<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="//www.egilmez-nakliyat.com.tr/main-sitemap.xsl"?>
<sitemapindex xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
	<sitemap>
		<loc>https://www.egilmez-nakliyat.com.tr/post-sitemap.xml</loc>
		<lastmod>2026-02-03T17:17:02+00:00</lastmod>
	</sitemap>
	<sitemap>
		<loc>https://www.egilmez-nakliyat.com.tr/page-sitemap.xml</loc>
		<lastmod>2026-03-26T14:19:09+00:00</lastmod>
	</sitemap>
	<sitemap>
		<loc>https://www.egilmez-nakliyat.com.tr/category-sitemap.xml</loc>
		<lastmod>2026-02-03T17:17:02+00:00</lastmod>
	</sitemap>
</sitemapindex>
<!-- XML Sitemap generated by Rank Math SEO Plugin (c) Rank Math - rankmath.com -->
<!-- Served from cache in 0.001 second(s) (Memory usage: 1.71 KB) -->
<!-- Array
(
    [0] => Array
        (
            [0] => SELECT option_name, option_value FROM wpd9_options WHERE autoload IN ( 'yes', 'on', 'auto-on', 'auto' )
            [1] => 0.025997877120972
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), wp_not_installed, is_blog_installed, wp_load_alloptions
            [3] => 1791651094.2691
            [4] => Array
                (
                )

        )

    [1] => Array
        (
            [0] => SHOW ENGINES
            [1] => 0.0023880004882812
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\MuLoader::buildPipeline, CloudLinux\Imunify\App\Bot\DbStorageFactory::detect, CloudLinux\Imunify\App\Bot\DbStorageFactory::isMemoryEngineAvailable
            [3] => 1791651094.9589
            [4] => Array
                (
                )

        )

    [2] => Array
        (
            [0] => SELECT 1 FROM `wpd9_imunify_bot_blocks_active` WHERE `ip_key` = 'rl:b:balanced:verified_ai_crawler:216.73.216.110' AND `site_id` = '05b6089c27ebd44c' AND `expires_at` > 1791651094 LIMIT 1
            [1] => 0.0013961791992188
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\RateLimiter->check, CloudLinux\Imunify\App\Bot\MemoryBlockStorage->isBlocked, CloudLinux\Imunify\App\Bot\MemoryBlockStorage->queryActiveTable
            [3] => 1791651094.9876
            [4] => Array
                (
                )

        )

    [3] => Array
        (
            [0] => INSERT INTO `wpd9_imunify_bot_rl` (`rl_key`, `counter`, `expires_at`) VALUES ('rl:c:05b6089c27ebd44c:balanced:verified_ai_crawler:216.73.216.110', 1, 1791651154) ON DUPLICATE KEY UPDATE `counter` = IF(`expires_at` > 1791651094, `counter` + 1, 1), `expires_at` = IF(`expires_at` > 1791651094, `expires_at`, 1791651154)
            [1] => 0.00051999092102051
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\RateLimiter->check, CloudLinux\Imunify\App\Bot\MemoryCounterStorage->increment, CloudLinux\Imunify\App\Bot\MemoryCounterStorage->exec
            [3] => 1791651094.9892
            [4] => Array
                (
                )

        )

    [4] => Array
        (
            [0] => SELECT `counter` FROM `wpd9_imunify_bot_rl` WHERE `rl_key` = 'rl:c:05b6089c27ebd44c:balanced:verified_ai_crawler:216.73.216.110' AND `expires_at` > 1791651094
            [1] => 0.00016593933105469
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\RateLimiter->check, CloudLinux\Imunify\App\Bot\MemoryCounterStorage->increment, CloudLinux\Imunify\App\Bot\MemoryCounterStorage->getAt
            [3] => 1791651094.9898
            [4] => Array
                (
                )

        )

    [5] => Array
        (
            [0] => INSERT INTO `wpd9_imunify_bot_hourly` (`hour_bucket`,`category`,`bot`,`verdict`,`req_count`,`cur_min`,`cur_min_cnt`,`peak_req_min`) VALUES (497680, 'verified_ai_crawler', 'ClaudeBot', 'allow', 1, 51, 1, 1) ON DUPLICATE KEY UPDATE `req_count` = `req_count` + 1, `peak_req_min` = GREATEST(`peak_req_min`, IF(`cur_min` = 51, `cur_min_cnt` + 1, 1)), `cur_min_cnt` = IF(`cur_min` = 51, `cur_min_cnt` + 1, 1), `cur_min` = 51
            [1] => 0.0008399486541748
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\Pipeline->recordStats, CloudLinux\Imunify\App\Bot\Pipeline->guardTelemetry, call_user_func, CloudLinux\Imunify\App\Bot\Pipeline->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyStatsStorage->record, CloudLinux\Imunify\App\Bot\HourlyStatsStorage->guardVoid, CloudLinux\Imunify\App\Bot\HourlyStatsStorage->guard, call_user_func, CloudLinux\Imunify\App\Bot\HourlyStatsStorage->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyStatsStorage->exec
            [3] => 1791651094.9908
            [4] => Array
                (
                )

        )

    [6] => Array
        (
            [0] => SHOW FULL COLUMNS FROM `wpd9_imunify_bot_hourly_ip`
            [1] => 0.0010251998901367
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\Pipeline->recordStats, CloudLinux\Imunify\App\Bot\Pipeline->guardTelemetry, call_user_func, CloudLinux\Imunify\App\Bot\Pipeline->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->record, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guardVoid, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guard, call_user_func, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->bumpExisting, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->exec
            [3] => 1791651094.9919
            [4] => Array
                (
                )

        )

    [7] => Array
        (
            [0] => UPDATE `wpd9_imunify_bot_hourly_ip` SET `req_count` = `req_count` + 1, `verdict` = IF( FIELD('allow','allow','rate_limit','block') > FIELD(`verdict`,'allow','rate_limit','block'), 'allow', `verdict` ) WHERE `hour_bucket` = 497680 AND `category` = 'verified_ai_crawler' AND `bot` = 'ClaudeBot' AND `ip` = 'ĜIĜn'
            [1] => 0.00029087066650391
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\Pipeline->recordStats, CloudLinux\Imunify\App\Bot\Pipeline->guardTelemetry, call_user_func, CloudLinux\Imunify\App\Bot\Pipeline->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->record, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guardVoid, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guard, call_user_func, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->bumpExisting, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->exec
            [3] => 1791651094.993
            [4] => Array
                (
                )

        )

    [8] => Array
        (
            [0] => SELECT COUNT(*) FROM `wpd9_imunify_bot_hourly_ip` WHERE `hour_bucket` = 497680 AND `category` = 'verified_ai_crawler' AND `bot` = 'ClaudeBot'
            [1] => 0.00017905235290527
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\Pipeline->recordStats, CloudLinux\Imunify\App\Bot\Pipeline->guardTelemetry, call_user_func, CloudLinux\Imunify\App\Bot\Pipeline->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->record, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guardVoid, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guard, call_user_func, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->groupCount
            [3] => 1791651094.9933
            [4] => Array
                (
                )

        )

    [9] => Array
        (
            [0] => INSERT INTO `wpd9_imunify_bot_hourly_ip` (`hour_bucket`,`category`,`bot`,`ip`,`verdict`,`req_count`) VALUES (497680, 'verified_ai_crawler', 'ClaudeBot', 'ĜIĜn', 'allow', 1) ON DUPLICATE KEY UPDATE `req_count` = `req_count` + 1, `verdict` = IF( FIELD(VALUES(`verdict`),'allow','rate_limit','block') > FIELD(`verdict`,'allow','rate_limit','block'), VALUES(`verdict`), `verdict` )
            [1] => 0.00020813941955566
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/mu-plugins/imunify-security-bots.php'), CloudLinux\Imunify\App\Bot\MuLoader::run, CloudLinux\Imunify\App\Bot\MuLoader::runWith, CloudLinux\Imunify\App\Bot\Pipeline->run, CloudLinux\Imunify\App\Bot\Pipeline->runInner, CloudLinux\Imunify\App\Bot\Pipeline->recordStats, CloudLinux\Imunify\App\Bot\Pipeline->guardTelemetry, call_user_func, CloudLinux\Imunify\App\Bot\Pipeline->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->record, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guardVoid, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->guard, call_user_func, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->CloudLinux\Imunify\App\Bot\{closure}, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->insertNew, CloudLinux\Imunify\App\Bot\HourlyIpStatsStorage->exec
            [3] => 1791651094.9936
            [4] => Array
                (
                )

        )

    [10] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'uninstall_plugins' LIMIT 1
            [1] => 0.0077362060546875
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/elementor/elementor.php'), require('/plugins/elementor/includes/plugin.php'), Elementor\Plugin::instance, Elementor\Plugin->__construct, Elementor\Maintenance::init, register_uninstall_hook, get_option
            [3] => 1791651095.078
            [4] => Array
                (
                )

        )

    [11] => Array
        (
            [0] => SELECT option_name, option_value FROM wpd9_options WHERE option_name IN ('_transient_imunify_security_rules_4.1.3_1791649597_4185595','_transient_timeout_imunify_security_rules_4.1.3_1791649597_4185595')
            [1] => 0.00045394897460938
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/imunify-security/imunify-security.php'), CloudLinux\Imunify\App\Plugin->init, CloudLinux\Imunify\App\Plugin->coreSetup, CloudLinux\Imunify\App\Defender\RuleProvider->loadRules, get_transient, wp_prime_option_caches
            [3] => 1791651095.1767
            [4] => Array
                (
                )

        )

    [12] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'active_sitewide_plugins' LIMIT 1
            [1] => 0.00054407119750977
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/imunify-security/imunify-security.php'), CloudLinux\Imunify\App\Plugin->init, CloudLinux\Imunify\App\Plugin->coreSetup, CloudLinux\Imunify\App\Defender\RuleProvider->loadRules, CloudLinux\Imunify\App\Defender\RuleProvider->getRelevantRules, CloudLinux\Imunify\App\Defender\RuleProvider->getTargetInfo, CloudLinux\Imunify\App\Defender\RuleProvider->loadPlugins, get_site_option, get_network_option, get_option
            [3] => 1791651095.2592
            [4] => Array
                (
                )

        )

    [13] => Array
        (
            [0] => INSERT INTO `wpd9_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_timeout_imunify_security_rules_4.1.3_1791649597_4185595', '1791672695', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`)
            [1] => 0.00098896026611328
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/imunify-security/imunify-security.php'), CloudLinux\Imunify\App\Plugin->init, CloudLinux\Imunify\App\Plugin->coreSetup, CloudLinux\Imunify\App\Defender\RuleProvider->loadRules, set_transient, add_option
            [3] => 1791651095.3332
            [4] => Array
                (
                )

        )

    [14] => Array
        (
            [0] => SHOW FULL COLUMNS FROM `wpd9_options`
            [1] => 0.00068902969360352
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/imunify-security/imunify-security.php'), CloudLinux\Imunify\App\Plugin->init, CloudLinux\Imunify\App\Plugin->coreSetup, CloudLinux\Imunify\App\Defender\RuleProvider->loadRules, set_transient, add_option
            [3] => 1791651095.3356
            [4] => Array
                (
                )

        )

