Tag: security

  • WP Engine Identifies Cloud Infrastructure Provider as Entry Point for Recent Security Breach

    WP Engine Identifies Cloud Infrastructure Provider as Entry Point for Recent Security Breach

    On December 9th, 2015, WP Engine sent out an urgent notice to its customers regarding a security breach wherein customer credentials were exposed. This incident prompted an investigation, which is now complete. According to the most recent and final update, investigators determined that the security exposure came through one of the host’s cloud infrastructure providers.…

  • WP Engine Security Breach: Customer Credentials Exposed

    WP Engine Security Breach: Customer Credentials Exposed

    WP Engine customers received an urgent notification in their inboxes Wednesday evening regarding a security breach. At WP Engine we are committed to providing robust security. We are writing today to let you know that we learned of an exposure involving some of our customers’ credentials. Out of an abundance of caution, we are proactively…

  • Imperva’s Web Application Attack Report Shows Spam Is WordPress’ Largest Security Threat

    Imperva’s Web Application Attack Report Shows Spam Is WordPress’ Largest Security Threat

    Imperva, an international cyber security company founded in 2002, published its 2015 web application attack report. The report includes a thorough analysis of attack data obtained through its WAF or Web Application Firewall. In the report, Imperva’s application defense center group analyzed 297,954 attacks and 22,850,023 alerts on 198 of the applications it protects behind…

  • BuddyPress 2.3.5 Patches Privilege Escalation Issue

    BuddyPress 2.3.5 Patches Privilege Escalation Issue

    BuddyPress 2.3.5 is available and patches a security vulnerability that may allow privilege escalation for logged-in users. BuddyPress 2.3.4 and previous versions are affected however, versions 2.0.4, 2.1.2, and 2.2.4 include the patch. According to the BuddyPress development team, there is no evidence that the bug has been exploited in the wild. If your WordPress…

  • Jetpack 3.7.2 Patches Two Security Vulnerabilities

    Jetpack 3.7.2 Patches Two Security Vulnerabilities

    Jetpack 3.7.2 is available for download and patches two security vulnerabilities. The first is a cross-site scripting vulnerability in the contact form due to improper input sanitation that affects Jetpack 3.7.0 and below. Marc-Alexandre Montpas of Sucuri is credited with responsibly disclosing the vulnerability. The second is an information disclosure vulnerability present in certain hosting…

  • WP Super Cache 1.4.5 Patches XSS Vulnerability

    WP Super Cache 1.4.5 Patches XSS Vulnerability

    If you use WP Super Cache, you should immediately update to version 1.4.5 as it patches a XSS vulnerability in the settings page. This version also prevents PHP object injections. In addition to security patches, 1.4.5 contains a number of bug fixes. Make sure to update your sites as soon as possible to patch the…

  • WPML Confirms It Did Not Have a Security Breach

    WPML Confirms It Did Not Have a Security Breach

    When WPML emailed new passwords to customers in plaintext, some customers thought it was due to a security breach. Amit Kvint, compatibility team leader for WPML, confirmed the emails are not a result of a security breach. In a post on the official WPML blog, Kvint says the emails were a preventive measure to insure…

  • WPML Emails Passwords to Affected Customers in Plaintext

    WPML Emails Passwords to Affected Customers in Plaintext

    Customers who purchased WPML, a multilingual plugin for WordPress, are receiving a suspicious email that looks similar to a phishing attempt. Matt Radford, a customer of WPML, kindly sent the Tavern a copy of the email. Dear Matt, We want to make sure that your WPML account remains secure. For this, we are updating all…

  • BuddyPress 2.3.3 Patches Security Vulnerabilities in BuddyPress Messages Component

    BuddyPress 2.3.3 Patches Security Vulnerabilities in BuddyPress Messages Component

    BuddyPress 2.3.3 is available and users are encouraged to update as soon as possible. A few security vulnerabilities were discovered in BuddyPress Messages, a core component that allows users to send and receive private messages. A vulnerability was responsibly disclosed to the BuddyPress team that could allow members to manipulate a failed private outbound message…

  • WPWeekly Episode 202 – Prestige is Serious Business

    WPWeekly Episode 202 – Prestige is Serious Business

    On this week’s episode, Marcus Couch and I talk about the news of the week, including the release of WordPress 4.2.4 which patches six security vulnerabilities. I shared my experience attending Prestige last weekend while Marcus describes what it was like to watch the livestream. Marcus and I closed out the show with a candid…

  • The WordPress Core Team Receives Praise for Their Efforts to Maintain Security

    The WordPress Core Team Receives Praise for Their Efforts to Maintain Security

    Netanel Rubin, a vulnerability researcher for Check Point Software and credited for properly disclosing a security vulnerability to WordPress, published the first in a trilogy of posts that explains how he discovered it. The vulnerability was discovered during a full audit of WordPress’ code base in which Rubin praised the efforts of the WordPress development…

  • Behind the Scenes of WordPress 4.2.3 With Gary Pendergast

    Behind the Scenes of WordPress 4.2.3 With Gary Pendergast

    When WordPress 4.2.3 was released last week, not only did it patch a critical security vulnerability, but also adversely impacted a number of sites. Changes to the Shortcode API which were necessary as part of the patch caused some plugins that rely on the API to break. These changes were not immediately communicated to plugin…

  • Plugin Developers Demand a Better Security Release Process After WordPress 4.2.3 Breaks Thousands of Websites

    Plugin Developers Demand a Better Security Release Process After WordPress 4.2.3 Breaks Thousands of Websites

    WordPress 4.2.3, a critical security release, was automatically pushed out to users yesterday to fix an XSS vulnerability. Shortly afterwards, the WordPress.org support forums were flooded with reports of websites broken by the update. Roughly eight hours later Robert Chapin (@miqrogroove) published a post to the Make.WordPress.org/Core blog, detailing changes to the Shortcode API that…

  • WordPress 4.2.3 is a Critical Security Release, Fixes an XSS Vulnerability

    WordPress 4.2.3 is a Critical Security Release, Fixes an XSS Vulnerability

    WordPress users in the Americas woke this morning to find update notices in their inboxes due to a critical security vulnerability. WordPress 4.2.3 was released today and automatically pushed out to sites that have auto-updates enabled. Because this is a security release for all previous versions of WordPress, those who do not have automatic update…

  • Update Adobe Flash Immediately to Patch Critical Security Vulnerability

    Update Adobe Flash Immediately to Patch Critical Security Vulnerability

    If you have Adobe Flash installed, you’ll want to make sure it’s updated to the latest version as it patches a critical security vulnerability. According to The Register, confidential source code was stolen from Hacking Team and leaked online. Within the leaked source code, software vulnerabilities used by Hacking Team to break into PCs was…