Tag: security

  • Contact Form 7 Version 5.3.2 Patches Critical Vulnerability, Immediate  Update Recommended

    Contact Form 7 Version 5.3.2 Patches Critical Vulnerability, Immediate Update Recommended

    Contact Form 7 has patched a critical file upload vulnerability in version 5.3.2, released today by plugin author Takayuki Miyoshi. The plugin is installed on more than five million WordPress sites. “An unrestricted file upload vulnerability has been found in Contact Form 7 5.3.1 and older versions,” Miyoshi said. “Utilizing this vulnerability, a form submitter…

  • Easy WP SMTP 1.4.3 Patches Sensitive Data Disclosure Vulnerability

    Easy WP SMTP 1.4.3 Patches Sensitive Data Disclosure Vulnerability

    Easy WP SMTP has patched a vulnerability that allows attackers to capture the password reset link from the plugin’s debug log file and gain unauthorized access to the site. The plugin is used by more than 500,000 WordPress sites to configure and send all outgoing emails via a SMTP server so they are less likely…

  • WooCommerce Patches Vulnerability that Allowed Spam Bots to Create Accounts at Checkout

    WooCommerce Patches Vulnerability that Allowed Spam Bots to Create Accounts at Checkout

    WooCommerce 4.6.2 was released yesterday with a fix for a vulnerability that allowed account creation at checkout, even when the “Allow customers to create an account during checkout” setting is disabled. The WooCommerce team discovered it after several dozen users reported their sites were receiving spam orders, or “failed orders” where the payment details were fake.…

  • Loginizer Plugin Gets Forced Security Update for Vulnerabilities Affecting 1 Million Users

    Loginizer Plugin Gets Forced Security Update for Vulnerabilities Affecting 1 Million Users

    WordPress.org has pushed out a forced security update for the Loginizer plugin, which is active on more than 1 million websites. The plugin offers brute force protection in its free version, along with other security features like two-factor auth, reCAPTCHA, and PasswordLess login in its commercial upgrade. Last week security researcher Slavco Mihajloski discovered an…

  • All in One SEO Pack Plugin Patches XSS Vulnerability

    All in One SEO Pack Plugin Patches XSS Vulnerability

    All in One SEO Pack patched an XSS vulnerability this week that was discovered by the security researchers at Wordfence on July 10. The popular plugin has more than 2 million active installs, according to WordPress.org. Wordfence researchers categorized it as “a medium severity security issue” that could result in “a complete site takeover and…

  • Google Patches Critical Vulnerability in Site Kit Plugin

    Google Patches Critical Vulnerability in Site Kit Plugin

    In late April Wordfence discovered a critical vulnerability in Google’s Site Kit plugin for WordPress that would make it possible for any user on the site to gain full access to the Google Search Console without verifying ownership. Google patched the vulnerability and released the fix in version 1.8.0 on May 7, 2020. Wordfence published…

  • WordPress 5.2.4 Release Addresses Several Security Issues

    WordPress 5.2.4 Release Addresses Several Security Issues

    The core WordPress team released version 5.2.4 of WordPress on October 14. The release addresses six security issues that were all privately reported through WordPress’ responsible disclosure procedure. Like any security release, users should update immediately to the latest version to keep their sites secure. For those with automatic updates enabled, the new version is…

  • Rich Reviews Plugin Discontinued after Vulnerabilities Exploited in the Wild

    Rich Reviews Plugin Discontinued after Vulnerabilities Exploited in the Wild

    After tracking exploits of a zero day XSS vulnerability in the Rich Reviews plugin for WordPress, Wordfence is recommending that users remove it from their websites. The company estimates that there are 16,000 active installations vulnerable to unauthenticated plugin option updates: Attackers are currently abusing this exploit chain to inject malvertising code into target websites.…

  • Proposal to Auto-Update Old Versions of WordPress to 4.7 Sparks Heated Debate

    Proposal to Auto-Update Old Versions of WordPress to 4.7 Sparks Heated Debate

    WordPress contributors, developers, and community members are currently debating a proposal to would implement a new policy regarding security support for older versions. The discussion began last week when security team lead Jake Spurlock asked for feedback on different approaches to backporting security fixes to older versions. Following up on this discussion, Ian Dunn, a…

  • WordPress Security Team Discusses Backporting Security Releases to Fewer Versions

    WordPress Security Team Discusses Backporting Security Releases to Fewer Versions

    The WordPress Security Team is exploring different approaches to backporting security fixes to older versions of the software. The effort that goes into supporting versions back to 3.7 (the release that introduced automatic background updates) increases with each major version released. “For the Core Security team, that means when security updates need to be released,…

  • WP Super Cache 1.6.9 Patches Security Issue

    WP Super Cache 1.6.9 Patches Security Issue

    There’s a new release of WP Super Cache (1.6.9) available that patches a security issue discovered in the debug log. The vulnerability can only be exploited if users have debugging enabled. It’s highly recommended that all users upgrade to 1.6.9 to patch the security issue. Details of the vulnerability will be published after users have…

  • All-in-One WP Migration 7.0 Patches XSS Vulnerability

    All-in-One WP Migration 7.0 Patches XSS Vulnerability

    Those who use the All-in-One WP Migration plugin are encouraged to update to version 7.0 as soon as possible as 6.97 contains an admin backend cross-site-scripting vulnerability. An attacker would already have to be able to either compromise the database or gain access to a user account with high enough privileges to view the backup…

  • WPWeekly Episode 353 – Slack of Boundaries and A Walk to WCEU

    WPWeekly Episode 353 – Slack of Boundaries and A Walk to WCEU

    In this episode, John James Jacoby and I discuss an article published by Vox on how Slack is not improving productivity, especially in large team environments. We highlight what’s new in WordPress 5.2.1, why libraries are important to the communities they serve, and new security features in WordPress 5.2. At the end of the show,…

  • WordPress 5.2 Improves the Security of Automatic Updates

    WordPress 5.2 Improves the Security of Automatic Updates

    WordPress 5.2, released earlier this month, added the first step towards fully secure updates with offline digital signatures. Scott Arciszewski, Chief Development Officer for Paragon Initiative Enterprises, explains how it works and how developers can migrate away from mcrypt to libsodium. When your WordPress site installs an automatic update, from version 5.2 onwards, it will…

  • PluginVulnerabilities.com is Protesting WordPress.org Support Forum Moderators by Publishing Zero-Day Vulnerabilities

    PluginVulnerabilities.com is Protesting WordPress.org Support Forum Moderators by Publishing Zero-Day Vulnerabilities

    A security service called Plugin Vulnerabilities, founded by John Grillot, is taking a vigilante approach to addressing grievances against WordPress.org support forum moderators. The company is protesting the moderators’ actions by publishing zero-day vulnerabilities (those for which no patch has been issued) and then attempting to contact the plugin author via the WordPress.org support forums:…