    [15] => Array
        (
            [0] => INSERT INTO `wpd9_options` (`option_name`, `option_value`, `autoload`) VALUES ('_transient_imunify_security_rules_4.1.3_1791649597_4185595', 'a:2:{s:7:\"version\";s:8:\"0.1392.2\";s:5:\"rules\";a:56:{s:41:\"RULE-CAMPAIGN-FAKEPLUGIN-INSTALL-BLOCK-01\";a:12:{s:3:\"cve\";s:36:\"CAMPAIGN-FAKEPLUGIN-INSTALL-BLOCK-01\";s:11:\"description\";s:615:\"Blocks upload of known fake-plugin archives at the WordPress plugin\ninstall endpoint. Seed slugs are confirmed malicious backdoor-dropper\nplugins (wp_org_exists=false, shared payload generator signature) that\ninstall further payloads when activated. Fires on the plugin upload\nstep before the zip is extracted, preventing backdoor deployment via\nstolen or compromised admin credentials. The slug denylist should be\nupdated as new IOC slugs are identified via the malware research\npipeline. This rule covers the HTTP install vector; on-disk detection\nis handled by AiBolit recognizers via the malware-team pipeline.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:9;s:4:\"tags\";a:6:{i:0;s:19:\"fake-plugin-install\";i:1;s:15:\"post-compromise\";i:2;s:7:\"dropper\";i:3;s:21:\"php-bkdr-wpplugin-mal\";i:4;s:22:\"admin-credential-abuse\";i:5;s:16:\"wpplugin1-family\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:3:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:24:\"~^/wp-admin/update\\.php~\";}i:1;a:3:{s:4:\"name\";s:11:\"ARGS:action\";s:4:\"type\";s:6:\"equals\";s:5:\"value\";s:13:\"upload-plugin\";}i:2;a:3:{s:4:\"name\";s:20:\"FILES:pluginzip:name\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:75:\"~^(platformist-quadendpointer|theme-js-wpcode|framework-triappment)\\.zip$~i\";}}}s:30:\"RULE-CAMPAIGN-IMGCDN-INJECT-01\";a:11:{s:3:\"cve\";s:31:\"CAMPAIGN-2026-W41-IMGCDN-INJECT\";s:11:\"description\";s:44:\"Campaign payload host in request parameters.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:8.8;s:4:\"tags\";a:4:{i:0;s:8:\"campaign\";i:1;s:10:\"stored-xss\";i:2;s:3:\"ioc\";i:3;s:7:\"wp-core\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:4:\"ARGS\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:46:\"~imgcdn1(?:\\.|&#0*46;?|&#x0*2e;?|\\\\u002e)com~i\";}}}s:29:\"RULE-CAMPAIGN-IMGCDN-LOGIN-01\";a:11:{s:3:\"cve\";s:36:\"CAMPAIGN-2026-W41-IMGCDN-MAGIC-LOGIN\";s:11:\"description\";s:34:\"Campaign backdoor login parameter.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:8.1;s:4:\"tags\";a:4:{i:0;s:8:\"campaign\";i:1;s:25:\"post-compromise-signature\";i:2;s:3:\"ioc\";i:3;s:7:\"wp-core\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"name\";s:17:\"ARGS:/^_wplogin$/\";s:4:\"type\";s:6:\"exists\";}}}s:27:\"RULE-CAMPAIGN-IMGCDN-PKG-01\";a:11:{s:3:\"cve\";s:32:\"CAMPAIGN-2026-W41-IMGCDN-PACKAGE\";s:11:\"description\";s:43:\"Campaign plugin in uploaded plugin archive.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:8.8;s:4:\"tags\";a:4:{i:0;s:8:\"campaign\";i:1;s:16:\"malicious-plugin\";i:2;s:3:\"ioc\";i:3;s:7:\"wp-core\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:23:\"FILES:pluginzip:content\";s:4:\"type\";s:8:\"contains\";s:5:\"value\";s:20:\"wp-smart-thumbnails/\";}}}s:27:\"RULE-CAMPAIGN-IMGCDN-PKG-02\";a:11:{s:3:\"cve\";s:32:\"CAMPAIGN-2026-W41-IMGCDN-PACKAGE\";s:11:\"description\";s:53:\"Campaign plugin slug in uploaded plugin archive name.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:8.8;s:4:\"tags\";a:4:{i:0;s:8:\"campaign\";i:1;s:16:\"malicious-plugin\";i:2;s:3:\"ioc\";i:3;s:7:\"wp-core\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:20:\"FILES:pluginzip:name\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:22:\"~wp-smart-thumbnails~i\";}}}s:41:\"RULE-CAMPAIGN-IMGCDN1-DELIVERY-MONITOR-01\";a:11:{s:3:\"cve\";s:34:\"CAMPAIGN-2026-W41-IMGCDN1-DELIVERY\";s:11:\"description\";s:219:\"Observes request parameters referencing the campaign loader host imgcdn1.com (delivered as <script src=https://imgcdn1.com/fz/x.js> in woosb_ids[..][qty] and in Ninja Forms nf_ajax_submit fields), on any plugin version.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:12:\"campaign-ioc\";i:2;s:16:\"delivery-attempt\";i:3;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:4:\"ARGS\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:15:\"~imgcdn1\\.com~i\";}}}s:45:\"RULE-CAMPAIGN-IMGCDN1-HIDDEN-ADMIN-MONITOR-01\";a:12:{s:3:\"cve\";s:38:\"CAMPAIGN-2026-W41-IMGCDN1-HIDDEN-ADMIN\";s:11:\"description\";s:217:\"Observes administrator creation with an @wordpress.org email, the address pattern the x.js payload uses for its hidden admins (user-new.php form or REST /wp/v2/users JSON). The exact creation request is not published.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:12:\"campaign-ioc\";i:2;s:25:\"post-compromise-signature\";i:3;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:10:\"ARGS:email\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:22:\"~@wordpress\\.org\\s*$~i\";}i:1;a:3:{s:4:\"name\";s:15:\"ARGS:/^roles?$/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:18:\"~^administrator$~i\";}}}s:45:\"RULE-CAMPAIGN-IMGCDN1-IMPLANT-ARGS-MONITOR-01\";a:11:{s:3:\"cve\";s:33:\"CAMPAIGN-2026-W41-IMGCDN1-IMPLANT\";s:11:\"description\";s:168:\"Observes request parameters naming the fake plugin wp-smart-thumbnails, such as bulk activation (checked[]) or plugin= in a POST body, which the URI monitor cannot see.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:12:\"campaign-ioc\";i:2;s:25:\"post-compromise-signature\";i:3;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:4:\"ARGS\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:22:\"~wp-smart-thumbnails~i\";}}}s:44:\"RULE-CAMPAIGN-IMGCDN1-IMPLANT-URI-MONITOR-01\";a:11:{s:3:\"cve\";s:33:\"CAMPAIGN-2026-W41-IMGCDN1-IMPLANT\";s:11:\"description\";s:377:\"Observes URIs naming the campaign\'s fake plugin wp-smart-thumbnails (implant paths, plugins.php activation links, REST plugin routes) or its MU-plugin files class-wp-query-<8 hex>.php / class-wp-token-validate.php. Direct requests to an existing implant file reach WordPress only if that file bootstraps it; probes for absent files are routed through index.php and are visible.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:12:\"campaign-ioc\";i:2;s:25:\"post-compromise-signature\";i:3;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:85:\"~wp-smart-thumbnails|/mu-plugins/class-wp-(?:query-[0-9a-f]{8}|token-validate)\\.php~i\";}}}s:44:\"RULE-CAMPAIGN-IMGCDN1-MAGIC-LOGIN-MONITOR-01\";a:11:{s:3:\"cve\";s:40:\"CAMPAIGN-2026-W41-IMGCDN1-BACKDOOR-LOGIN\";s:11:\"description\";s:493:\"Observes the implant\'s magic-login parameter _wplogin=<token> (tokens kept in option fz_emer_login_tokens) on any path and method. The backdoor reads it on init, so it works on any front-end URL, not only wp-login.php; ModSec 77117086 saw 21,495 of 23,718 hits on / over 60 days. _wplogin is not a WordPress core parameter. Where the blocking RULE-CAMPAIGN-IMGCDN-LOGIN-01 is active it registers first and records the incident itself; this monitor keeps the signal where that rule is disabled.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:12:\"campaign-ioc\";i:2;s:25:\"post-compromise-signature\";i:3;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"name\";s:17:\"ARGS:/^_wplogin$/\";s:4:\"type\";s:6:\"exists\";}}}s:36:\"RULE-CAMPAIGN-SC-REST-CMD-CHANNEL-01\";a:11:{s:3:\"cve\";s:29:\"CAMPAIGN-2026-W37-SC-REST-CMD\";s:11:\"description\";s:1049:\"Detects the SC framework REST command channel. SC v2.8.1 registers an\nunauthenticated REST route at /wp-json/<slug>/v1/cmd with Ed25519 request signing,\ncarrying fifteen commands including exec, install_plugin, create_user and inject_js.\nSlugs are generated as a plausible multi-word WordPress feature name plus a four-hex\nsuffix. Observed fleet-wide over seven days: cors-handler-b1fd, cors-handler-1a0f,\nheartbeat-controller-22dc, heartbeat-controller-23cb, shortcode-renderer-f1a4,\ncomment-spam-filter-26e6, image-compression-service-f283, http-request-handler-c12d,\ndeferred-script-loader-9703, post-meta-indexer-5959, admin-bar-optimizer-29c3,\nthumbnail-regenerator-dea4, rest-api-cache-6702, login-throttle-service-eee8. Two base\nnames recurring under different hex suffixes is what confirms generation rather than\nhand-picking. The mandatory four-hex tail on a multi-word prefix is the false-positive\nfloor: other /v1/cmd routes seen in the same window (wab, cg, vs-admin, wpcli-bridge,\nwp-update) do not match and are deliberately excluded.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:9;s:4:\"tags\";a:4:{i:0;s:15:\"post-compromise\";i:1;s:8:\"backdoor\";i:2;s:15:\"command-channel\";i:3;s:21:\"core-fs-path-coverage\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:91:\"~(?:^/wp-json|(?:^|&|\\?)rest_route=)/[a-z0-9]+(?:-[a-z0-9]+)+-[0-9a-f]{4}/v1/cmd([/?&]|$)~i\";}}}s:37:\"RULE-CAMPAIGN-SC-ROGUE-ADMIN-LOGIN-01\";a:12:{s:3:\"cve\";s:32:\"CAMPAIGN-2026-W37-SC-ROGUE-ADMIN\";s:11:\"description\";s:848:\"Detects login attempts using the SC framework\'s generated administrator\naccounts. The framework creates hidden admin users and the operator then authenticates\nwith them normally, so the credential is valid and nothing upstream objects. Observed\nshapes: administrator_<6 hex>, adm_<10 hex>, admin_<10 hex>, backup_<10 digits>,\nindependently documented across ten incident cases by the DEFA case series and\nconfirmed in production at 34,767 wp-login POSTs across 4,199 domains in three days.\nPasswords accompanying them are per-site 24-hex-character strings rather than\ndictionary guesses, which distinguishes this from ordinary brute-force traffic. No\nlegitimate WordPress installation generates usernames of this shape, and the existing\nModSec rule 77433257 does not cover them - it matches usr_<6-10 hex>, a different\nmalware family\'s convention.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:8.5;s:4:\"tags\";a:4:{i:0;s:15:\"post-compromise\";i:1;s:11:\"rogue-admin\";i:2;s:16:\"credential-abuse\";i:3;s:19:\"core-param-coverage\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:25:\"~/wp-login\\.php([?#]|$)~i\";}i:1;a:3:{s:4:\"name\";s:8:\"ARGS:log\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:86:\"~^(?:administrator_[0-9a-f]{6}|adm_[0-9a-f]{10}|admin_[0-9a-f]{10}|backup_[0-9]{10})$~\";}}}s:30:\"RULE-CAMPAIGN-SC-SW-CLEANUP-01\";a:12:{s:3:\"cve\";s:22:\"CAMPAIGN-SC-SW-CLEANUP\";s:11:\"description\";s:150:\"A service worker from the SC malware campaign is registered in an administrator\'s browser. It survives server-side cleanup and can re-infect the site.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:9;s:4:\"tags\";a:2:{i:0;s:14:\"client-payload\";i:1;s:14:\"service-worker\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:16:\"imunify-security\";s:8:\"versions\";s:7:\">=4.1.2\";s:11:\"ajax_action\";s:32:\"imunify_security_payload_carrier\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:22:\"client_payload_carrier\";s:4:\"type\";s:13:\"probabilistic\";s:5:\"value\";s:1:\"0\";}}s:7:\"payload\";a:9:{s:7:\"actions\";a:1:{s:6:\"reload\";a:2:{s:7:\"enabled\";b:1;s:6:\"prompt\";a:2:{s:5:\"admin\";s:4:\"none\";s:5:\"login\";s:4:\"none\";}}}s:8:\"contexts\";a:2:{i:0;s:5:\"admin\";i:1;s:5:\"login\";}s:7:\"enabled\";b:1;s:7:\"enforce\";b:1;s:2:\"id\";s:10:\"sw-cleanup\";s:6:\"limits\";a:1:{s:16:\"verdict_ttl_days\";i:7;}s:5:\"match\";a:2:{s:16:\"required_signals\";i:1;s:16:\"script_url_regex\";a:2:{i:0;s:33:\"[?&]sc_[0-9a-fA-F]{6}=1(?:[&#]|$)\";i:1;s:33:\"^[^?#]*/\\?p=[0-9]{8,12}(?:[&#]|$)\";}}s:6:\"schema\";i:1;s:7:\"version\";i:6;}}s:28:\"RULE-CAMPAIGN-SCPB-BEACON-01\";a:11:{s:3:\"cve\";s:29:\"CAMPAIGN-2026-W37-SCPB-BEACON\";s:11:\"description\";s:626:\"Detects the client-side beacon of the sc_pb/sc_c mass-implant campaign.\nThe injected page script polls the site root with sc_pb=<13-digit millisecond\nepoch> as a cache-buster; the implanted mu-plugin answers the request and drives\nan outbound cURL call to the operator infrastructure through the WordPress HTTP\nAPI. 100% of observed values are exactly 13 digits. Production one-day window\n2026-09-08: 502,159 requests across 23,186 domains and 3,482 servers, of which\n98.1% also execute a campaign-shaped dropper file. Zero occurrences fleet-wide\nbefore 2026-09-01. Starts in pass mode pending the false-positive floor check.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:8;s:4:\"tags\";a:4:{i:0;s:15:\"post-compromise\";i:1;s:6:\"beacon\";i:2;s:13:\"mass-campaign\";i:3;s:19:\"core-param-coverage\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:10:\"ARGS:sc_pb\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:13:\"~^[0-9]{13}$~\";}}}s:36:\"RULE-CAMPAIGN-SCPB-CANARY-MONITOR-01\";a:12:{s:3:\"cve\";s:33:\"CAMPAIGN-2026-W37-SCPB-IMPLANT-ID\";s:11:\"description\";s:83:\"Samples SC canary checks carrying sc_c and _r on directory or WordPress login URLs.