bbioonThemes
  • Home
  • Blog

Category: Bug Fixing

Bug Fixing, Development

WordPress security: the risk is your plugins, not core

Almost every WordPress vulnerability comes from a plugin or theme, not from core. Where the risk actually sits, the hardening I put on sites I manage, and the maintenance habits that keep them clean.

Read Article
Bug Fixing, Core Updates

WooCommerce Store API vulnerability: how to check and patch

CVE-2026-3589 is a CSRF flaw in the WooCommerce Store API, affecting versions 5.4 to 10.5.2, that can be used to create admin accounts through batch requests. How the flaw works, and how to check your own version with WP-CLI or a small PHP snippet.

Read Article
Bug Fixing, Core Updates, Development

WooCommerce 10.5.3 patches a critical Store API bug

WooCommerce 10.5.3 patches a path validation bug in the Store API batch endpoint that let attackers skip nonce checks and gain admin access via CSRF. Don’t roll back to 10.5.2; update now and test your checkout.

Read Article
Bug Fixing, Development

DAX Filtering is killing your Power BI performance

Ahmad Wael breaks down why overusing FILTER() in DAX forces work into Power BI’s slow, single-threaded Formula Engine, and how a simple predicate lets the Storage Engine (VertiPaq) handle it instead.

Read Article
Bug Fixing, Core Updates, Development

CSS exploit in Chrome: how CVE-2026-2441 actually works

Ahmad Wael explains CVE-2026-2441, a Use-After-Free bug in Chrome’s Blink CSS engine triggered through @font-feature-values. It’s not literal code execution via CSS, but it’s a real reason to update your browser now.

Read Article
AI, Bug Fixing, Development

Vibe coding security risks I keep finding in client code

AI agents optimize for code that runs, not code that is safe. Two failures I keep finding in agent-written WordPress code, hardcoded API keys and REST routes with no permission callback, plus the review habits that catch them.

Read Article
AI, Bug Fixing, Development

Agentic AI for repositories: automating READMEs and CI

Writing the README and wiring up CI is the part everyone puts off. OSA is a multi-agent tool that reads the repository, drafts the docs and docstrings, and generates the workflow files. Here is how it works and how to run it.

Read Article
Bug Fixing, Core Updates

WooCommerce 10.5.2 fixes the disabled add to cart button

WooCommerce 10.5.2 reverts the change that left the Add to Cart button disabled on variable products when a theme or plugin altered how the variation scripts load. What went wrong, and the WP-CLI steps to update without stale variation data.

Read Article
Bug Fixing, Development, E-commerce Development

Running a chi-square test on your WooCommerce A/B data

A plugin showing a green arrow is not proof that a variant won. This post walks through a 2×2 chi-square test in PHP: expected counts, degrees of freedom, the 3.84 cutoff at p=0.05, and the four assumptions that break the result.

Read Article
Bug Fixing, Development, E-commerce Development

WooCommerce testing tools and the March core team office hours

WooCommerce core devs Greg Bell and Lance Willet are running an open office hours session on testing on March 4, 2026. What to test before you ship, and what to ask them on Slack.

Read Article

Posts navigation

Previous 1 … 3 4 5 … 17 Next

bbioonThemes

Senior WordPress Engineer
Toptal & Codeable Expert

Connect

  • GitHub
  • Twitter
  • LinkedIn
  • Codeable

Explore

  • Expertise
  • Work
  • Insights
  • Blog

Resources

  • bbioonThemes
  • Contact
  • Privacy Policy
© 2026 bbioonThemes. All rights reserved.
Privacy