Yet another WordPress plugin has made headlines—and this time it’s the OttoKit/OttoPress plugin. It's updated now, however, hackers were able to exploit a critical vulnerability to inject admin accounts into your WordPress site. If you’ve ever installed OttoPress, and still have it installed, this episode is essential listening.
If you don't have it - the episosde is still worth listening to, to understand how to respond if it happens to you.
📌 In this episode, Charly walks you through:
✅ What this vulnerability is and why it's dangerous
✅ How to check if you’re using the OttoPress plugin
✅ The critical steps to take if it’s installed—update immediately
✅ How to audit user accounts and reset all passwords
✅ When and why you should consider changing your database credentials
🔗 Read more about the exploit:
👉 Don’t delay. Even dormant or deactivated plugins can leave you open to attack.
📢 Join the discussion in my community: https://askcharlyleetham.locals.com
📲 Follow us for more business and tech insights:
Locals: https://askcharlyleetham.locals.com
aaaa
Rumble: https://rumble.com/askcharlyleetham
Odyssey: https://odysee.com/@askcharlyleetham:4
YouTube: https://youtube.com/askcharlyleetham
Facebook: https://www.facebook.com/askcharlyleetham
Twitter: https://twitter.com/yourbizmgr
Instagram: https://instagram.com/ask_charly_leetham
LinkedIn: www.linkedin.com/in/charlyleetham
LinkedIn Company: https://www.linkedin.com/company/ask-charly-leetham/
Spotify:
https://askcharlyleetham.com/likes/rise-and-shine
Apple Podcasts: https://podcasts.apple.com/us/podcast/ask-charlyleetham-online-business-manager/id1659738721
iHeartRadio: https://www.iheart.com/podcast/269-ask-charlyleetham-online-105944212/
Amazon Music: https://music.amazon.com/podcasts/662f1e44-115d-4094-862b-efe9307e0df4/ask-charlyleetham-online-business-manager
https://rumble.com/v6t5nrx-ottopress-plugin-vulnerability-what-do-you-do-2025487.html
Life is busy and there's just so many things to remember. What tools do you use to help you keep on top of ALL the things?
Have you ever received a notification that looked like your tech was hurling abuse at you? A friend of a friend sent Charly a screenshot of their Apple Fitness notification displaying what appeared to be profanity, and the mystery needed solving. In this lighthearted Boxing Day episode, Charly explains what personalisation tokens are, why they sometimes fail spectacularly, and how to avoid embarrassing automation mishaps in your own business communications.
In this episode, Charly covers:
✅ What the mysterious %@ symbol actually means in app notifications
📌 Why personalisation tokens break and display placeholder text instead of names
🛡️ The importance of testing automations with varied name formats including hyphenated, accented, and long names
✅ A classic QA testing joke that every tech person will appreciate
Book a Free 30minute Breakthrough Session: https://askcharlyleetham.com/book-me
(1 per person only)
Follow us:
Locals: https://askcharlyleetham.locals.com
Rumble: ...
It's Christmas Eve, so Charly is taking a break from the usual tech tips to bring you something special. If you've ever wondered what would happen if the classic Christmas poem met the world of IT, wonder no more. In this festive episode, Charly performs a tech-themed retelling of 'Twas the Night Before Christmas, complete with firewalls, backups, SSL certificates, and a very special visit from Saint Nick the sysadmin.
In this episode, Charly covers:
✅ A fun, festive tech parody perfect for sharing with your team
📌 Why even Santa needs strong passwords and two-factor authentication
🛡️ A lighthearted reminder that your backups and firewalls should be sorted before the holidays
✅ Season's greetings from the Ask Charly Leetham team
Merry Christmas from Charly and the team!
Book a Free 30minute Breakthrough Session: https://askcharlyleetham.com/book-me
(1 per person only)
Follow us:
Locals: https://askcharlyleetham.locals.com
Rumble: https://rumble.com/askcharlyleetham
Odyssey: ...
Many small business owners spent 2025 chasing the latest tech trends while the boring fundamentals quietly kept their businesses running. In this year-end review, Charly reflects on what tech actually delivered results, what disappointed, and the valuable lessons learned along the way.
In this episode, Charly covers:
✅ Why properly configured backups, DNS, and regular updates remained the unsung heroes of business tech throughout 2025
✅ Tools that delivered on their promises, including password managers and email authentication systems like SPF and DKIM
📌 The disappointments of the year, from AI overpromises to platforms prioritising their interests over users
🛡️ Why building your business on rented land remains a significant risk and what preventable failures taught us
📌 The key insight that consistency beats perfection, and why systems and processes matter more than perfect technology
Book a Free 30minute Breakthrough Session: https://askcharlyleetham.com/book-me
(1 per person only)
...