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:25:\"post-compromise-signature\";i:2;s:21:\"infection-unconfirmed\";i:3;s:19:\"sampled-observation\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:3:\"GET\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:5:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:176:\"~\\A/(?:[^/?#\\r\\n]+/)*(?:wp-login\\.php)?\\?(?=(?:[^&]*&)*sc_c=[0-9a-f]{16}(?:&|\\z))(?=(?:[^&]*&)*_r=[0-9]{6}(?:&|\\z))[A-Za-z0-9_-]+=[^?&#\\r\\n]*(?:&[A-Za-z0-9_-]+=[^?&#\\r\\n]*)*\\z~\";}i:1;a:3:{s:4:\"name\";s:26:\"REQUEST_HEADERS:User-Agent\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:18:\"~^WordPress/[0-9]~\";}i:2;a:3:{s:4:\"name\";s:9:\"ARGS:sc_c\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:18:\"~\\A[0-9a-f]{16}\\z~\";}i:3;a:3:{s:4:\"name\";s:7:\"ARGS:_r\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:14:\"~\\A[0-9]{6}\\z~\";}i:4;a:2:{s:4:\"type\";s:13:\"probabilistic\";s:5:\"value\";s:6:\"0.0005\";}}}s:40:\"RULE-CAMPAIGN-SCPB-HIDDEN-DIR-MONITOR-01\";a:11:{s:3:\"cve\";s:33:\"CAMPAIGN-2026-W37-SCPB-HIDDEN-DIR\";s:11:\"description\";s:925:\"Monitors direct HTTP access to the campaign hidden payload directory\nwp-content/.sc_<8 hex>/. No WordPress distribution, plugin or theme ships a\ndot-prefixed directory under wp-content, so the path cannot resolve on a clean\ninstallation and every hit is attacker or researcher traffic by construction\n(zero false-positive floor). The directory holds the implant module set\n(.g_/.gr_/.gs_/.gm_/.gv_/.gk_/.gl_/.gsu_ plus own_<8hex>.php and the\ncore_<8hex>.php kill switch) and the implant writes its own .htaccess there,\nso a probe is likely denied before PHP executes. That is why PHP-layer\ntelemetry records nothing on this surface and why a request-layer rule is the\ninstrument that can answer whether it is probed at all. Ships pass with\nblock_policy: never_block â it is a monitor by design, and the release\npipeline must not auto-promote it into an enforcing rule on the strength of\na zero-false-positive record alone.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:2;s:4:\"tags\";a:5:{i:0;s:21:\"post-compromise-probe\";i:1;s:27:\"filesystem-planted-backdoor\";i:2;s:16:\"hidden-directory\";i:3;s:7:\"monitor\";i:4;s:21:\"core-fs-path-coverage\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:32:\"~/wp-content/\\.sc_[0-9a-f]{8}/~i\";}}}s:32:\"RULE-CAMPAIGN-SCPB-IMPLANT-ID-01\";a:11:{s:3:\"cve\";s:33:\"CAMPAIGN-2026-W37-SCPB-IMPLANT-ID\";s:11:\"description\";s:750:\"Detects the per-site implant identifier of the sc_pb/sc_c mass-implant\ncampaign. The implanted loader answers requests carrying sc_c=<16 lowercase hex>\non / and /wp-login.php. The value is constant per victim host (one distinct\nvalue per domain across a full production day), which makes it an implant ID\nrather than a cache-buster. This parameter had zero occurrences fleet-wide\nbefore 2026-09-01 and reached 45,986 distinct domains by 2026-09-08, a growth\nshape no legitimately-distributed plugin produces. Starts in pass mode so the\nrelease pipeline can confirm the false-positive floor before promotion.\nThis rule does NOT remediate the compromise; it severs one implant control\nchannel and routes the host to filesystem-integrity investigation.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:8.5;s:4:\"tags\";a:4:{i:0;s:15:\"post-compromise\";i:1;s:23:\"implant-control-channel\";i:2;s:13:\"mass-campaign\";i:3;s:19:\"core-param-coverage\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:9:\"ARGS:sc_c\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:16:\"~^[0-9a-f]{16}$~\";}}}s:42:\"RULE-CAMPAIGN-SCPB-IMPLANT-ID-COMPANION-01\";a:11:{s:3:\"cve\";s:33:\"CAMPAIGN-2026-W37-SCPB-IMPLANT-ID\";s:11:\"description\";s:245:\"Relaxed sampling sibling of RULE-CAMPAIGN-SCPB-IMPLANT-ID-01. Matches\nany sc_c value regardless of shape so that operator rotation of the identifier\nformat (length or alphabet) is visible as companion>0 while primary=0. Never\npromoted to block.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:2:{i:0;s:17:\"companion-sampler\";i:1;s:13:\"mass-campaign\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"name\";s:9:\"ARGS:sc_c\";s:4:\"type\";s:6:\"exists\";}}}s:38:\"RULE-CAMPAIGN-SCPB-LOOPBACK-MONITOR-01\";a:12:{s:3:\"cve\";s:29:\"CAMPAIGN-2026-W37-SCPB-BEACON\";s:11:\"description\";s:60:\"Samples SC loopback checks carrying sc_pb on directory URLs.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:25:\"post-compromise-signature\";i:2;s:21:\"infection-unconfirmed\";i:3;s:19:\"sampled-observation\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:3:\"GET\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:4:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:122:\"~\\A/(?:[^/?#\\r\\n]+/)*\\?(?=(?:[^&]*&)*sc_pb=[0-9]{13}(?:&|\\z))[A-Za-z0-9_-]+=[^?&#\\r\\n]*(?:&[A-Za-z0-9_-]+=[^?&#\\r\\n]*)*\\z~\";}i:1;a:3:{s:4:\"name\";s:26:\"REQUEST_HEADERS:User-Agent\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:18:\"~^WordPress/[0-9]~\";}i:2;a:3:{s:4:\"name\";s:10:\"ARGS:sc_pb\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:15:\"~\\A[0-9]{13}\\z~\";}i:3;a:2:{s:4:\"type\";s:13:\"probabilistic\";s:5:\"value\";s:6:\"0.0005\";}}}s:33:\"RULE-CAMPAIGN-SCPB-WLH-CHANNEL-01\";a:11:{s:3:\"cve\";s:26:\"CAMPAIGN-2026-W37-SCPB-WLH\";s:11:\"description\";s:236:\"Monitors the SC wlhck channel: exactly eight ASCII alphanumeric characters. Historical WLH-CHANNEL-01 also covered wlh_sc; from this split, wlh_sc telemetry belongs to WLH-CHANNEL-02. Parameter shape alone does not establish compromise.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:7.5;s:4:\"tags\";a:4:{i:0;s:15:\"post-compromise\";i:1;s:23:\"implant-control-channel\";i:2;s:13:\"mass-campaign\";i:3;s:19:\"core-param-coverage\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:22:\"ARGS:/wlhck(?![\\s\\S])/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:20:\"~\\A[0-9A-Za-z]{8}\\z~\";}}}s:33:\"RULE-CAMPAIGN-SCPB-WLH-CHANNEL-02\";a:11:{s:3:\"cve\";s:26:\"CAMPAIGN-2026-W37-SCPB-WLH\";s:11:\"description\";s:212:\"Monitors the SC wlh_sc channel: exactly twelve ASCII alphanumeric characters. Split from historical WLH-CHANNEL-01 so each parameter keeps its observed length. Parameter shape alone does not establish compromise.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:7.5;s:4:\"tags\";a:4:{i:0;s:15:\"post-compromise\";i:1;s:23:\"implant-control-channel\";i:2;s:13:\"mass-campaign\";i:3;s:19:\"core-param-coverage\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:23:\"ARGS:/wlh_sc(?![\\s\\S])/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:21:\"~\\A[0-9A-Za-z]{12}\\z~\";}}}s:43:\"RULE-CAMPAIGN-SERVICE-WORKER-FETCH-PROBE-01\";a:11:{s:3:\"cve\";s:42:\"CAMPAIGN-2026-W37-SERVICE-WORKER-TELEMETRY\";s:11:\"description\";s:757:\"Telemetry-only sampler. Browsers send the request header\n\"Service-Worker: script\" on service-worker registration and on the periodic\nupdate fetch, so this rule records which WordPress-served URLs are being\nregistered as service workers. A rogue service worker gives an attacker\npersistent client-side MITM on every subsequent navigation, and the\nregistration URL is not otherwise recoverable from any Imunify telemetry\nstream today. Sampling is capped at 1 request in 200 because legitimate PWA\nplugins (SuperPWA, Webpushr, Firebase messaging, PWA for WP) register service\nworkers on 11,598 distinct domains per day; the header alone is not a\ncompromise signal, it is the collection surface that makes rogue registrations\nfindable. Never promoted to block.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:3:{i:0;s:9:\"telemetry\";i:1;s:14:\"service-worker\";i:2;s:23:\"client-side-persistence\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:30:\"REQUEST_HEADERS:Service-Worker\";s:4:\"type\";s:6:\"equals\";s:5:\"value\";s:6:\"script\";}i:1;a:2:{s:4:\"type\";s:13:\"probabilistic\";s:5:\"value\";s:5:\"0.005\";}}}s:38:\"RULE-CAMPAIGN-WP-EDITOR-AUTH-COOKIE-02\";a:12:{s:3:\"cve\";s:29:\"CAMPAIGN-2026-WP-EDITOR-ABUSE\";s:11:\"description\";s:100:\"Block WordPress core editor writes that select an administrator and create an authentication cookie.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:9;s:4:\"tags\";a:4:{i:0;s:26:\"authenticated-editor-abuse\";i:1;s:23:\"authentication-backdoor\";i:2;s:15:\"post-compromise\";i:3;s:25:\"wordpress-core-entrypoint\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:11:\"ajax_action\";s:22:\"edit-theme-plugin-file\";s:10:\"conditions\";a:3:{i:0;a:3:{s:4:\"name\";s:13:\"ARGS:/^file$/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:9:\"~\\.php$~i\";}i:1;a:3:{s:4:\"name\";s:15:\"ARGS:newcontent\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:18:\"~<\\?(?:php\\b|=)?~i\";}i:2;a:3:{s:4:\"name\";s:15:\"ARGS:newcontent\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:846:\"~(?is)(?=.*\\$[A-Za-z_]\\w*(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*=(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\bget_users(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\((?=[^;]{0,512}\\b(?:role|roles)\\b[^;]{0,512}\\badministrator\\b))(?=.*\\bwp_set_current_user(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\((?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\$[A-Za-z_]\\w*(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*(?:\\[\\s*\\d+\\s*\\])?(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*->(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*ID\\b)(?=.*\\bwp_set_auth_cookie(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\((?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\$[A-Za-z_]\\w*(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*(?:\\[\\s*\\d+\\s*\\])?(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*->(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*ID\\b)~\";}}}s:43:\"RULE-CAMPAIGN-WP-EDITOR-REQUEST-CALLABLE-01\";a:12:{s:3:\"cve\";s:29:\"CAMPAIGN-2026-WP-EDITOR-ABUSE\";s:11:\"description\";s:111:\"Block WordPress core editor writes that extract request variables and invoke an attacker-selected PHP callable.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:9;s:4:\"tags\";a:4:{i:0;s:26:\"authenticated-editor-abuse\";i:1;s:12:\"php-backdoor\";i:2;s:15:\"post-compromise\";i:3;s:25:\"wordpress-core-entrypoint\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:11:\"ajax_action\";s:22:\"edit-theme-plugin-file\";s:10:\"conditions\";a:3:{i:0;a:3:{s:4:\"name\";s:13:\"ARGS:/^file$/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:9:\"~\\.php$~i\";}i:1;a:3:{s:4:\"name\";s:15:\"ARGS:newcontent\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:18:\"~<\\?(?:php\\b|=)?~i\";}i:2;a:3:{s:4:\"name\";s:15:\"ARGS:newcontent\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:347:\"~(?is)(?=.*\\bextract(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\((?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\$_(?:REQUEST|GET|POST)\\b)(?=.*(?:\\$[A-Za-z_]\\w*|\\bcall_user_func|\\$_(?:REQUEST|GET|POST)\\s*\\[\\s*[\\x22\\x27][A-Za-z_]\\w*[\\x22\\x27]\\s*\\]|\\$\\{\\s*[\\x22\\x27][A-Za-z_]\\w*[\\x22\\x27]\\s*\\})(?:\\s|/\\*.*?\\*/|(?:\\/\\/|#)[^\\r\\n]*(?:\\r?\\n|$))*\\()~\";}}}s:36:\"RULE-CAMPAIGN-WPACCT-ADMIN-CREATE-01\";a:12:{s:3:\"cve\";s:27:\"CAMPAIGN-WPACCT-ADMIN-GRANT\";s:11:\"description\";s:295:\"Observes creation of an administrator through wp-admin/user-new.php, whatever the username. Backdoor accounts are not always named after a known family; every administrator grant is the evidence needed to trace a compromised account to the accounts it created (ModSec 77433249 tracks all roles).\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:3:{i:0;s:7:\"monitor\";i:1;s:15:\"privilege-grant\";i:2;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:3:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:36:\"~/wp-admin/user-new\\.php(?:[?#]|$)~i\";}i:1;a:3:{s:4:\"name\";s:11:\"ARGS:action\";s:4:\"type\";s:6:\"equals\";s:5:\"value\";s:10:\"createuser\";}i:2;a:3:{s:4:\"name\";s:9:\"ARGS:role\";s:4:\"type\";s:6:\"equals\";s:5:\"value\";s:13:\"administrator\";}}}s:30:\"RULE-CAMPAIGN-WPACCT-CREATE-01\";a:12:{s:3:\"cve\";s:30:\"CAMPAIGN-WPACCT-KNOWN-BACKDOOR\";s:11:\"description\";s:303:\"Observes a request that submits a known backdoor username as user_login or username on any path (user-new.php, REST /wp/v2/users, registration, plugin AJAX handlers, lost-password). Includes the SC framework shapes and bd_<6 base36>; bd_ also fits some real usernames, which is acceptable for a monitor.