Description
We are looking for an experienced WordPress security specialist to help us remediate findings from a PCI vulnerability scan and prepare our WooCommerce website to pass a rescan. The website is a production WooCommerce site running on WordPress with Cloudflare and several third-party integrations (analytics, marketing scripts, WPML, Elementor, etc.). We are looking for someone with proven experience in WordPress security, PCI compliance, and server configuration who can implement the required changes without affecting site functionality. Scope of Work: 1. Review the PCI Vulnerability Report * Review the provided PCI scan report. * Separate genuine security issues from false positives or standard WordPress behavior. * Recommend compensating controls where appropriate. 2. Cookie Security Review * Audit all cookies flagged by the PCI scan. * Identify which plugin or component creates each cookie. * Configure Secure, HttpOnly, and SameSite attributes where appropriate. * Ensure WooCommerce cart functionality, checkout, AJAX features, analytics, and third-party integrations continue to work correctly. * Avoid blanket server-side cookie modifications that could break functionality. 3. Security Headers * Configure HTTP Strict Transport Security (HSTS). * Review and improve other relevant security headers where appropriate. 4. WordPress Hardening * Verify PHP errors and debug output are disabled. * Investigate the reported "Full Path Disclosure" findings and determine whether they are