
Thank you for attending my talk
The Attacker That Never Logged In: Session Hijacking, Stolen Cookies, and the Blind Spot in WordPress Security
The slides are available for download.
Click the button below to download them.
During the talk I covered how WordPress authentication cookies and session tokens actually work, the different ways sessions get hijacked, and, the part most WordPress security setups miss entirely; post login security. In other words, what to do about visibility and control after someone is already logged in.
Below you’ll find the plugins that add the specific capabilities highlighted during the talk, the reports and data cited during the talk, and some further reading if you want to go deeper on any of it.
Plugins mentioned in this talk
The talk touches several distinct capabilities, which are; activity logging, session visibility, account lifecycle management, device recognition, and user roles. A plugin covering more than one is only listed once below, with all relevant capabilities noted alongside it.
| Plugin | Type | Capabilities covered in this talk |
|---|---|---|
| WP Activity Log | Melapress Free & Premium options | Activity logging & forensic visibility (free) Real-time view of logged-in users (premium) Concurrent session limits (premium) Inactive session expiry (premium) |
| Stream | Free alternative | Activity logs only. No session visibility or session management |
| Melapress Login Security | Melapress Free & Premium options | Inactive user cleanup (free) Temporary login links (free) Restricted login times (premium) Device recognition alerts (premium) IP address /device limiting (premium) Security questions (premium) |
| Temporary Login without Password | Free alternative | Temporary login links only |
| Melapress Role Editor | Melapress Free | User roles & least privilege |
| PublishPress Capabilities | Free alternative | User roles & least privilege |
| Members – Membership & User Role Editor Plugin | Free alternative | User roles & least privilege |
| WP 2FA | Melapress Free & Premium options | Add 2FA for sensitive user actions such as password reset. |
| Two Factor | Free alternative | Add 2FA (no option to add 2FA for sensitive user actions) |
No free plugin covers real-time session visibility or concurrent session limits in full. That’s a genuine gap in the free plugin space.
Reports & research referenced in this talk
- SpyCloud – 2026 Identity Exposure Report – 8.6 billion stolen cookies in 2025.
- Red canary 2026 Thread Detection Report – Identity threats accounted for 53% of the total detection volum in 2025, up from 20% in 2024.
- Recorded Future — 2025 Identity Threat Landscape Report – 276 million credentials with active session cookies usable to bypass MFA.
Security awareness training
Technical controls only go so far, and the talk closes on the human layer. A couple of starting points if you want to build this out for your team or clients:
- SANS Security Awareness Training – widely regarded as the gold standard in security awareness training.
- Pluralsight – more technical/educational than compliance-focused, better suited to developers and security champions than general staff. Troy Hunt has authored several relevant courses here, including password security, authentication, data breaches, modern identity, and web security fundamentals.
Further reading
- How to conduct an activity log analysis
- Activity logs for newbies
- HTTP cookies, explained – if cookies are new territory for you
- How WordPress uses authentication cookies and sessions – a technical deep dive
- Session hijacking – background reading on the attack class itself
Would you like more information and tips on keeping your WordPress websites secure?
Subscribe to the newsletter for actionable WordPress security guidance, product know-how, and resources you can put to use right away.
It’s free and you can unsubscribe whenever you want. Check our blog for a taste. Read our Privacy Policy