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:25:\"post-compromise-signature\";i:2;s:11:\"rogue-admin\";i:3;s:22:\"known-backdoor-account\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:32:\"ARGS:/^(?:user_login|username)$/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:347:\"~^(?:admin\\d?backup|wpadminerlzp|adminlin|admin_lin|administratoir|sendsdesr|adminzaxhh34|rxrhack1337|siteseomanager461|admlnlx|serverhostx|adm1n1str4t0r|adm1njabarnews|adm1n_2411|sys_maint|nxploited\\w{0,64}|usr_[a-f0-9]{6,10}|sys_monitor[a-f0-9]{8}|bd_[0-9a-z]{6}|administrator_[0-9a-f]{6}|adm_[0-9a-f]{10}|admin_[0-9a-f]{10}|backup_[0-9]{10})$~i\";}}}s:30:\"RULE-CAMPAIGN-WPACCT-CREATE-02\";a:12:{s:3:\"cve\";s:30:\"CAMPAIGN-WPACCT-KNOWN-BACKDOOR\";s:11:\"description\";s:135:\"Observes a request that submits a known backdoor email address as email or user_email (account creation, registration, profile change).\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:25:\"post-compromise-signature\";i:2;s:11:\"rogue-admin\";i:3;s:22:\"known-backdoor-account\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:29:\"ARGS:/^(?:email|user_email)$/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:127:\"~^(?:admin\\d?backup@wordpress\\.org|wpadmin@volovmart\\.ru|sys@localhost\\.local|sys_maint@local\\.com|wordpresupport@\\S{1,253})$~i\";}}}s:29:\"RULE-CAMPAIGN-WPACCT-LOGIN-01\";a:12:{s:3:\"cve\";s:30:\"CAMPAIGN-WPACCT-KNOWN-BACKDOOR\";s:11:\"description\";s:368:\"Observes wp-login.php sign-in attempts with a per-site generated backdoor account (sys_monitor<8 hex>, usr_<6-10 hex>) or a known backdoor email address. Generated names cannot be guessed across sites, so an attempt points at a site where the account exists. SC framework names are covered by RULE-CAMPAIGN-SC-ROGUE-ADMIN-LOGIN-01; fixed names are sampled by LOGIN-02.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:25:\"post-compromise-signature\";i:2;s:11:\"rogue-admin\";i:3;s:22:\"known-backdoor-account\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:27:\"~/wp-login\\.php(?:[?#]|$)~i\";}i:1;a:3:{s:4:\"name\";s:8:\"ARGS:log\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:169:\"~^(?:usr_[a-f0-9]{6,10}|sys_monitor[a-f0-9]{8}|admin\\d?backup@wordpress\\.org|wpadmin@volovmart\\.ru|sys@localhost\\.local|sys_maint@local\\.com|wordpresupport@\\S{1,253})$~i\";}}}s:29:\"RULE-CAMPAIGN-WPACCT-LOGIN-02\";a:12:{s:3:\"cve\";s:30:\"CAMPAIGN-WPACCT-KNOWN-BACKDOOR\";s:11:\"description\";s:224:\"Samples 1% of wp-login.php sign-in attempts with a fixed-name backdoor account (sys_maint, admin<N>backup, wpadminerlzp, administratoir, adminlin and the rest of the ModSec 77896900 list). These names are sprayed fleet-wide.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:22:\"known-backdoor-account\";i:2;s:16:\"credential-spray\";i:3;s:19:\"sampled-observation\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:3:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:27:\"~/wp-login\\.php(?:[?#]|$)~i\";}i:1;a:3:{s:4:\"name\";s:8:\"ARGS:log\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:211:\"~^(?:admin\\d?backup|wpadminerlzp|adminlin|admin_lin|administratoir|sendsdesr|adminzaxhh34|rxrhack1337|siteseomanager461|admlnlx|serverhostx|adm1n1str4t0r|adm1njabarnews|adm1n_2411|sys_maint|nxploited\\w{0,64})$~i\";}i:2;a:2:{s:4:\"type\";s:13:\"probabilistic\";s:5:\"value\";s:4:\"0.01\";}}}s:31:\"RULE-CAMPAIGN-WPACCT-PROMOTE-01\";a:12:{s:3:\"cve\";s:27:\"CAMPAIGN-WPACCT-ADMIN-GRANT\";s:11:\"description\";s:219:\"Observes wp-admin/user-edit.php saves that set the role to administrator (ModSec 77488182). The form resubmits the current role, so saving an existing administrator\'s profile also matches; correlate with the prior role.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:3:{i:0;s:7:\"monitor\";i:1;s:15:\"privilege-grant\";i:2;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:37:\"~/wp-admin/user-edit\\.php(?:[?#]|$)~i\";}i:1;a:3:{s:4:\"name\";s:9:\"ARGS:role\";s:4:\"type\";s:6:\"equals\";s:5:\"value\";s:13:\"administrator\";}}}s:31:\"RULE-CAMPAIGN-WPACCT-PROMOTE-02\";a:11:{s:3:\"cve\";s:27:\"CAMPAIGN-WPACCT-ADMIN-GRANT\";s:11:\"description\";s:188:\"Observes the wp-admin/users.php bulk \"Change role to\" action granting administrator (new_role or new_role2), which ModSec does not track. The list form submits by GET, so no method is set.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:3:{i:0;s:7:\"monitor\";i:1;s:15:\"privilege-grant\";i:2;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:33:\"~/wp-admin/users\\.php(?:[?#]|$)~i\";}i:1;a:3:{s:4:\"name\";s:19:\"ARGS:/^new_role2?$/\";s:4:\"type\";s:6:\"equals\";s:5:\"value\";s:13:\"administrator\";}}}s:33:\"RULE-CAMPAIGN-WPACCT-REST-ROLE-01\";a:12:{s:3:\"cve\";s:27:\"CAMPAIGN-WPACCT-ADMIN-GRANT\";s:11:\"description\";s:220:\"Observes REST user creation or update (/wp/v2/users, /wp/v2/users/<id>, pretty or ?rest_route= form) that assigns the administrator role, which ModSec does not track. GET listings filtered by role are excluded by method.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:3:{i:0;s:7:\"monitor\";i:1;s:15:\"privilege-grant\";i:2;s:21:\"infection-unconfirmed\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:4:\"POST\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:115:\"~(?:/wp-json|[?&]rest_route=)(?:/|%2F)wp(?:/|%2F)v2(?:/|%2F)users(?:(?:/|%2F)(?:[0-9]+|me))?(?:/|%2F)?(?:[?#&]|$)~i\";}i:1;a:3:{s:4:\"name\";s:15:\"ARGS:/^roles?$/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:18:\"~^administrator$~i\";}}}s:31:\"RULE-CAMPAIGN-WPACCT-SESSION-01\";a:11:{s:3:\"cve\";s:30:\"CAMPAIGN-WPACCT-KNOWN-BACKDOOR\";s:11:\"description\";s:319:\"Observes requests carrying a WordPress logged-in cookie that names a known backdoor account (the named and hex-suffixed families above plus the SC framework shapes administrator_<6 hex>, adm_<10 hex>, admin_<10 hex>, backup_<10 digits>). A live session for such an account means the operator is already inside the site.\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:1;s:4:\"tags\";a:4:{i:0;s:7:\"monitor\";i:1;s:25:\"post-compromise-signature\";i:2;s:11:\"rogue-admin\";i:3;s:22:\"known-backdoor-account\";}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:22:\"REQUEST_HEADERS:Cookie\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:382:\"~(?:^|;)\\s*wordpress_logged_in_[^=;]{1,64}=(?:admin\\d?backup|wpadminerlzp|adminlin|admin_lin|administratoir|sendsdesr|adminzaxhh34|rxrhack1337|siteseomanager461|admlnlx|serverhostx|adm1n1str4t0r|adm1njabarnews|adm1n_2411|sys_maint|nxploited\\w{0,64}|usr_[a-f0-9]{6,10}|sys_monitor[a-f0-9]{8}|administrator_[0-9a-f]{6}|adm_[0-9a-f]{10}|admin_[0-9a-f]{10}|backup_[0-9]{10})(?:\\||%7C)~i\";}}}s:38:\"RULE-CAMPAIGN-WPCONFIG-BACKUP-EXFIL-01\";a:11:{s:3:\"cve\";s:30:\"CAMPAIGN-WPCONFIG-BACKUP-EXFIL\";s:11:\"description\";s:1030:\"Block credential-harvesting recon for wp-config.php derivatives â editor\nswap files (.swp/.swo/.un~/~), operator backups (.bak/.old/.save/.orig),\nand archive/rename artefacts (.zip/.txt/.1/.copy).  WordPress core ships\nexactly one wp-config.php and never a suffixed sibling, so a request for\n`wp-config.php<suffix>` is attacker traffic by construction â the same\nzero-FP-floor reasoning as RULE-CAMPAIGN-MAINT-INDEX-01.  A hit that\nreturns 200 leaks DB credentials and AUTH_KEY salts verbatim.\n\nEvidence (ClickHouse `incident`, full day 2026-08-20, `plugin_id=\'modsec\'`):\n2,154,801 matching requests across 32,887 distinct servers and 2,106\ndistinct URI variants.  Of those, 1,282,803 (59.5%) were NOT denied by any\nexisting rule â this rule closes that pass-through gap.  100% of matching\nrows are `modsec`, i.e. server-side observations that the behaviour exists\nat scale; this is not a measurement of WP-engine coverage.  The surface\ncarries no wp-rules coverage today: `wp-config` appears 0 times in\ninitial-rules.yaml.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:7;s:4:\"tags\";a:5:{i:0;s:19:\"credential-exposure\";i:1;s:17:\"config-disclosure\";i:2;s:5:\"recon\";i:3;s:15:\"unauthenticated\";i:4;s:13:\"zero-fp-floor\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:3:\">=0\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:35:\"~^[^?#]*/\\.?wp-config\\.php[^/?#]+~i\";}}}s:24:\"RULE-CAMPAIGN-WPMATES-01\";a:12:{s:3:\"cve\";s:19:\"CAMPAIGN-WPMATES-01\";s:11:\"description\";s:441:\"Blocks requests to /wp-mates.php, a documented planted-backdoor filename\nnot present in WordPress core or any tracked legitimate plugin or theme\ndistribution. Any HTTP request to this path is a post-compromise callback\nprobe from a threat actor confirming the backdoor remains reachable. The\nfile must be removed from the filesystem and admin credentials rotated;\nthis rule blocks the probe but does not remediate the underlying\ncompromise.\n\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:9;s:4:\"tags\";a:5:{i:0;s:21:\"post-compromise-probe\";i:1;s:22:\"dropper-survival-check\";i:2;s:27:\"filesystem-planted-backdoor\";i:3;s:21:\"core-fs-path-coverage\";i:4;s:17:\"wp-mates-backdoor\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:13:\"<=999.999.999\";s:6:\"method\";s:3:\"GET\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:23:\"~^/wp-mates\\.php($|\\?)~\";}}}s:22:\"RULE-CVE-2025-14732-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2025-14732\";s:11:\"description\";s:69:\"Elementor <=3.35.5 stored XSS via REST API meta _elementor_data field\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2025-14732\";s:8:\"severity\";d:6.4;s:4:\"tags\";a:3:{i:0;s:10:\"stored-xss\";i:1;s:8:\"rest-api\";i:2;s:13:\"authenticated\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:9:\"elementor\";s:8:\"versions\";s:8:\"<=3.35.5\";s:6:\"action\";s:13:\"rest_api_init\";s:10:\"conditions\";a:3:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:66:\"~(?:^/wp-json|(?:^|&|\\?)rest_route=)/wp/v2/posts/[0-9]+(?:[/?]|$)~\";}i:1;a:3:{s:4:\"name\";s:26:\"ARGS:meta[_elementor_data]\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:78:\"~(?:<script[\\s/>]|on(?:error|load|click|mouseover|focus)\\s*=|javascript\\s*:)~i\";}i:2;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:15:\"unfiltered_html\";}}}s:21:\"RULE-CVE-2026-1206-01\";a:11:{s:3:\"cve\";s:13:\"CVE-2026-1206\";s:11:\"description\";s:195:\"Elementor <=3.35.7 contributor+ sensitive information disclosure via get_template_data sub-action on elementor_ajax â authorization logic bypass (CWE-639) allows reading private/draft templates\";s:8:\"cve_link\";s:46:\"https://nvd.nist.gov/vuln/detail/CVE-2026-1206\";s:8:\"severity\";d:4.3;s:4:\"tags\";a:3:{i:0;s:21:\"broken-access-control\";i:1;s:22:\"information-disclosure\";i:2;s:4:\"idor\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:9:\"elementor\";s:8:\"versions\";s:8:\"<=3.35.7\";s:11:\"ajax_action\";s:14:\"elementor_ajax\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:12:\"ARGS:actions\";s:4:\"type\";s:8:\"contains\";s:5:\"value\";s:17:\"get_template_data\";}i:1;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:17:\"edit_others_posts\";}}}s:22:\"RULE-CVE-2026-18978-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-18978\";s:11:\"description\";s:135:\"LiteSpeed Cache <=7.8.1 unauthenticated stored XSS via numeric-entity (decimal or hex) encoded data-settings payload in comment content\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-18978\";s:8:\"severity\";d:7.2;s:4:\"tags\";a:4:{i:0;s:3:\"xss\";i:1;s:10:\"stored-xss\";i:2;s:15:\"unauthenticated\";i:3;s:15:\"comment-content\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:15:\"litespeed-cache\";s:8:\"versions\";s:7:\"<=7.8.1\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:26:\"~^/wp-comments-post\\.php~i\";}i:1;a:3:{s:4:\"name\";s:12:\"ARGS:comment\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:78:\"~data-settings\\s*=\\s*[\"\']?[^\"\'>]*&#(?:0*(?:34|39|60|62)|x0*(?:22|27|3c|3e));~i\";}}}s:22:\"RULE-CVE-2026-22440-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-22440\";s:11:\"description\";s:0:\"\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:7.1;s:4:\"tags\";a:0:{}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:7:\">=1.0.0\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:60:\"~^(?:/(?:index\\.php)?(?:\\?|$)|/(?:archive|blog)(?:/|\\?|$))~i\";}i:1;a:3:{s:4:\"name\";s:25:\"ARGS:/^(?:s|q|redirect)$/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:95:\"~(?:<script[\\s/>]|on(?:error|load|click|mouse(?:over|down|up)|focus|blur)\\s*=|javascript\\s*:)~i\";}}}s:22:\"RULE-CVE-2026-28048-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-28048\";s:11:\"description\";s:84:\"FlashMart Theme <=2.0.15 unauthenticated local file inclusion via template parameter\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-28048\";s:8:\"severity\";d:8.1;s:4:\"tags\";a:3:{i:0;s:20:\"local-file-inclusion\";i:1;s:14:\"path-traversal\";i:2;s:15:\"unauthenticated\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:5:\">=5.0\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:18:\"ARGS:flashtemplate\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:59:\"~(?:\\.