Tag: security

  • Get Email Alerts for Security Vulnerabilities in Your WordPress Plugins

    Get Email Alerts for Security Vulnerabilities in Your WordPress Plugins

    WordPress users have been subject to a rash of plugin vulnerabilities over the past couple of months. Some of these vulnerabilities have been so widespread that the FBI recently warned users of attacks designed to exploit WordPress sites. Not long after WordPress published its Security White Paper, an outbreak of issues popped up, starting with…

  • Critical Security Update For the WP REST API Plugin

    Critical Security Update For the WP REST API Plugin

    The WP REST API development team has released a critical security update. Rachel Baker, one of the lead developers of the WP REST API plugin says, “The release fixes a serious information disclosure vulnerability, which allowed for unpublished content and post revisions to be retrieved via the REST API.” The security vulnerability affects versions 1.2.0 and earlier. The security…

  • Persistent XSS Vulnerability Discovered in WP Super Cache Plugin

    Persistent XSS Vulnerability Discovered in WP Super Cache Plugin

    The security team at Sucuri has issued an advisory for WordPress users who have the WP Super Cache plugin activated on their sites. The popular caching plugin contains a dangerous persistent XSS vulnerability that was promptly patched in its 1.4.4 release. Sucuri ranks the risk as “Dangerous” with a DREAD score of 8/10. Exploiting the…

  • FBI Warns of ISIL Defacement Attacks on WordPress Sites

    FBI Warns of ISIL Defacement Attacks on WordPress Sites

    The FBI issued a public service announcement today, warning concerning WordPress website attacks being carried out by individuals sympathetic to the Islamic State in the Levant (ISIL) a.k.a. Islamic State of Iraq and al-Shams (ISIS). The perpetrators of these attacks are defacing sites across various platforms such as news organizations, businesses, government sites, and religious…

  • Slack Adds Two-Factor Authentication Support After Recent Security Breach

    Slack Adds Two-Factor Authentication Support After Recent Security Breach

    Slack, which is used by thousands of people world-wide to communicate, recently suffered a security breach. According to Slack, the breach occurred during a four-day period in February. Hackers gained access to a central database used to store user names, email addresses, and one-way encrypted (“hashed”) passwords. In addition, the database contains information that users…

  • Jetpack 3.4 Adds Protection Against Brute Force Attacks

    Jetpack 3.4 Adds Protection Against Brute Force Attacks

    Last August, Automattic acquired Parka, LLC, the makers of the BruteProtect security tool for WordPress, with the goal of integrating its features into Jetpack. The services provided in BruteProtect Pro were subsequently offered for free. Jetpack 3.4 was released today with brute force protection available to users via a new module called Protect. You can…

  • Hackers Hijack Fancybox Plugin to Deface WordPress Sites with ISIS Propaganda

    Hackers Hijack Fancybox Plugin to Deface WordPress Sites with ISIS Propaganda

    Last month a vulnerability was discovered in the Fancybox for WordPress plugin, making it possible for a hacker to inject an iframe into the website without needing administrator access. Although the issue was promptly patched, a string of seemingly random WordPress websites were recently compromised using this vulnerability. Hackers claiming to be acting on behalf…

  • Pods Framework Security Release Fixes Severe Vulnerability

    Pods Framework Security Release Fixes Severe Vulnerability

    Last week a blind SQL injection vulnerability was discovered in Yoast’s popular WordPress SEO plugin. Given the severity of the vulnerability and the fact that the plugin is installed on more than one million WordPress sites, the security team at WordPress.org pushed a forced update to mitigate the possibility of mass exploitation. Following this incident,…

  • WPWeekly Episode 183 – Backing Up The Backup

    WPWeekly Episode 183 – Backing Up The Backup

    In this episode of WordPress Weekly, Marcus Couch and I discuss a lot of different stories. We share our opinions on the redesigned theme and plugin directories. We discuss CodeGuard’s survey results that indicate WordPress users need a lot more education on backup plugins, strategies, and services. Last but not least, we discuss the WordPress…

  • Blind SQL Injection Vulnerability Discovered in WordPress SEO Plugin by Yoast: Immediate Update Recommended

    Blind SQL Injection Vulnerability Discovered in WordPress SEO Plugin by Yoast: Immediate Update Recommended

    A blind SQL injection vulnerability was discovered today in the popular WordPress SEO plugin by Yoast. WPScanVulnerability Database issued an advisory after responsibly disclosing the vulnerability to the plugin’s author: The latest version at the time of writing (1.7.3.3) has been found to be affected by two authenticated (admin, editor or author user) Blind SQL…

  • bbPress 2.5.5 Released, Patches Three Potential Security Vulnerabilities

    bbPress 2.5.5 Released, Patches Three Potential Security Vulnerabilities

    bbPress 2.5.5 is available for download. This release fixes three potential security vulnerabilities reported by J.D. Grimes and was pushed out within nearly 24 hours of being notified. Users should update as soon as possible as all previous 2.x versions are vulnerable. The patches have also been applied to the 2.6 development branch that will…

  • WordPress Publishes Security White Paper

    WordPress Publishes Security White Paper

    As WordPress currently powers 23% of the web, the platform’s security is constantly under scrutiny. WordPress has long been a favorite target of hackers and spammers who want to get the most return on their efforts. Since the the platform powers millions of websites, a critical vulnerability with a popular plugin or WordPress core can…

  • It’s Time For WordPress to Automatically Update Themes, Plugins, and Core by Default

    It’s Time For WordPress to Automatically Update Themes, Plugins, and Core by Default

    Over the weekend, the WordPress plugin directory implemented a major change that better reflects how popular a plugin is. The number of total downloads has been replaced with the number of active installs. While the numbers are not exact, they’re close enough to give people insight into usage. When it comes to reporting WordPress plugin…

  • High Risk Security Vulnerability Discovered in WP Slimstat, Update Immediately

    High Risk Security Vulnerability Discovered in WP Slimstat, Update Immediately

    If you use WP Slimstat, you’ll want to make sure you’re using version 3.9.6 or later as Sucuri has discovered a severe SQL injection vulnerability in versions 3.9.5 and lower. WP Slimstat is an analytics plugin for WordPress that provides real-time monitoring, heatmaps, and other features to monitor website data. According to Sucuri, the vulnerability…