Tag: security

  • Jetpack 5.6.1 Increases Security of the Contact Form Module

    Jetpack 5.6.1 Increases Security of the Contact Form Module

    Jetpack has released version 5.6.1 which hardens the Contact Form module by improving permissions checking when updating a form's settings. In addition to security fixes, the character count for when Publicize publishes content to Twitter has been increased to 280. This release also fixes a bug that disabled the ability to save widgets after removing…

  • WordPress 4.9.1 Released, Fixes Page Template Bug

    WordPress 4.9.1 Released, Fixes Page Template Bug

    WordPress 4.9.1 is available for download and is a maintenance and security release. This release addresses four security issues in WordPress 4.9 and below that could potentially be used as part of a multi-vector attack. According to the release notes, the following changes have been made to WordPress to protect against these vulnerabilities. Use a…

  • GitHub Launches Security Alerts for JavaScript and Ruby Projects, Python Support Coming in 2018

    GitHub Launches Security Alerts for JavaScript and Ruby Projects, Python Support Coming in 2018

    Last month GitHub launched its Dependency Graph feature that tracks a repository’s dependencies and sub-dependencies under the Insights tab. This week the company rolled out an expansion of the feature and will now identify known vulnerabilities and send notifications with suggested fixes from the GitHub community. Dependency graphs and security alerts are automatically enabled for…

  • WPWeekly Episode 293 – WordPress 4.8.3, RIP Firebug, and Patreon

    WPWeekly Episode 293 – WordPress 4.8.3, RIP Firebug, and Patreon

    In this episode, John James Jacoby and I discuss the news of the week including, a behind the scenes look at how WordPress 4.8.3 was released, WordPress 4.9 RC1, and Patreon launching an app directory along with a free WordPress plugin. We also talk about the difficulties of surveys, from asking the right questions, to…

  • WordPress 4.8.3, A Security Release Six Weeks in the Making

    WordPress 4.8.3, A Security Release Six Weeks in the Making

    WordPress 4.8.3 is available and is a security release for 4.8.2 and all previous versions. This release addresses an issue with $wpdb->prepare() that could lead to a potential SQL injection. While WordPress core is not vulnerable, hardening has been added to prevent plugins and themes from inadvertently causing a vulnerability. If you’re experiencing a bit…

  • Postman SMTP Plugin Forked after Removal from WordPress.org for Security Issues

    Postman SMTP Plugin Forked after Removal from WordPress.org for Security Issues

    In early October the popular Postman SMTP plugin was removed from WordPress.org due to security issues. The plugin had not been updated in two years and also contained a reflected cross-site scripting (XSS) vulnerability that was made public in June and left unfixed. The security researcher’s attempts to contact the plugin’s author, Jason Hendriks, were…

  • GitHub Launches New Dependency Graph Feature with Security Alerts Coming Soon

    GitHub Launches New Dependency Graph Feature with Security Alerts Coming Soon

    GitHub announced a new Dependency Graph feature at the Github Universe conference yesterday. It lists all the dependencies for a repository and will soon identify known vulnerabilities. The graph can be accessed under the Insights tab and currently supports Ruby and JavaScript dependencies with Python coming soon. Public repositories display the graph by default and…

  • Disqus Data Breach Affects 17.5 Million Accounts

    Disqus Data Breach Affects 17.5 Million Accounts

    Disqus, a comment management and hosting service, has announced it suffered a data breach that affects 17.5 million users. A snapshot of its database from 2012 with information dating back to 2007 containing email addresses, usernames, sign-up dates, and last login dates in plain-text were exposed. Passwords hashed with the SHA1 protocol and a salt…

  • New WP-CLI Project Aims to Extend Checksum Verification to Plugins and Themes

    New WP-CLI Project Aims to Extend Checksum Verification to Plugins and Themes

    The WP-CLI team is initiating a new project that aims to bring checksum verification to plugins and themes. Checksums are a method of verifying the integrity of files. Three years ago, WP-CLI added the capability of verifying WordPress core checksums using the MD5 algorithm. This is a useful security feature that allows developers to easily…

  • SI CAPTCHA Anti-Spam Plugin Permanently Removed from WordPress.org Due to Spam Code

    SI CAPTCHA Anti-Spam Plugin Permanently Removed from WordPress.org Due to Spam Code

    The SI CAPTCHA Anti-Spam plugin has been removed from the WordPress Directory due to its author including spam code. The plugin added a CAPTCHA image test to WordPress forms to prevent spam and was compatible with forms generated by bbPress, BuddyPress, Jetpack, and WooCommerce. It had more than 300,000 active installs at the time of…

  • WordPress 4.8.2 Patches Eight Security Vulnerabilities

    WordPress 4.8.2 Patches Eight Security Vulnerabilities

    WordPress 4.8.2 is available for download and users are encouraged to update as soon as possible. This release patches eight security vulnerabilities and has six maintenance related fixes. Hardening was also added to WordPress core to prevent plugins and themes from accidentally causing a vulnerability through $wpdb->prepare() which can create unexpected and unsafe queries leading…

  • Display Widgets Plugin Permanently Removed from WordPress.org Due to Malicious Code

    Display Widgets Plugin Permanently Removed from WordPress.org Due to Malicious Code

    Display Widgets, a plugin with more than 200,000 active installs, has been removed from WordPress.org due to its authors inserting malicious code. SEO consultant David Law was the first to bring this issue to the attention of the plugin team after discovering that Display Widgets was inserting content into sites from external servers and also…

  • Equifax Launches WordPress-Powered Site for Consumers Affected by Security Breach

    Equifax Launches WordPress-Powered Site for Consumers Affected by Security Breach

    Equifax has launched a WordPress-powered website to connect with consumers affected by its recent security breach, which compromised 143 million customers’ personal data. The exposed data includes names, birth dates, social security numbers, addresses, credit card numbers, driver’s license numbers, and other sensitive financial information. The equifaxsecurity2017.com site was launched shortly after disclosure to give…

  • SiteLock Acquires Patchman’s Malware and Vulnerability Detection Technology, Expands WordPress Customer Base to 4 Million

    SiteLock Acquires Patchman’s Malware and Vulnerability Detection Technology, Expands WordPress Customer Base to 4 Million

    SiteLock, a website security company, has acquired Patchman, a Dutch security startup that offers automated vulnerability patching and malware removal for hosting providers. Prior to the acquisition SiteLock protected 6 million sites, with 2.2 million of them running on WordPress. The addition of Patchman extends SiteLock’s customer base to 12 million sites and more than…

  • WPWeekly Episode 273 – Mental Health Awareness With Bridget Willard and Ed Finkler

    WPWeekly Episode 273 – Mental Health Awareness With Bridget Willard and Ed Finkler

    The month of May is Mental Health Awareness month. On this episode, Ed Finkler, founder of Open Sourcing Mental Illness (OSMI), and Bridget Willard, Marketing Manager for WordImpress, join me to raise awareness of mental health. We start the show by discussing what mental health is and what it means to feel normal. We talk…