Tag: security

  • Ninja Forms Update Patches Critical Security Vulnerability

    Ninja Forms Update Patches Critical Security Vulnerability

    Ninja Forms, a popular plugin active on more than 500K websites, released an update 48 hours ago that addresses a critical security vulnerability. Wordfence is reporting that Ninja Forms versions 2.9.36 to 2.9.42 contain multiple security vulnerabilities. One of the vulnerabilities allows an attacker to upload and execute code remotely on WordPress sites. The only…

  • bbPress 2.5.9 Patches Cross-Site-Scripting Vulnerability

    bbPress 2.5.9 Patches Cross-Site-Scripting Vulnerability

    John James Jacoby, lead developer of bbPress, has released bbPress 2.5.9 to patch a security vulnerability, “bbPress 2.5.8 and below are susceptible to a cross-site-scripting vulnerability that’s due to the way users are linked to their profiles when they are mentioned in topics and replies,” Jacoby said. Marc-Alexandre Montpas is credited for responsibly disclosing the…

  • Templatic Hacked, Files and Databases Compromised

    Templatic Hacked, Files and Databases Compromised

    Templatic, a WordPress commercial theme company, reported on Saturday, April 30th, that its site was hacked. Files and databases containing customer usernames and passwords were compromised. According to R. Bhavesh, founder of Templatic, the data is being held for ransom money. The hacker is now threatening us via email and demanding ransom money be paid.…

  • WPWeekly Episode 231 – An Inside Look at the Plugin Review Process with Mika Epstein

    WPWeekly Episode 231 – An Inside Look at the Plugin Review Process with Mika Epstein

    In this episode of WordPress Weekly, Marcus Couch and I are joined by Mika Epstein. Epstein reviews plugins before they’re added to the WordPress plugin directory and volunteers on the WordPress support forums. We learn what the plugin review process is like and common security issues she discovers. I was shocked to learn that Epstein…

  • Sucuri Partners with Let’s Encrypt to Offer Free SSL Certificates to All Customers

    Sucuri Partners with Let’s Encrypt to Offer Free SSL Certificates to All Customers

    Sucuri, a website security company that specializes in securing WordPress (and other CMS) sites, announced that SSL certificates are now available at no cost to all customers who make use of the company’s firewall. As a sponsor of the Let’s Encrypt initiative, Sucuri joins Automattic as one of the first companies to fully automate free…

  • WPWeekly Episode 229 – VersionPress Goes Open Source

    WPWeekly Episode 229 – VersionPress Goes Open Source

    In this episode of WordPress Weekly, Marcus Couch and I discuss the news of the week, including a big move for VersionPress as it transitions into an open source project. We provide an update on the development status of bbPress and BuddyPress. We also share details of a critical security vulnerability that was patched in…

  • User Role Editor 4.25 Patches Critical Security Vulnerability

    User Role Editor 4.25 Patches Critical Security Vulnerability

    Vladimir Garagulya, developer of the User Role Editor has patched a critical security vulnerability. User Role Editor is used to edit, manage, and create user roles and capabilities and is active on more than 300K sites. User Role Editor 4.24 and below allows any registered user to gain administrator access. Wordfence, a popular security plugin…

  • WPWeekly Episode 225 – Interview With Scott Kingsley Clark Lead Developer of Pods

    WPWeekly Episode 225 – Interview With Scott Kingsley Clark Lead Developer of Pods

    In this episode of WordPress Weekly, Marcus Couch and I interview Scott Kingsley Clark, lead developer of the Pods framework plugin. Clark explains the financial and organizational structure of the Friends of Pods program and how it benefits the plugin’s development. He also explains what the Fields API project is and its significance to WordPress.…

  • Custom Content Type Manager Plugin Update Creates a Security Nightmare

    Custom Content Type Manager Plugin Update Creates a Security Nightmare

    Over the years, we’ve told users that the WordPress plugin directory is the safest place to download and install plugins from. This is due in large part to the dedication of volunteers who act as gatekeepers and review plugins before they’re added to the directory. Plugin updates, however don’t receive the same scrutiny as there’s…

  • Roots Team Releases wp-password-bcrypt Plugin to Improve WordPress Password Security

    Roots Team Releases wp-password-bcrypt Plugin to Improve WordPress Password Security

    This week the Roots development team released wp-password-bcrypt, a plugin that uses bcrypt instead of MD5 password hashing. MD5’s known and exploited weaknesses have rendered it “cryptographically broken and unsuitable for further use,” according to the CMU Software Engineering Institute. In a post announcing the plugin, Scott Walkinshaw explained why WordPress’ default MD5 hashing function…

  • Critical Security Vulnerability Discovered in Elegant Themes Products

    Critical Security Vulnerability Discovered in Elegant Themes Products

    Elegant Themes emailed its customers last night to inform them of a critical security vulnerability affecting a large segment of its product line. An information disclosure vulnerability was found in the Divi Builder (included in our Divi and Extra themes, as well as our Divi Builder plugin) which resulted in the potential for user privilege…

  • WPWeekly Episode 220 – Automattic’s Relationship With WordPress

    WPWeekly Episode 220 – Automattic’s Relationship With WordPress

    In this episode of WordPress Weekly, Marcus Couch and I discuss the latest news in the WordPress ecosystem. On the first episode of 2016, I rant about the conspiracy theorists who believe Automattic owns and controls the WordPress project. I try to set the record straight and explain why it’s not the case. Later in…

  • WordPress 4.4.1 Patches XSS Security Vulnerability

    WordPress 4.4.1 Patches XSS Security Vulnerability

    WordPress 4.4.1 is available for download and includes 52 fixes, one of which patches a cross site scripting vulnerability reported by Crtc4L. This release address two severe bugs and updates the polyfill used for emoji to support Unicode 8. Support for Unicode 8 adds new diversity emoji to WordPress. Other notable changes include the removal…

  • Linode Confirms Data Security Breach That Matches Recent WP Engine Attack

    Linode Confirms Data Security Breach That Matches Recent WP Engine Attack

    Cloud hosting provider Linode has been combatting DDoS attacks since Christmas Day, which have caused multiple disruptions and service outages across its global data centers. The attacks are ongoing and the company is struggling to keep its status blog up to notify customers. In addition to the DDoS attacks, Linode has also confirmed a data…