\\.[\\/]|wp-config\\.php|/etc/passwd|\\.htaccess|\\.env)~i\";}}}s:21:\"RULE-CVE-2026-3129-01\";a:11:{s:3:\"cve\";s:13:\"CVE-2026-3129\";s:11:\"description\";s:215:\"LiteSpeed Cache <=7.7 stored XSS via crafted img tag attributes bypassing Lazy Load Images width/height stripping regex; blocks malicious img event-handler payloads submitted in post content by Author-level accounts\";s:8:\"cve_link\";s:46:\"https://nvd.nist.gov/vuln/detail/CVE-2026-3129\";s:8:\"severity\";d:6.4;s:4:\"tags\";a:4:{i:0;s:3:\"xss\";i:1;s:6:\"stored\";i:2;s:13:\"authenticated\";i:3;s:17:\"content-injection\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:15:\"litespeed-cache\";s:8:\"versions\";s:5:\"<=7.7\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:22:\"~^/wp-admin/post\\.php~\";}i:1;a:3:{s:4:\"name\";s:17:\"ARGS:post_content\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:43:\"~<img\\b(?:[^>]|\\r|\\n)*\\bon[a-z]{3,20}\\s*=~i\";}}}s:21:\"RULE-CVE-2026-3129-02\";a:11:{s:3:\"cve\";s:13:\"CVE-2026-3129\";s:11:\"description\";s:215:\"LiteSpeed Cache <=7.7 stored XSS via crafted img tag attributes bypassing Lazy Load Images width/height stripping regex; blocks malicious img event-handler payloads submitted in post content by Author-level accounts\";s:8:\"cve_link\";s:46:\"https://nvd.nist.gov/vuln/detail/CVE-2026-3129\";s:8:\"severity\";d:6.4;s:4:\"tags\";a:4:{i:0;s:3:\"xss\";i:1;s:6:\"stored\";i:2;s:13:\"authenticated\";i:3;s:17:\"content-injection\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:15:\"litespeed-cache\";s:8:\"versions\";s:5:\"<=7.7\";s:6:\"action\";s:13:\"rest_api_init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:69:\"~(?:^/wp-json|(?:^|&|\\?)rest_route=)/wp/v2/(?:posts|pages)(/|\\?|&|$)~\";}i:1;a:3:{s:4:\"name\";s:12:\"ARGS:content\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:43:\"~<img\\b(?:[^>]|\\r|\\n)*\\bon[a-z]{3,20}\\s*=~i\";}}}s:21:\"RULE-CVE-2026-3534-01\";a:11:{s:3:\"cve\";s:13:\"CVE-2026-3534\";s:11:\"description\";s:171:\"Astra theme <=4.12.3 stored XSS via ast-page-background-meta post meta field due to missing input sanitization and output escaping in astra_get_responsive_background_obj()\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:5;s:4:\"tags\";a:0:{}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:5:\"theme\";s:4:\"slug\";s:5:\"astra\";s:8:\"versions\";s:8:\"<=4.12.3\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:23:\"~^/wp-admin/post\\.php~i\";}i:1;a:3:{s:4:\"name\";s:41:\"ARGS:ast-page-background-meta[/.+/][/.+/]\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:116:\"~(?:<script[\\s/>]|on(?:error|load|mouseover|click|focus|blur)\\s*=|javascript\\s*:|</style|expression\\s*\\(|[\"\']\\s*>)~i\";}}}s:21:\"RULE-CVE-2026-3534-02\";a:11:{s:3:\"cve\";s:13:\"CVE-2026-3534\";s:11:\"description\";s:174:\"Astra theme <=4.12.3 stored XSS via ast-content-background-meta post meta field due to missing input sanitization and output escaping in astra_get_responsive_background_obj()\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:5;s:4:\"tags\";a:0:{}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:5:\"theme\";s:4:\"slug\";s:5:\"astra\";s:8:\"versions\";s:8:\"<=4.12.3\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:23:\"~^/wp-admin/post\\.php~i\";}i:1;a:3:{s:4:\"name\";s:44:\"ARGS:ast-content-background-meta[/.+/][/.+/]\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:116:\"~(?:<script[\\s/>]|on(?:error|load|mouseover|click|focus|blur)\\s*=|javascript\\s*:|</style|expression\\s*\\(|[\"\']\\s*>)~i\";}}}s:22:\"RULE-CVE-2026-40764-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-40764\";s:11:\"description\";s:93:\"WPForms Lite <=1.10.0.2 CSRF on save_tags AJAX handler â missing nonce and capability check\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-40764\";s:8:\"severity\";d:8.1;s:4:\"tags\";a:3:{i:0;s:4:\"csrf\";i:1;s:21:\"missing-authorization\";i:2;s:21:\"broken-access-control\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:12:\"wpforms-lite\";s:8:\"versions\";s:10:\"<=1.10.0.2\";s:11:\"ajax_action\";s:38:\"wpforms_admin_forms_overview_save_tags\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:14:\"manage_options\";}}}s:22:\"RULE-CVE-2026-40764-02\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-40764\";s:11:\"description\";s:95:\"WPForms Lite <=1.10.0.2 CSRF on delete_tags AJAX handler â missing nonce and capability check\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-40764\";s:8:\"severity\";d:8.1;s:4:\"tags\";a:3:{i:0;s:4:\"csrf\";i:1;s:21:\"missing-authorization\";i:2;s:21:\"broken-access-control\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:12:\"wpforms-lite\";s:8:\"versions\";s:10:\"<=1.10.0.2\";s:11:\"ajax_action\";s:40:\"wpforms_admin_forms_overview_delete_tags\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:14:\"manage_options\";}}}s:22:\"RULE-CVE-2026-40764-03\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-40764\";s:11:\"description\";s:106:\"WPForms Lite <=1.10.0.2 CSRF on update_lite_connect_enabled_setting â missing nonce and capability check\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-40764\";s:8:\"severity\";d:8.1;s:4:\"tags\";a:3:{i:0;s:4:\"csrf\";i:1;s:21:\"missing-authorization\";i:2;s:21:\"broken-access-control\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:12:\"wpforms-lite\";s:8:\"versions\";s:10:\"<=1.10.0.2\";s:11:\"ajax_action\";s:43:\"wpforms_update_lite_connect_enabled_setting\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:14:\"manage_options\";}}}s:22:\"RULE-CVE-2026-40764-04\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-40764\";s:11:\"description\";s:92:\"WPForms Lite <=1.10.0.2 CSRF on lite_connect_finalize â missing nonce and capability check\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-40764\";s:8:\"severity\";d:8.1;s:4:\"tags\";a:3:{i:0;s:4:\"csrf\";i:1;s:21:\"missing-authorization\";i:2;s:21:\"broken-access-control\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:12:\"wpforms-lite\";s:8:\"versions\";s:10:\"<=1.10.0.2\";s:11:\"ajax_action\";s:29:\"wpforms_lite_connect_finalize\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:14:\"manage_options\";}}}s:22:\"RULE-CVE-2026-40764-05\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-40764\";s:11:\"description\";s:86:\"WPForms Lite <=1.10.0.2 missing capability check on lite_settings_upgrade AJAX handler\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-40764\";s:8:\"severity\";d:8.1;s:4:\"tags\";a:3:{i:0;s:4:\"csrf\";i:1;s:21:\"missing-authorization\";i:2;s:21:\"broken-access-control\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:12:\"wpforms-lite\";s:8:\"versions\";s:10:\"<=1.10.0.2\";s:11:\"ajax_action\";s:29:\"wpforms_lite_settings_upgrade\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:14:\"manage_options\";}}}s:22:\"RULE-CVE-2026-48835-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-48835\";s:11:\"description\";s:102:\"WPForms Lite <=1.10.0.4 unauthenticated broken access control via wpforms_connect_process AJAX handler\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:7.5;s:4:\"tags\";a:0:{}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:12:\"wpforms-lite\";s:8:\"versions\";s:10:\"<=1.10.0.4\";s:11:\"ajax_action\";s:23:\"wpforms_connect_process\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:14:\"manage_options\";}}}s:22:\"RULE-CVE-2026-62062-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-62062\";s:11:\"description\";s:130:\"Elementor Website Builder <=4.3.1 CSRF via admin_post_elementor_site_clear_cache missing capability check on cache-clearing action\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-62062\";s:8:\"severity\";d:8.8;s:4:\"tags\";a:4:{i:0;s:4:\"csrf\";i:1;s:21:\"missing-authorization\";i:2;s:12:\"state-change\";i:3;s:13:\"authenticated\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:9:\"elementor\";s:8:\"versions\";s:7:\"<=4.3.1\";s:6:\"action\";s:37:\"admin_post_elementor_site_clear_cache\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:18:\"missing_capability\";s:5:\"value\";s:14:\"manage_options\";}}}s:22:\"RULE-CVE-2026-77782-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-77782\";s:11:\"description\";s:250:\"Rank Math SEO <1.0.277.1 discloses password-protected post content via publicly generated SEO metadata reachable through the headless getHead REST endpoint; endpoint-scoping only, no exploit-specific payload signal is groundable from current evidence\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-77782\";s:8:\"severity\";d:5.3;s:4:\"tags\";a:3:{i:0;s:22:\"information-disclosure\";i:1;s:15:\"unauthenticated\";i:2;s:18:\"needs-human-review\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:16:\"seo-by-rank-math\";s:8:\"versions\";s:10:\"<1.0.277.1\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:21:\"~/getHead(?:[/?]|$)~i\";}i:1;a:2:{s:4:\"name\";s:8:\"ARGS:url\";s:4:\"type\";s:6:\"exists\";}}}s:22:\"RULE-CVE-2026-84761-01\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-84761\";s:11:\"description\";s:133:\"LiteSpeed Cache <=7.9 unauthenticated SSRF via err_domains REST callback main_domain/alias parameters (is_from_cloud IP check bypass)\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-84761\";s:8:\"severity\";d:7.2;s:4:\"tags\";a:4:{i:0;s:4:\"ssrf\";i:1;s:15:\"unauthenticated\";i:2;s:8:\"rest-api\";i:3;s:21:\"missing-authorization\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:15:\"litespeed-cache\";s:8:\"versions\";s:5:\"<=7.9\";s:6:\"action\";s:13:\"rest_api_init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:11:\"REQUEST_URI\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:90:\"~(?:^(?:/[^?]*)?/wp-json|(?:^|[?&])rest_route=)/litespeed/v3/err_domains[\\\\/]*(?:[?&]|$)~i\";}i:1;a:3:{s:4:\"name\";s:24:\"ARGS:/main_domain|alias/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:309:\"~(?:^(?:file|gopher|dict|ftp|sftp|ldap|php|expect|jar|s3|glusterfs)://|^(?:https?://)?(?:127\\.0\\.0\\.1|localhost|0\\.0\\.0\\.0|10\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}|172\\.(?:1[6-9]|2[0-9]|3[01])\\.[0-9]{1,3}\\.[0-9]{1,3}|192\\.168\\.[0-9]{1,3}\\.[0-9]{1,3}|169\\.254\\.[0-9]{1,3}\\.[0-9]{1,3}|\\[::1\\]|\\[fd[0-9a-f]{2}:))~i\";}}}s:22:\"RULE-CVE-2026-84761-02\";a:11:{s:3:\"cve\";s:14:\"CVE-2026-84761\";s:11:\"description\";s:133:\"LiteSpeed Cache <=7.9 unauthenticated SSRF via err_domains REST callback main_domain/alias parameters (is_from_cloud IP check bypass)\";s:8:\"cve_link\";s:47:\"https://nvd.nist.gov/vuln/detail/CVE-2026-84761\";s:8:\"severity\";d:7.2;s:4:\"tags\";a:4:{i:0;s:4:\"ssrf\";i:1;s:15:\"unauthenticated\";i:2;s:8:\"rest-api\";i:3;s:21:\"missing-authorization\";}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:6:\"plugin\";s:4:\"slug\";s:15:\"litespeed-cache\";s:8:\"versions\";s:5:\"<=7.9\";s:6:\"action\";s:13:\"rest_api_init\";s:10:\"conditions\";a:2:{i:0;a:3:{s:4:\"name\";s:15:\"ARGS:rest_route\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:36:\"~^/litespeed/v3/err_domains[\\\\/]*$~i\";}i:1;a:3:{s:4:\"name\";s:24:\"ARGS:/main_domain|alias/\";s:4:\"type\";s:5:\"regex\";s:5:\"value\";s:309:\"~(?:^(?:file|gopher|dict|ftp|sftp|ldap|php|expect|jar|s3|glusterfs)://|^(?:https?://)?(?:127\\.0\\.0\\.1|localhost|0\\.0\\.0\\.0|10\\.[0-9]{1,3}\\.[0-9]{1,3}\\.[0-9]{1,3}|172\\.(?:1[6-9]|2[0-9]|3[01])\\.[0-9]{1,3}\\.[0-9]{1,3}|192\\.168\\.[0-9]{1,3}\\.[0-9]{1,3}|169\\.254\\.[0-9]{1,3}\\.[0-9]{1,3}|\\[::1\\]|\\[fd[0-9a-f]{2}:))~i\";}}}s:14:\"TEST-HEARTBEAT\";a:11:{s:3:\"cve\";s:14:\"TEST-HEARTBEAT\";s:11:\"description\";s:0:\"\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:0.1;s:4:\"tags\";a:0:{}s:4:\"mode\";s:4:\"pass\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:7:\">=1.0.0\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:2:{s:4:\"type\";s:13:\"probabilistic\";s:5:\"value\";s:6:\"0.0002\";}}}s:9:\"TEST-RULE\";a:11:{s:3:\"cve\";s:8:\"TEST-CVE\";s:11:\"description\";s:0:\"\";s:8:\"cve_link\";s:0:\"\";s:8:\"severity\";d:2;s:4:\"tags\";a:0:{}s:4:\"mode\";s:5:\"block\";s:6:\"target\";s:4:\"core\";s:4:\"slug\";s:0:\"\";s:8:\"versions\";s:7:\">=1.0.0\";s:6:\"action\";s:4:\"init\";s:10:\"conditions\";a:1:{i:0;a:3:{s:4:\"name\";s:14:\"ARGS:test-rule\";s:4:\"type\";s:6:\"equals\";s:5:\"value\";s:36:\"b3d45e60-53a5-4959-b911-5178baaef7ac\";}}}}}', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`)
            [1] => 0.0054440498352051
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/imunify-security/imunify-security.php'), CloudLinux\Imunify\App\Plugin->init, CloudLinux\Imunify\App\Plugin->coreSetup, CloudLinux\Imunify\App\Defender\RuleProvider->loadRules, set_transient, add_option
            [3] => 1791651095.3392
            [4] => Array
                (
                )

