OpenAI says it intends to end its model-supply agreement with Cursor after SpaceX acquired the coding-tool company. The proposed shutoff date is November 12. OpenAI says it no longer trusts SpaceX to comply with its contractual terms, citing previous disputes with Elon Musk's companies. Cursor says it is talking with OpenAI, so the date is not yet necessarily final. For developers who specifically depend on OpenAI models inside Cursor, there is at least a migration path: OpenAI says users can bring their own API key, use the Codex IDE extension inside Cursor, or connect through a compatible gateway such as Azure or Amazon Bedrock. That makes this less of a "your editor stops working in November" story and more of a reminder about platform dependencies. If one model is important to your workflow, know whether you're buying access from the model provider or borrowing it through somebody else's contract. Those are not the same dependency. Business IT goes well beyond the website. Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between. The 2026-27 COVID vaccines are cleared for the fall season. The FDA approved updated 2026-27 formulas from Moderna, Pfizer-BioNTech, and Novavax-Sanofi on August 27. The shots target the XFG variant, following the recommendation of the FDA's vaccine advisory committee earlier this year. The approval is narrower than the old "everyone six months and up" language people may remember. Current FDA product labels approve the vaccines for adults 65 and older and for younger people with at least one underlying condition that raises their risk of severe COVID; the minimum age varies by product. Spikevax goes down to 6 months, Comirnaty to age 5, and mNEXSPIKE and Nuvaxovid to age 12. This is product approval, not individualized medical advice and not the same thing as a CDC recommendation for every person. The practical news is that manufacturers now have the regulatory clearance needed for the updated fall supply. If you're deciding whether the 2026-27 shot makes sense for you or your family, use the current CDC guidance and your own healthcare provider rather than a headline about what FDA approved. There's a theme running through this morning's stories that I like because none of it requires pretending technology is magic. A WordPress patch can fix a catastrophic vulnerability and still break a widget. Patching ordinary software can stop a nation-state intrusion. AI can help classify sensitive files, but somebody still needs to write the access rules. A coding tool can keep working even when two vendors decide they can't stand each other anymore, provided you understand the dependency. And a vaccine formula can be technologically updated without turning an FDA approval into a blanket recommendation for everybody. The details are usually where the useful story is hiding. Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life - without requiring a computer-science degree to get through it.
Critical WordPress vulnerability (CVSS 9.8): update to 7.0.2 right now. July 18, 2026 Note: Terminus Agency clients are already protected from this vulnerability. A critical, actively dangerous security hole was just disclosed in WordPress core, and if your site is running any version up to and including 7.0.1, it is exposed right now. This one earns a CVSS score of 9.8 out of 10 - about as severe as vulnerabilities get - and it requires no login, no password, and no user interaction for an attacker to exploit. If you manage a WordPress site and you have not yet updated, stop reading and go update. Then come back and read the rest of this. The announcement. On July 17, 2026, Patchstack published an advisory for an unauthenticated SQL injection vulnerability in WordPress core, affecting all versions up to and including 7.0.1 and patched in 7.0.2. Because no authentication is required and the flaw touches the database directly, Patchstack classifies it as high-priority and warns it is "expected to become exploited," with real potential for mass-exploitation campaigns hitting large numbers of sites at once. You can read the two authoritative sources here: The official WordPress announcement confirms this is a security release addressing one critical and one high-severity issue, and that the severity was serious enough for the WordPress.org team to enable forced updates through the auto-update system. When the core team pushes a forced update, that is your signal the threat is real and immediate. What to do if you haven't updated yet. Terminus Agency's recommendation is simple and non-negotiable: update to WordPress 7.0.2 immediately. Here is exactly what Terminus Agency, LLC. advise every site owner do today, in order. First, update WordPress core to 7.0.2 (or the appropriate patched release for your branch - 6.9.5 and 6.8.6 were also issued for older supported versions). You can do this from your WordPress Dashboard under Dashboard | Updates, or by downloading the release directly. If your site is on WordPress.org's auto-update system, the forced update may already have applied it - but verify, don't assume. Second, confirm the version actually changed. Check the bottom-right of your dashboard or your site's Site Health screen to make sure you are genuinely on a patched release and the update didn't silently fail. Third, take a fresh backup before and after, so you have a clean restore point. Fourth, look for signs of compromise. Because this flaw was disclosed publicly, opportunistic scanning starts within hours. Review recent admin users, check for unfamiliar files, and scan for unexpected database changes. If