Tag: security

  • Wordfence CLI 2.0.1 Update Adds Free Vulnerability Scanning

    Wordfence CLI 2.0.1 Update Adds Free Vulnerability Scanning

    Wordfence CLI 2.0.1 introduced free vulnerability scanning this week. The new CLI product was launched at WordCamp US two months ago with malware detection capabilities, but the latest update brings in the most highly requested feature – vulnerability scanning at scale. Wordfence is most well-known for its Web Application Firewall, malware scanner, and login security…

  • Patchstack Reports 404 Vulnerabilities Affecting 1.6M+ Websites to WordPress.org Plugins Team

    Patchstack Reports 404 Vulnerabilities Affecting 1.6M+ Websites to WordPress.org Plugins Team

    After an accumulation of undisclosed and unpatched vulnerabilities in plugins hosted on WordPress.org, Patchstack has reported 404 plugins to WordPress’ Plugin Review Team. “This situation creates a significant risk for the WordPress community, and we decided to take action,” Patchstack researcher Darius Sveikauskas said. “Since these developers have been unreachable, we sent the full list…

  • Ninja Forms Version 3.6.26 Patches Multiple High Severity Security Vulnerabilities

    Ninja Forms Version 3.6.26 Patches Multiple High Severity Security Vulnerabilities

    If you use the Ninja Forms plugin and your sites aren’t set to get automatic plugin updates, add a round of updates to your weekend plans. Patchstack is reporting multiple high severity security vulnerabilities in the plugin, including the following: Patchstack researchers discovered the vulnerabilities on June 22, 2023, and Ninja Forms patched them on…

  • All-In-One Security Plugin Patches Sensitive Data Exposure Vulnerability in Version 5.2.0

    All-In-One Security Plugin Patches Sensitive Data Exposure Vulnerability in Version 5.2.0

    All-In-One Security (AIOS), a plugin active on more than a million WordPress sites, was found to be logging plaintext passwords from login attempts in the database and has patched the security issue in version 5.2.0. In a post titled “Cleartext passwords written to aiowps_audit_log” published to the plugin’s support forum two weeks and five days…

  • MalCare, Blogvault, and WPRemote Plugins Patch Vulnerabilities Allowing Site Takeover Through Stolen API Credentials

    MalCare, Blogvault, and WPRemote Plugins Patch Vulnerabilities Allowing Site Takeover Through Stolen API Credentials

     Snicco, a WordPress security services provider, has published an advisory on a vulnerability in the MalCare plugin, which is active on more than 300,000 sites. “MalCare uses broken cryptography to authenticate API requests from its remote servers to connected WordPress sites,” WordPress security researcher Calvin Alkan said. “Requests are authentication by comparing a shared secret stored…

  • Ultimate Member 2.6.7 Patches Privilege Escalation Vulnerability

    Ultimate Member 2.6.7 Patches Privilege Escalation Vulnerability

    Authors of the Ultimate Member plugin have released version 2.6.7 with a patch for a privilege escalation vulnerability. Last week WPScan reported that Ultimate Member had still not fully patched the vulnerability after multiple inadequate attempts. There was evidence that it was being actively exploited in the wild. Working through the complexities of this security…

  • Hackers Actively Exploiting Unpatched Privilege Escalation Vulnerability in Ultimate Member Plugin

    Hackers Actively Exploiting Unpatched Privilege Escalation Vulnerability in Ultimate Member Plugin

    WPScan is reporting a hacking campaign actively exploiting an unpatched vulnerability in the Ultimate Member plugin, which allows unauthenticated attackers to create new user accounts with administrative privileges and take over the site. The vulnerability has been assigned a CVSSv3.1 (Common Vulnerability Scoring System) score of 9.8 (Critical). Automattic’s WP.cloud and Pressable.com hosting platforms picked…

  • Really Simple SSL Plugin Adds Free Vulnerability Detection

    Really Simple SSL Plugin Adds Free Vulnerability Detection

    Really Simple SSL, a popular plugin used on more than five million sites for installing SSL certificates, handling website migrations, mixed content, redirects, and security headers, has added a new feature in its most recent major update. Version 7.0.0 introduces vulnerability detection as part of a partnership with WP Vulnerability, an open source, free API…

  • WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

    WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

    Patchstack is reporting an Insecure Direct Object References (IDOR) vulnerability in WooCommerce Stripe Gateway, the most popular WooCommerce Stripe payment plugin with more than 900,000 active users. It was discovered by Patchstack researcher Rafie Muhammad on April 17, 2023, and patched by WooCommerce on May 30, 2023, in version 7.4.1. The security advisory describes the…

  • #79 – Robert Abela on How to Keep Your WordPress Website Secure

    #79 – Robert Abela on How to Keep Your WordPress Website Secure

    On the podcast today we have Robert Abela. Robert is the CEO and founder of MelaPress, formerly known as WP White Security. They make niche WordPress security and admin plugins. He has over 18 years experience in the IT and software industries, and has written numerous web security articles and white papers. We all know…

  • WordPress 6.2.2 Restores Shortcode Support in Block Templates, Fixes Security Issue

    WordPress 6.2.2 Restores Shortcode Support in Block Templates, Fixes Security Issue

    WordPress 6.2.2 was released early this morning as a rapid follow-up to 6.2.1, which introduced a bug that broke shortcode support in block templates. Version 6.2.1 was also an important security release, but due to the catastrophic breakage for those using shortcodes in block templates, some users were implementing insecure workarounds or simply downgrading to…

  • WordPress 6.2.1 Released with Fixes for 5 Security Vulnerabilities

    WordPress 6.2.1 Released with Fixes for 5 Security Vulnerabilities

    WordPress 6.2.1 was released today. Those with automatic background updates enabled should see a notice in their email, as updates rolled out earlier today. This is a maintenance and security release that includes important fixes for five security vulnerabilities outlined by core contributor and release co-lead Jb Audras: The patches were backported to WordPress 4.1.…

  • Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

    Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

    Essential Addons for Elementor, a plugin with more than a million active installs, has patched an unauthenticated privilege escalation vulnerability in version 5.7.2. The vulnerability was discovered on May 8, 2023, and reported by Patchstack researcher Rafie Muhammad. It was given a 9.8 (Critical severity) CVSS 3.1 score and is not yet known to have been…

  • Advanced Custom Fields Plugin Patches Reflected XSS Vulnerability

    Advanced Custom Fields Plugin Patches Reflected XSS Vulnerability

    Advanced Custom Fields (ACF) has patched a reflected XSS vulnerability that affects versions 6.1.5 and below of ACF and ACF Pro, potentially impacting more than 2+ million users. It was discovered by Patchstack researcher Rafie Muhammad in May 2, 2023, and patched by ACF developers in version 6.1.6 on May 4, 2023. Patchstack published a security…

  • WooCommerce Payments Plugin Patches Critical Vulnerability That Would Allow Site Takeover

    WooCommerce Payments Plugin Patches Critical Vulnerability That Would Allow Site Takeover

    WooCommerce Payments, a plugin that allows WooCommerce store owners to accept credit and debit card payments and manage transactions inside the WordPress dashboard, has patched an Authentication Bypass and Privilege Escalation vulnerability with a 9.8 (Critical) CVSS score. The plugin is active on more than 500,000 websites. Beau Lebens, WooCommerce’s Head of Engineering, published an…