        )

    [16] => Array
        (
            [0] => SELECT option_name, option_value FROM wpd9_options WHERE option_name IN ('_transient_imunify_disabled_rules','_transient_timeout_imunify_disabled_rules')
            [1] => 0.00048112869262695
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/imunify-security/imunify-security.php'), CloudLinux\Imunify\App\Plugin->init, CloudLinux\Imunify\App\Plugin->coreSetup, CloudLinux\Imunify\App\Defender\Defender->processRules, CloudLinux\Imunify\App\Defender\Defender->isRuleDisabled, CloudLinux\Imunify\App\Defender\DisabledRulesManager->isRuleDisabled, CloudLinux\Imunify\App\Defender\DisabledRulesManager->getDisabledRules, get_transient, wp_prime_option_caches
            [3] => 1791651095.3559
            [4] => Array
                (
                )

        )

    [17] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'rttpg_options' LIMIT 1
            [1] => 0.00039100646972656
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/the-post-grid/the-post-grid.php'), require_once('/plugins/the-post-grid/app/RtTpg.php'), rtTPG, RtTpg::getInstance, RtTpg->__construct, RtTpg->__init, RT\ThePostGrid\Controllers\BlocksController->__construct, get_option
            [3] => 1791651095.6133
            [4] => Array
                (
                )

        )

    [18] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'wp_debugging' LIMIT 1
            [1] => 0.00054597854614258
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include_once('/plugins/wp-debugging/wp-debugging.php'), Fragen\WP_Debugging\Bootstrap->__construct, get_site_option, get_network_option, get_option
            [3] => 1791651095.6257
            [4] => Array
                (
                )

        )

    [19] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'wpcode_settings' LIMIT 1
            [1] => 0.00021195411682129
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, WPCode_Auto_Insert->load_types, require_once('/plugins/insert-headers-and-footers/includes/auto-insert/class-wpcode-auto-insert-everywhere.php'), WPCode_Auto_Insert_Type->__construct, WPCode_Settings->get_option, WPCode_Settings->get_options, WPCode_Settings->load_options, get_option
            [3] => 1791651095.9506
            [4] => Array
                (
                )

        )

    [20] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'WPLANG' LIMIT 1
            [1] => 0.0068740844726562
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, STImporter\ST_Importer_Loader->load_textdomain, get_locale, get_option
            [3] => 1791651095.9613
            [4] => Array
                (
                )

        )

    [21] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'astra_sites_import_started' LIMIT 1
            [1] => 0.0002129077911377
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, astra_sites_setup, require_once('/plugins/astra-sites/inc/classes/class-astra-sites.php'), Astra_Sites::get_instance, Astra_Sites->__construct, Astra_Sites->includes, require_once('/plugins/astra-sites/inc/classes/class-astra-sites-error-handler.php'), Astra_Sites_Error_Handler::get_instance, Astra_Sites_Error_Handler->__construct, astra_sites_has_import_started, get_option
            [3] => 1791651095.9911
            [4] => Array
                (
                )

        )