anything looks off, treat the site as potentially breached and get professional help. Fifth, if you can't update right this moment, put a virtual patch or web application firewall (WAF) rule in front of the site. Patchstack has issued mitigation rules to block these attacks until systems are updated - but this is a stopgap, not a substitute for patching. If you're a Terminus managed-hosting client, you don't need to do any of this. Your site was patched as part of its monitoring and maintenance process. That's the entire point of managed maintenance - you found out about this vulnerability from its blog, not from your site going down. What the vulnerability actually is. SQL injection is one of the oldest and most damaging classes of web vulnerability - it sits in the OWASP "Injection" category for good reason. In plain terms: your website talks to a database that stores everything - user accounts, passwords (hashed), posts, orders, customer records, configuration. A SQL injection flaw lets an attacker sneak their own database commands into that conversation through an input the application failed to properly sanitize. The reason this particular flaw is a 9.8 and not a 6 is the word unauthenticated. The attacker doesn't need an account. They don't need to trick a logged-in admin. They can hit the vulnerable endpoint directly, from anywhere, at scale, with an automated script. What an attacker could do if you leave it unpatched. Left in place, this vulnerability gives an attacker the ability to interact directly with your database. In practice, that means they could: * Steal data - dump user tables, email addresses, hashed passwords, customer information, and order history, creating a breach you'd be legally obligated to disclose. * Extract admin credentials - and use them or a password reset to gain full control of the site. * Escalate to full takeover - the official WordPress release notes that a related issue chains a REST API flaw with SQL injection to enable remote code execution. RCE is the worst case: it means running arbitrary code on your server, which can lead to defacement, malware injection, SEO spam, redirect scams, or using your server as a launchpad for further attacks. A stolen database and a compromised server aren't hypothetical inconveniences. They mean customer trust destroyed, potential regulatory penalties, cleanup costs, and lost revenue while your site is offline or blocklisted by Google. Why "we'll update it later" is how sites get hacked. Here's the uncomfortable truth about most WordPress breaches: they don't happen because of some brilliant, novel exploit. They happen because a site was running software with a known vulnerability that a patch had already fixed - the owner just never applied it. The most famous example is the Panama Papers - the 2016 leak of 11.5 million documents from law firm Mossack Fonseca, one of the largest data breaches in history. Security analysts at Wordfence traced a likely entry point to the firm's WordPress site, which was running an outdated version of the Revolution Slider plugin with a well-known, already-patched vulnerability. The site's core WordPress install was also months out of date. Because the firm's mail server sat on the same infrastructure as its neglected website, attackers were able to pivot from the vulnerable plugin into the email system and exfiltrate a staggering volume of confidential client documents. The lesson is brutal and clear: the vulnerability that took down a global law firm wasn't a zero-day. It was a patch that existed and simply hadn't been applied. Maintenance - not luck - is what stands between a routine update and a career-ending breach. (Sources: The Register, Wordfence.) Stop patching by hand. Let Terminus Agency, LLC. handle it. Every WordPress site is a moving target. Core, themes, and plugins all get updated constantly, and every one of those updates can carry a security fix you can't afford to miss. Keeping up with that manually - while running your actual business - is a losing game. The Panama Papers proved what happens when maintenance slips. Terminus Agency's WordPress Hosting & Maintenance service is built exactly for moments like this. Terminus Agency, LLC. monitor the vulnerability feeds, test and apply core and plugin updates, run WAF and virtual patching for zero-day windows, maintain off-site backups, and watch for compromise around the clock - using security operations best practices so a headline like this one is its problem to solve, not yours to panic over. Don't wait for the next 9.8 to find out whether your site is covered.
Estonia-based Patchstack has partnered with GoDaddy to integrate vulnerability detection capabilities into GoDaddy's Managed WordPress hosting platform. The collaboration will provide eligible customers with access to Patchstack's vulnerability-specific detection tools and premium RapidMitigate technology, which automatically deploys targeted protection rules before vulnerabilities become widely exploited. The partnership addresses the shrinking gap between vulnerability disclosure and exploitation. Patchstack research shows heavily targeted vulnerabilities are often exploited within hours, with a median time to mass exploitation of just five hours. GoDaddy, the world's largest domain registrar, will embed Patchstack's security tools directly into its hosting environment, enabling small businesses to identify and respond to security risks without requiring additional tools or expertise. The integration moves security from reactive incident response towards proactive, real-time protection.
