Tag: security

  • Matt Mullenweg Appoints Nikolay Bachiyski as Security Czar for the WordPress Project

    Matt Mullenweg Appoints Nikolay Bachiyski as Security Czar for the WordPress Project

    While on stage at WordCamp Europe answering a question related to WordPress’ security track record, Matt Mullenweg named Nikolay Bachiyski as the first Security Czar for the WordPress project. https://twitter.com/redcrew/status/614414379380011009 Bachiyski is employed by Automattic and has been a member of the WordPress community for more than 10 years. Over that time period, he’s established…

  • WordPress Plugin Developers Need to Communicate Better in Change Logs

    WordPress Plugin Developers Need to Communicate Better in Change Logs

    One of the habits I developed when I started using WordPress is to always read a plugin’s changelog before updating. The changelog is a communication channel that bridges the gap between me and the developer. It tells me what’s changed, what to expect, and any other information the developer thinks I should know. The most…

  • WooCommerce 2.3.11 Patches Object Injection Vulnerability

    WooCommerce 2.3.11 Patches Object Injection Vulnerability

    WooCommerce 2.3.11 patches an object injection vulnerability discovered by Sucuri. According to the security research company, the vulnerability is only present when the PayPal Identity Token option is set in WooCommerce. Researchers used a combination of WordPress and WooCommerce components with a known PHP bug and were able to download critical files, including wp-config.php which…

  • WooThemes Fixes XSS Vulnerability in Products Using the prettyPhoto Library

    WooThemes Fixes XSS Vulnerability in Products Using the prettyPhoto Library

    Jeff Ikus of WooThemes, announced on the company’s themes development blog, that it has pushed out updates to all of its products that use the prettyPhoto library. The update fixes a DOM based cross-site scripting vulnerability discovered in 2014. prettyPhoto is a jQuery lightbox clone used in a potentially large number of WordPress products. If…

  • Sucuri is Building a Comprehensive Alternative to CloudFlare

    Sucuri is Building a Comprehensive Alternative to CloudFlare

    Sucuri launched a new free performance tool today. The Global Website Performance Tester allows anyone to enter a URL and get a quick assessment of how fast the website is loading from 13 globally distributed testing stations. Results include three key metrics: connection time, time to first byte (TTFB) and total load time. At the…

  • XSS Vulnerability in Jetpack and the Twenty Fifteen Default Theme Affects Millions of WordPress Users

    XSS Vulnerability in Jetpack and the Twenty Fifteen Default Theme Affects Millions of WordPress Users

    Jetpack and the Twenty Fifteen default theme have been updated after a DOM-based Cross-Site Scripting (XSS) vulnerability was discovered. According to Sucuri, any plugin or theme that uses Genericons is vulnerable due to an insecure file included within the package. Genericons ships with a file called example.html which is vulnerable to attack from the Document…

  • WordPress 4.2.1 Released to Patch Comment Exploit Vulnerability

    WordPress 4.2.1 Released to Patch Comment Exploit Vulnerability

    This morning we reported on an XSS vulnerability in WordPress 4.2, 4.1.2, 4.1.1, and 3.9.3, which allows an attacker to compromise a site via its comments. The security team quickly patched the vulnerability and released 4.2.1 within hours of being notified. WordPress’ official statement on the security issue: The WordPress team was made aware of…

  • Zero Day XSS Vulnerability in WordPress 4.2 Currently Being Patched

    Zero Day XSS Vulnerability in WordPress 4.2 Currently Being Patched

    Klikki Oy is reporting a new comment XSS exploit vulnerability in WordPress 4.2, 4.1.2, 4.1.1, and 3.9.3, which allows an unauthenticated attacker to inject JavaScript into comments. If triggered by a logged-in administrator, under default settings the attacker can leverage the vulnerability to execute arbitrary code on the server via the plugin and theme editors.…

  • XSS Vulnerability: What to do if You Buy or Sell Items on Themeforest and CodeCanyon

    XSS Vulnerability: What to do if You Buy or Sell Items on Themeforest and CodeCanyon

    Earlier this week, one of the largest coordinated efforts between WordPress plugin authors, Sucuri, and the WordPress security team resulted in a number of popular plugins receiving security updates. Due to inaccurate information within the WordPress codex, a number of developers improperly assumed the add_query_arg() and remove_query_arg() functions would properly escape user input. When combined,…

  • WordPress 4.1.2 is a Critical Security Release, Immediate Update Recommended

    WordPress 4.1.2 is a Critical Security Release, Immediate Update Recommended

    WordPress 4.1.2 is available and is a critical security update for all previous versions of WordPress. The release has eight security fixes, one of which is high risk, three are medium-low risk, and the last four added to harden WordPress. This is the first major security update to WordPress core since WordPress 4.0.1 released in…

  • XSS Vulnerability Affects More Than a Dozen Popular WordPress Plugins

    XSS Vulnerability Affects More Than a Dozen Popular WordPress Plugins

    For the past week, security firm Sucuri has worked with the WordPress core security team to address a cross site scripting vulnerability discovered in more than a dozen popular WordPress plugins. The vulnerability stems from the improper use of the add_query_arg() and remove_query_arg() functions. Inaccurate information within the WordPress Codex lead many developers to assume…

  • Banking on WordPress: Matt Mullenweg Weighs in on Security Concerns

    Banking on WordPress: Matt Mullenweg Weighs in on Security Concerns

    If you follow WordPress topics on Quora, you may have noticed a popular question making the rounds regarding security. The question has been viewed more than 30,000 times: I am powering a bank’s website using WordPress. What security measures should I take? Ordinarily, such a question is a magnet for trollish responses and uninformed WordPress…

  • iThemes Patches Vulnerability that Affects All Versions of the iThemes Security Plugin

    iThemes Patches Vulnerability that Affects All Versions of the iThemes Security Plugin

    iThemes has released new versions of iThemes Security and iThemes Security Pro to address a critical security vulnerability. Every version of both plugins is at risk, including Better WP Security 3.0. The vulnerability allowed potentially dangerous JavaScript to run when viewing 404 logs. When the 404 Detection feature is enabled, data about requests for non-existent…

  • Wordfence Premium Adds the Ability to Audit User Passwords in WordPress

    Wordfence Premium Adds the Ability to Audit User Passwords in WordPress

    By utilizing the power of graphical processing units and partnering with Netriver, Wordfence can simulate a password cracking attempt using a library that contains more than 260 million passwords. The library is made up of previous hacks on major websites and services. For example, if your password was leaked during the LinkdIn hack in 2012,…

  • BuddyPress 2.2.2 Released Addresses Two Potential Security Issues

    BuddyPress 2.2.2 Released Addresses Two Potential Security Issues

    BuddyPress 2.2.2 is available from the WordPress plugin directory. It fixes two potential security issues and has a few bug fixes. This is what is fixed in 2.2.2. Activity: sanitize output of “Load More” link Members: better nonce check on members widget Core: improve filtering of wp_title The security issues were responsibly disclosed by Todd…