    [22] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'astra-sites-force-sync' LIMIT 1
            [1] => 0.00021886825561523
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, astra_sites_setup, require_once('/plugins/astra-sites/inc/classes/class-astra-sites.php'), Astra_Sites::get_instance, Astra_Sites->__construct, Astra_Sites->includes, require_once('/plugins/astra-sites/inc/classes/class-astra-sites-importer.php'), Astra_Sites_Importer::get_instance, Astra_Sites_Importer->__construct, require_once('/plugins/astra-sites/inc/importers/batch-processing/class-astra-sites-batch-processing.php'), Astra_Sites_Batch_Processing::get_instance, Astra_Sites_Batch_Processing->__construct, Astra_Sites_Batch_Processing->check_is_force_sync, get_site_option, get_network_option, get_option
            [3] => 1791651096.0222
            [4] => Array
                (
                )

        )

    [23] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'wp_mail_smtp' LIMIT 1
            [1] => 0.00038695335388184
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, WPMailSMTP\Core->WPMailSMTP\{closure}, WPMailSMTP\OptimizedEmailSending->hooks, WPMailSMTP\OptimizedEmailSending::is_enabled, WPMailSMTP\Options::init, WPMailSMTP\Options->__construct, WPMailSMTP\Options->populate_options, get_option
            [3] => 1791651096.0971
            [4] => Array
                (
                )

        )

    [24] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'fresh_site' LIMIT 1
            [1] => 0.00028395652770996
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, WPForms\WPForms->objects, do_action('wpforms_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, WPForms\Integrations\Loader::get_instance, WPForms\Integrations\Loader->__construct, WPForms\Integrations\Loader->load_integration, WPForms\Integrations\DefaultContent\DefaultContent->allow_load, get_option
            [3] => 1791651096.1441
            [4] => Array
                (
                )

        )

    [25] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'wpforms_square_connections' LIMIT 1
            [1] => 0.0003659725189209
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, WPForms\WPForms->objects, do_action('wpforms_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, WPForms\Integrations\Loader::get_instance, WPForms\Integrations\Loader->__construct, WPForms\Integrations\Loader->load_integration, WPForms\Integrations\Square\Square->load, WPForms\Integrations\Square\Square->load_payments_actions, WPForms\Integrations\Square\Connection::get, get_option
            [3] => 1791651096.1748
            [4] => Array
                (
                )

        )

    [26] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'zip_ai_settings' LIMIT 1
            [1] => 0.00023198127746582
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, ZipAI\Loader->setup_classes, ZipAI\Classes\Module::migrate_options, ZipAI\Classes\Helper::get_admin_settings_option, get_option
            [3] => 1791651096.1964
            [4] => Array
                (
                )

        )

    [27] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'zip_ai_modules' LIMIT 1
            [1] => 0.00020694732666016
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('plugins_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, ZipAI\Loader->setup_classes, ZipAI\Classes\Module::is_enabled, ZipAI\Classes\Module::get_all_modules, ZipAI\Classes\Helper::get_admin_settings_option, get_option
            [3] => 1791651096.2083
            [4] => Array
                (
                )

        )

    [28] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'astra_partner_url_param' LIMIT 1
            [1] => 0.00029611587524414
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include('/themes/astra/functions.php'), astra_get_pro_url, get_option
            [3] => 1791651096.2458
            [4] => Array
                (
                )

        )

    [29] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'astra_admin_settings' LIMIT 1
            [1] => 0.00028300285339355
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), include('/themes/astra/functions.php'), require_once('/themes/astra/admin/includes/class-astra-api-init.php'), Astra_API_Init::get_instance, Astra_API_Init->__construct, get_option
            [3] => 1791651096.3203
            [4] => Array
                (
                )

        )

    [30] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'rank_math_google_oauth_tokens' LIMIT 1
            [1] => 0.00032591819763184
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('after_setup_theme'), WP_Hook->do_action, WP_Hook->apply_filters, RankMath\Module\Manager->load_modules, RankMath\Module\Manager->load_module, RankMath\Module\Manager->load_module_common, RankMath\Analytics\Analytics_Common->__construct, RankMath\Analytics\Analytics_Stats->__construct, RankMath\Helper::can_add_frontend_stats, RankMath\Google\Authentication::is_authorized, RankMath\Google\Authentication::tokens, get_option
            [3] => 1791651096.5281
            [4] => Array
                (
                )

        )

    [31] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'rank_math_google_analytic_profile' LIMIT 1
            [1] => 0.00025486946105957
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('after_setup_theme'), WP_Hook->do_action, WP_Hook->apply_filters, RankMath\Module\Manager->load_modules, RankMath\Module\Manager->load_module, RankMath\Module\Manager->load_module_common, RankMath\Analytics\Analytics_Common->__construct, RankMath\Analytics\Workflow\Jobs::get, RankMath\Analytics\Workflow\Jobs->hooks, RankMath\Google\Console::is_console_connected, get_option
            [3] => 1791651096.5353
            [4] => Array
                (
                )

        )

    [32] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'googlesitekit_first_admin' LIMIT 1
            [1] => 0.00029802322387695
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Google\Site_Kit\Plugin->Google\Site_Kit\{closure}, Google\Site_Kit\Core\Authentication\Authentication->register, Google\Site_Kit\Core\Storage\Setting->register, Google\Site_Kit\Core\Authentication\Owner_ID->get_default, Google\Site_Kit\Core\Storage\Options->get, get_option
            [3] => 1791651096.6673
            [4] => Array
                (
                )

        )

    [33] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'googlesitekit_active_modules' LIMIT 1
            [1] => 0.00027799606323242
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Google\Site_Kit\Plugin->Google\Site_Kit\{closure}, Google\Site_Kit\Core\Modules\Modules->register, Google\Site_Kit\Core\Modules\Modules->get_active_modules, Google\Site_Kit\Core\Modules\Modules->get_active_modules_option, Google\Site_Kit\Core\Storage\Options->get, get_option
            [3] => 1791651096.7085
            [4] => Array
                (
                )

        )

    [34] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'googlesitekit-active-modules' LIMIT 1
            [1] => 0.00019001960754395
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Google\Site_Kit\Plugin->Google\Site_Kit\{closure}, Google\Site_Kit\Core\Modules\Modules->register, Google\Site_Kit\Core\Modules\Modules->get_active_modules, Google\Site_Kit\Core\Modules\Modules->get_active_modules_option, Google\Site_Kit\Core\Storage\Options->get, get_option
            [3] => 1791651096.7089
            [4] => Array
                (
                )

        )

    [35] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'googlesitekit_dashboard_sharing' LIMIT 1
            [1] => 0.00044393539428711
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Google\Site_Kit\Plugin->Google\Site_Kit\{closure}, Google\Site_Kit\Core\Assets\Assets->register, current_user_can, user_can, WP_User->has_cap, map_meta_cap, apply_filters('map_meta_cap'), WP_Hook->apply_filters, Google\Site_Kit\Core\Permissions\Permissions->Google\Site_Kit\Core\Permissions\{closure}, Google\Site_Kit\Core\Permissions\Permissions->map_meta_capabilities, Google\Site_Kit\Core\Permissions\Permissions->check_view_splash_capability, Google\Site_Kit\Core\Permissions\Permissions->user_has_shared_role, Google\Site_Kit\Core\Modules\Module_Sharing_Settings->get_all_shared_roles, Google\Site_Kit\Core\Modules\Module_Sharing_Settings->get, Google\Site_Kit\Core\Storage\Setting->get, Google\Site_Kit\Core\Storage\Options->get, get_option
            [3] => 1791651096.7172
            [4] => Array
                (
                )

        )

    [36] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'googlesitekit_credentials' LIMIT 1
            [1] => 0.0002140998840332
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Google\Site_Kit\Plugin->Google\Site_Kit\{closure}, Google\Site_Kit\Core\Assets\Assets->register, current_user_can, user_can, WP_User->has_cap, map_meta_cap, apply_filters('map_meta_cap'), WP_Hook->apply_filters, Google\Site_Kit\Core\Permissions\Permissions->Google\Site_Kit\Core\Permissions\{closure}, Google\Site_Kit\Core\Permissions\Permissions->map_meta_capabilities, Google\Site_Kit\Core\Authentication\Authentication->is_setup_completed, Google\Site_Kit\Core\Authentication\Credentials->has, Google\Site_Kit\Core\Authentication\Credentials->get, Google\Site_Kit\Core\Storage\Encrypted_Options->get, Google\Site_Kit\Core\Storage\Options->get, get_option
            [3] => 1791651096.722
            [4] => Array
                (
                )

        )

    [37] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'googlesitekit_consent_mode' LIMIT 1
            [1] => 0.00024294853210449
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Google\Site_Kit\Plugin->Google\Site_Kit\{closure}, Google\Site_Kit\Core\Consent_Mode\Consent_Mode->register, Google\Site_Kit\Core\Consent_Mode\Consent_Mode_Settings->is_consent_mode_enabled, Google\Site_Kit\Core\Storage\Setting->get, Google\Site_Kit\Core\Storage\Options->get, get_option
            [3] => 1791651096.7595
            [4] => Array
                (
                )

        )

    [38] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_enable_inspector' LIMIT 1
            [1] => 0.00042080879211426
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Debug\Inspector->__construct, get_option
            [3] => 1791651096.7748
            [4] => Array
                (
                )

        )

    [39] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_icon_manager_needs_update' LIMIT 1
            [1] => 0.00025296211242676
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Icons_Manager->__construct, Elementor\Icons_Manager::is_migration_allowed, Elementor\Icons_Manager::get_needs_upgrade_option, get_option
            [3] => 1791651096.8258
            [4] => Array
                (
                )

        )

    [40] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_maintenance_mode_mode' LIMIT 1
            [1] => 0.00024914741516113
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Maintenance_Mode->__construct, Elementor\Maintenance_Mode::get, get_option
            [3] => 1791651096.8415
            [4] => Array
                (
                )

        )

    [41] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_safe_mode' LIMIT 1
            [1] => 0.00022983551025391
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Base\Module::instance, Elementor\Modules\SafeMode\Module->__construct, Elementor\Modules\SafeMode\Module->is_enabled, get_option
            [3] => 1791651096.853
            [4] => Array
                (
                )

        )

    [42] => Array
        (
            [0] => SELECT   wpd9_posts.ID
					 FROM wpd9_posts  INNER JOIN wpd9_postmeta ON ( wpd9_posts.ID = wpd9_postmeta.post_id )
					 WHERE 1=1  AND ( 
  ( wpd9_postmeta.meta_key = '_elementor_template_type' AND wpd9_postmeta.meta_value = 'landing-page' )
) AND wpd9_posts.post_type = 'e-landing-page' AND ((wpd9_posts.post_status <> 'trash' AND wpd9_posts.post_status <> 'auto-draft'))
					 GROUP BY wpd9_posts.ID
					 ORDER BY wpd9_posts.post_date DESC
					 LIMIT 0, 1
            [1] => 0.010303974151611
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Base\Module::instance, Elementor\Modules\LandingPages\Module->__construct, Elementor\Modules\LandingPages\Module->should_activate_landing_pages, Elementor\Modules\LandingPages\Module->has_landing_pages, WP_Query->__construct, WP_Query->query, WP_Query->get_posts
            [3] => 1791651096.8758
            [4] => Array
                (
                )

        )

    [43] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_pro_free_trial_popup' LIMIT 1
            [1] => 0.00046610832214355
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9025
            [4] => Array
                (
                )

        )

    [44] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-pages_panel' LIMIT 1
            [1] => 0.0003049373626709
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Base\Module::instance, Elementor\Modules\SiteNavigation\Module->__construct, Elementor\Modules\SiteNavigation\Module->register_pages_panel_experiment, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9215
            [4] => Array
                (
                )

        )

    [45] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-home_screen' LIMIT 1
            [1] => 0.00027704238891602
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9263
            [4] => Array
                (
                )

        )

    [46] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_atomic_elements' LIMIT 1
            [1] => 0.00023794174194336
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9372
            [4] => Array
                (
                )

        )

    [47] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_classes' LIMIT 1
            [1] => 0.00024294853210449
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Base\Module::instance, Elementor\Modules\GlobalClasses\Module->__construct, Elementor\Modules\GlobalClasses\Module->register_features, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9389
            [4] => Array
                (
                )

        )

    [48] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-global_classes_should_enforce_capabilities' LIMIT 1
            [1] => 0.00014805793762207
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Base\Module::instance, Elementor\Modules\GlobalClasses\Module->__construct, Elementor\Modules\GlobalClasses\Module->register_features, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9393
            [4] => Array
                (
                )