NEW: Patchstack Protection for WordPress websites at JetHost. WordPress security has never been more important. Most successful attacks happen within hours of a vulnerability being publicly disclosed and understandably, many websites haven't been updated yet. Simply relying on updates is no longer a sufficient security strategy. That's why JetHost Inc. has integrated Patchstack - a global leader in WordPress vulnerability intelligence and mitigation. Why Patchstack? The WordPress ecosystem includes over 60,000 free plugins and more than 20,000 premium extensions. A total of 11,334 new vulnerabilities were discovered in the WordPress ecosystem in 2025, a 42% increase compared to 2024. Additionally: * Of those, 36% were serious enough to require active protection rules due to high exploit risk. * 17% were classified as high severity, meaning they were likely to be exploited in automated, mass-scale attacks. * 91% of vulnerabilities were found in plugins and 9% in themes, with only a handful in WordPress core. * 46% of vulnerabilities did not receive a patch before public disclosure, leaving sites exposed at the moment they became public. * Attackers are fast: the median time to first exploit for heavily exploited flaws was just ~5 hours after disclosure, and about half were exploited within 24 hours. The takeaway is simple: if you're just waiting for the next update, you may already be too late. How Patchstack works. Patchstack has been the #1 vulnerability processor since 2023 and maintains the largest real-time WordPress vulnerability database in the world. The platform offers over 11,000 specialized mitigation rules that: * Analyze WordPress core, plugin, and theme versions * Detect vulnerable installations in real time * Automatically apply mitigation rules without modifying code * Block RCE, SQL Injection (SQLi), XSS, and other attack vectors * Send clear, human-readable alerts - no technical jargon. Unlike traditional Web Application Firewalls (WAFs), Patchstack activates only when there's an actual exploitation attempt, meaning no constant resource drain and no performance impact. This is a proactive approach: instead of cleaning up after a breach, you prevent the attack before it happens. In fact, proactive cybersecurity is proven to be up to 70% more cost-effective than reacting after a hack. Patchstack Protection at JetHost. WordPress hosting - Business plan. With the Business plan, you get Patchstack protection included for one domain of your choice for the full duration of your hosting service. Activation is simple: Client Profile | WP Manager | Patchstack Protection. WordPress hosting - mini, start & maverick plans. For all other plans, Patchstack protection can be added for just $3.99 per domain per month. With only a few clicks, you can add an extra layer of defense against the most commonly exploited WordPress vulnerabilities. Activation is just as easy: Client Profile | WP Manager | Patchstack Protection. What Patchstack Protection means for you. * Lower risk of being hacked * Reduced emergency cleanup costs * Greater peace of mind * More time to focus on growing your project By integrating Patchstack, JetHost Inc. is taking another step toward delivering safer hosting for all WordPress websites at JetHost. This is also part of its ongoing commitment to the WordPress community. JetHost Inc. believe in the growth of this ecosystem and want to actively contribute to its security, stability, and long-term success. Activate your protection today and stay one step ahead. Rosie is a senior hosting expert with more than 17 years of experience working with servers, hosting platforms, and WordPress websites.
Automation, security, and the rise of AI: WordPress in full throttle. In a bustling week for the WordPress ecosystem, we've seen a flurry of updates and integrations that signal a major shift in how we build, secure, and manage our websites. Leading the pack was Pressable's announcement of its Developer Toolkit Update, aimed at reducing the dreaded manual overhead that haunts developers and agencies. With new automation features and a slick UI, we're promised a future where managing multiple WordPress sites is less about wrangling Bash scripts and more about focusing on creativity and growth. But let's not just gloss over the fact that automation, while massively helpful, comes with its own set of challenges. Sure, the updated API endpoints introduce a world of possibilities for programmatic site management, but they also necessitate a learning curve for developers who need to familiarize themselves with these changes. Ultimately, this toolkit is a nod to the future where efficiency reigns supreme - assuming you can keep up with the pace. Meanwhile, the long-awaited Divi 5 is finally out of beta, bringing a modern design system to the masses. Elegant Themes' shift from a traditional page builder to a scalable, cohesive design system feels like a necessary evolution. There's Flexbox and CSS Grid support, infinite nesting, and more - all promising to make intricate layouts a breeze. Yet, the real world isn't always as rosy as the marketing promises. Backward compatibility is touted, but there's always the lurking fear of incompatibilities with third-party plugins. Their promise to support Divi 4 for another year is reassuring, yet it doesn't completely eliminate the anxiety of transition for many site owners. Security remains a dominant theme, with BigWetFish Hosting partnering with Patchstack for proactive WordPress security measures. This integration sees Patchstack's vulnerability detection rolled out to BigWetFish's customers, a much-needed move in an era where vulnerabilities are discovered faster than they can be patched. It's a crucial reminder that security isn't just an add-on feature but a foundational necessity. As more hosting providers follow suit, we'll hopefully see a trend where security is baked into the very infrastructure of WordPress hosting. Speaking of infrastructure, the WordPress ecosystem is abuzz with the forthcoming WordPress 7.0 update, which introduces AI integration and real-time collaboration features. The beta is already here, and while these features are exciting, they bring to light the perennial issue of feature bloat and compatibility. Integrating AI might revolutionize content creation, but it also opens up a can of worms regarding privacy and data handling. What this week signals. This week's flurry of activity signals a definitive trend toward more streamlined, secure, and intelligent WordPress experiences. We're seeing a shift where the traditional lines between developer and designer blur as roles adapt to new tools and methodologies. Automation and AI aren't just buzzwords - they're becoming integral to the workflow. However, this rapid pace of innovation also requires a reevaluation of how we approach training and support. The landscape is changing so quickly that it risks leaving less experienced users behind. It's crucial that as these tools evolve, we also see parallel advancements in user education and support infrastructure. Final thoughts. This week, WordPress is clearly pushing boundaries, but the onus is on us - developers, site owners, and agencies - to keep pace. As we embrace these new tools and features, we'll need to balance the excitement of innovation with the pragmatic realities of implementation and maintenance. The ecosystem is evolving, and as always, those who adapt will thrive.
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series A
Total Funding
$6.9M
Headquarters
Pärnu linn, Estonia
Founded
2017
Find jobs on Simplify and start your career today