        )

    [49] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_variables' LIMIT 1
            [1] => 0.00017690658569336
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9406
            [4] => Array
                (
                )

        )

    [50] => Array
        (
            [0] => SELECT * FROM wpd9_posts WHERE ID = 435 LIMIT 1
            [1] => 0.00088906288146973
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Base\Module::instance, Elementor\Modules\Checklist\Module->__construct, Elementor\Modules\Checklist\Module->handle_checklist_visibility_with_kit, Elementor\Modules\Checklist\Module->should_switch_preferences_off, Elementor\Core\Isolation\Elementor_Adapter->is_active_kit_default, get_post, WP_Post::get_instance
            [3] => 1791651096.9457
            [4] => Array
                (
                )

        )

    [51] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_opt_in_v4_page' LIMIT 1
            [1] => 0.00025582313537598
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9557
            [4] => Array
                (
                )

        )

    [52] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_opt_in_v4' LIMIT 1
            [1] => 0.00020599365234375
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Base\Module::instance, Elementor\Modules\AtomicOptIn\Module->__construct, Elementor\Modules\AtomicWidgets\OptIn\Opt_In->init, Elementor\Modules\AtomicWidgets\OptIn\Opt_In->register_feature, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9578
            [4] => Array
                (
                )

        )

    [53] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_components' LIMIT 1
            [1] => 0.00019407272338867
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9611
            [4] => Array
                (
                )

        )

    [54] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_interactions' LIMIT 1
            [1] => 0.00027298927307129
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9627
            [4] => Array
                (
                )

        )

    [55] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_experiment-e_editor_one' LIMIT 1
            [1] => 0.00016593933105469
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Modules_Manager->__construct, Elementor\Core\Experiments\Manager->add_feature, Elementor\Core\Experiments\Manager->get_saved_feature_state, get_option
            [3] => 1791651096.9641
            [4] => Array
                (
                )

        )

    [56] => Array
        (
            [0] => 
			SELECT COUNT(*)
			FROM wpd9_options
			WHERE option_name LIKE 'elementor\\_1\\_custom\\_task\\_manger\\_batch\\_%'
		
            [1] => 0.00029087066650391
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Upgrade\Custom_Tasks_Manager->__construct, Elementor\Core\Base\Background_Task->is_running, Elementor\Core\Base\BackgroundProcess\WP_Background_Process->is_queue_empty
            [3] => 1791651096.9951
            [4] => Array
                (
                )

        )

    [57] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'elementor_custom_tasks' LIMIT 1
            [1] => 0.00012803077697754
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, Elementor\Plugin->init, Elementor\Plugin->init_components, Elementor\Core\Upgrade\Custom_Tasks_Manager->__construct, Elementor\Core\Upgrade\Custom_Tasks_Manager->start_run, Elementor\Core\Upgrade\Custom_Tasks_Manager->get_custom_tasks, Elementor\Core\Upgrade\Custom_Tasks_Manager->get_tasks_requested_to_run, get_option
            [3] => 1791651096.9955
            [4] => Array
                (
                )

        )

    [58] => Array
        (
            [0] => SELECT a.hook FROM wpd9_actionscheduler_actions a
					JOIN wpd9_actionscheduler_groups g ON g.group_id = a.group_id
					WHERE g.slug = 'wp_mail_smtp' AND a.status IN ('in-progress', 'pending')
            [1] => 0.010096073150635
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, WPMailSMTP\Core->get_tasks, WPMailSMTP\Tasks\Tasks->init, WPMailSMTP\Tasks\Reports\SummaryEmailTask->init, WPMailSMTP\Tasks\Tasks::is_scheduled, WPMailSMTP\Tasks\Tasks::get_active_actions
            [3] => 1791651097.0274
            [4] => Array
                (
                )

        )

    [59] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'litespeed.placeholder._summary' LIMIT 1
            [1] => 0.00026917457580566
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, LiteSpeed\Core->after_user_init, LiteSpeed\Root::cls, LiteSpeed\Placeholder->__construct, LiteSpeed\Root::get_summary, LiteSpeed\Root::get_option, get_option
            [3] => 1791651097.0418
            [4] => Array
                (
                )

        )

    [60] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'litespeed.img_optm.need_pull' LIMIT 1
            [1] => 0.00017189979553223
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, LiteSpeed\Core->after_user_init, LiteSpeed\Task->init, LiteSpeed\Img_Optm::need_pull, LiteSpeed\Root::get_option, get_option
            [3] => 1791651097.0423
            [4] => Array
                (
                )

        )

    [61] => Array
        (
            [0] => SELECT option_name, option_value FROM wpd9_options WHERE option_name IN ('_site_transient_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba','_site_transient_timeout_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba')
            [1] => 0.00028395652770996
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, _register_theme_block_patterns, WP_Theme->get_block_patterns, WP_Theme->get_pattern_cache, get_site_transient, wp_prime_site_option_caches, wp_prime_network_option_caches, wp_prime_option_caches
            [3] => 1791651097.0932
            [4] => Array
                (
                )

        )

    [62] => Array
        (
            [0] => SELECT autoload FROM wpd9_options WHERE option_name = '_site_transient_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba'
            [1] => 0.00016498565673828
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, _register_theme_block_patterns, WP_Theme->get_block_patterns, WP_Theme->get_pattern_cache, get_site_transient, delete_site_option, delete_network_option, delete_option
            [3] => 1791651097.0936
            [4] => Array
                (
                )

        )

    [63] => Array
        (
            [0] => DELETE FROM `wpd9_options` WHERE `option_name` = '_site_transient_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba'
            [1] => 0.00018596649169922
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, _register_theme_block_patterns, WP_Theme->get_block_patterns, WP_Theme->get_pattern_cache, get_site_transient, delete_site_option, delete_network_option, delete_option
            [3] => 1791651097.0939
            [4] => Array
                (
                )

        )

    [64] => Array
        (
            [0] => SELECT autoload FROM wpd9_options WHERE option_name = '_site_transient_timeout_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba'
            [1] => 0.00011396408081055
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, _register_theme_block_patterns, WP_Theme->get_block_patterns, WP_Theme->get_pattern_cache, get_site_transient, delete_site_option, delete_network_option, delete_option
            [3] => 1791651097.0941
            [4] => Array
                (
                )

        )

    [65] => Array
        (
            [0] => DELETE FROM `wpd9_options` WHERE `option_name` = '_site_transient_timeout_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba'
            [1] => 0.00019097328186035
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, _register_theme_block_patterns, WP_Theme->get_block_patterns, WP_Theme->get_pattern_cache, get_site_transient, delete_site_option, delete_network_option, delete_option
            [3] => 1791651097.0943
            [4] => Array
                (
                )

        )

    [66] => Array
        (
            [0] => INSERT INTO `wpd9_options` (`option_name`, `option_value`, `autoload`) VALUES ('_site_transient_timeout_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba', '1791652897', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`)
            [1] => 0.00026082992553711
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, _register_theme_block_patterns, WP_Theme->get_block_patterns, WP_Theme->set_pattern_cache, set_site_transient, add_site_option, add_network_option, add_option
            [3] => 1791651097.0947
            [4] => Array
                (
                )

        )

    [67] => Array
        (
            [0] => INSERT INTO `wpd9_options` (`option_name`, `option_value`, `autoload`) VALUES ('_site_transient_wp_theme_files_patterns-16d40630ef2c3f7804e98e9db439daba', 'a:2:{s:7:\"version\";s:7:\"4.11.17\";s:8:\"patterns\";a:0:{}}', 'off') ON DUPLICATE KEY UPDATE `option_name` = VALUES(`option_name`), `option_value` = VALUES(`option_value`), `autoload` = VALUES(`autoload`)
            [1] => 0.00029206275939941
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, _register_theme_block_patterns, WP_Theme->get_block_patterns, WP_Theme->set_pattern_cache, set_site_transient, add_site_option, add_network_option, add_option
            [3] => 1791651097.095
            [4] => Array
                (
                )

        )

    [68] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'rank_math_connect_data' LIMIT 1
            [1] => 0.00018692016601562
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, RankMath\Tracking->hooks, RankMath\Tracking->init_user_data, RankMath\Tracking->get_user_email, RankMath\Admin\Admin_Helper::get_registration_data, get_option
            [3] => 1791651097.0965
            [4] => Array
                (
                )

        )

    [69] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'can_compress_scripts' LIMIT 1
            [1] => 0.00023198127746582
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, RT\ThePostGrid\Controllers\ScriptController->init, wp_register_script, wp_scripts, WP_Scripts->__construct, WP_Scripts->init, do_action_ref_array('wp_default_scripts'), WP_Hook->do_action, WP_Hook->apply_filters, wp_default_packages, wp_register_tinymce_scripts, script_concat_settings, get_site_option, get_network_option, get_option
            [3] => 1791651097.12
            [4] => Array
                (
                )

        )

    [70] => Array
        (
            [0] => SELECT a.hook FROM wpd9_actionscheduler_actions a
					JOIN wpd9_actionscheduler_groups g ON g.group_id = a.group_id
					WHERE g.slug = 'wpforms' AND a.status IN ( 'in-progress', 'pending' )
            [1] => 0.0034959316253662
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, WPForms\WPForms->WPForms\{closure}, WPForms\Tasks\Tasks->init, WPForms\Tasks\Tasks->get_active_actions
            [3] => 1791651097.1347
            [4] => Array
                (
                )

        )

    [71] => Array
        (
            [0] => SELECT a.action_id FROM wpd9_actionscheduler_actions a WHERE 1=1 AND a.hook='wpforms_process_entry_emails_meta_cleanup' AND a.status IN ('in-progress', 'pending') LIMIT 0, 1
            [1] => 0.0010230541229248
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, WPForms\WPForms->WPForms\{closure}, WPForms\Tasks\Tasks->init, WPForms\Tasks\Actions\EntryEmailsMetaCleanupTask->__construct, WPForms\Tasks\Actions\EntryEmailsMetaCleanupTask->init, WPForms\Tasks\Tasks->is_scheduled, as_has_scheduled_action, ActionScheduler_Store->query_action, ActionScheduler_DBStore->query_actions
            [3] => 1791651097.1394
            [4] => Array
                (
                )

        )

    [72] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'astra-site-permalink-update-status' LIMIT 1
            [1] => 0.00029206275939941
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, AiBuilder\Inc\Classes\Importer\Ai_Builder_Importer->permalink_update_after_import, get_option
            [3] => 1791651097.1686
            [4] => Array
                (
                )

        )

    [73] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'bsf_analytics_optin' LIMIT 1
            [1] => 0.00035810470581055
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, BSF_Analytics->maybe_track_analytics, BSF_Analytics->is_tracking_enabled, get_site_option, get_network_option, get_option
            [3] => 1791651097.2158
            [4] => Array
                (
                )

        )

    [74] => Array
        (
            [0] => SELECT option_name, option_value FROM wpd9_options WHERE option_name IN ('_site_transient_bsf_analytics_track','_site_transient_timeout_bsf_analytics_track')
            [1] => 0.00018978118896484
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('init'), WP_Hook->do_action, WP_Hook->apply_filters, BSF_Analytics->maybe_track_analytics, get_site_transient, wp_prime_site_option_caches, wp_prime_network_option_caches, wp_prime_option_caches
            [3] => 1791651097.2164
            [4] => Array
                (
                )

        )

    [75] => Array
        (
            [0] => SELECT option_value FROM wpd9_options WHERE option_name = 'getting_started_is_setup_wizard_showing' LIMIT 1
            [1] => 0.00027704238891602
            [2] => require('wp-blog-header.php'), require_once('wp-load.php'), require_once('wp-config.php'), require_once('wp-settings.php'), do_action('wp_loaded'), WP_Hook->do_action, WP_Hook->apply_filters, GS\Getting_Started_Plugin_Loader->load_files, require_once('/plugins/astra-sites/inc/lib/getting-started/classes/class-gs-admin.php'), GS\Classes\GS_Admin::get_instance, GS\Classes\GS_Admin->__construct, GS\Classes\GS_Admin->is_show_setup, get_option
            [3] => 1791651097.2454
            [4] => Array
                (
                )

        )

)
 -->