Tag: security

  • WPWeekly Episode 263 – Plugins Disappearing, WordCamp Miami, and OSTraining

    WPWeekly Episode 263 – Plugins Disappearing, WordCamp Miami, and OSTraining

    In this episode, Marcus Couch and I discuss the news making headlines including, WordCamp Miami in its 9th year, OSTraining partnering with GoDaddy to release training videos, and why plugins sometimes disappear from the WordPress plugin directory. We also provide an update on the REST API vulnerability that is actively being exploited to deface webpages.…

  • Matt Mullenweg Responds to Security Rant: Digital Signatures for WordPress Updates Are Important but Not a Priority

    Matt Mullenweg Responds to Security Rant: Digital Signatures for WordPress Updates Are Important but Not a Priority

    Scott Arciszewski, Chief Development Officer for Paragon Initiative Enterprises, who is most widely known for his cryptography engineering work, published a post on Medium criticizing Matt Mullenweg, co-creator of the WordPress open-source software project, for not caring enough about security. Arciszewski has since retracted the post but you can read it via the Wayback Machine.…

  • Why Plugins Sometimes Disappear From the WordPress Plugin Directory

    Why Plugins Sometimes Disappear From the WordPress Plugin Directory

    Nearly 50K publicly available plugins call the WordPress plugin directory home but once in awhile a few of them seem to disappear. There is usually a good reason for why this happens but the only information available to the public is a page that says the plugin cannot be found. If the plugin is popular…

  • WordPress REST API Vulnerability Exploits Continue

    WordPress REST API Vulnerability Exploits Continue

    It has been nearly two weeks since the WordPress security team disclosed an unauthenticated privilege escalation vulnerability in a REST API endpoint in 4.7 and 4.7.1. The vulnerability was patched silently and disclosure was delayed for a week to give WordPress site owners a head start on updating to 4.7.2. Last week hundreds of thousands…

  • WPWeekly Episode 262 – Interview With Morten Rand-Hendriksen

    WPWeekly Episode 262 – Interview With Morten Rand-Hendriksen

    On this episode, Marcus Couch and I are joined by Morten Rand-Hendriksen to discuss his WordPress Telemetry proposal. We discuss the potential benefits of having an opt-in usage data collection system that could help core developers and others make informed decisions. Rand-Hendriksen also shares what he’s learned from teaching WordPress at Lynda.com, on how difficult…

  • WP Super Cache 1.4.9 Patches Multiple XSS Vulnerabilities

    WP Super Cache 1.4.9 Patches Multiple XSS Vulnerabilities

    WP Super Cache is a nearly 10-year-old plugin that is maintained by Donncha Ó Caoimh and is actively installed on more than a million sites. Releases have been far and few between, but Ó Caoimh has released WP Super Cache 1.4.9 that patches cross-site-scripting vulnerabilities on the settings page. “Those pages are only accessible by admin…

  • WPWeekly Episode 261 – WordPress for Schools With Cameron Barrett

    WPWeekly Episode 261 – WordPress for Schools With Cameron Barrett

    In this episode, Marcus Couch and I are joined by Cameron Barrett, founder of SchoolPresser, LLC. Barrett explains how he negotiated and helped migrate Newark New Jersey’s public school system from a proprietary CMS to WordPress. He shares the pitfalls he experienced and the amount of money the district is saving since making the switch.…

  • Aaron D. Campbell Replaces Nikolay Bachiyski as WordPress’ Security Czar

    Aaron D. Campbell Replaces Nikolay Bachiyski as WordPress’ Security Czar

    Aaron D. Campbell, WordPress Core Contributor at GoDaddy, is replacing Nikolay Bachiyski as WordPress’ Security Czar or WordPress Core Security Team Lead. The role was created in 2015 to provide more structure and focus around incident responses. “The responsibilities of the position include, organizing the security team and making sure all security concerns and reports…

  • WordPress 4.7.1 Fixes Eight Security Issues

    WordPress 4.7.1 Fixes Eight Security Issues

    WordPress 4.7.1 is available for download and fixes eight security issues that affect WordPress 4.7 and below. The PHPMailer library was updated to patch a remote code execution (RCE) vulnerability. WordFence reported the vulnerability last month as critical and that it affects WordPress core. However, in the announcement post for 4.7.1, Aaron Campbell, WordPress’ new…

  • BuddyPress 2.7.4 Patches Security Vulnerability That Could Allow Arbitrary File Deletion

    BuddyPress 2.7.4 Patches Security Vulnerability That Could Allow Arbitrary File Deletion

    The BuddyPress development team has released BuddyPress 2.7.4 to address a security vulnerability that affects all versions back to 2.0. According to John James Jacoby, lead developer of BuddyPress, “This version patches a vulnerability to the BuddyPress core attachments API that could allow arbitrary file deletion on certain installation configurations.” The vulnerability was responsibly disclosed by…

  • WPWeekly Episode 256 – Interview With Tony Perez, CEO and Co-Founder of Sucuri

    WPWeekly Episode 256 – Interview With Tony Perez, CEO and Co-Founder of Sucuri

    In this episode of WordPress Weekly, Marcus Couch and I are joined by Tony Perez, co-founder and CEO of Sucuri. It’s easy to tell from this episode that Perez is extremely passionate about web security. We discussed a wide range of topics related to security including, trends involving WordPress, the FUD factor, messaging surrounding HTTPS,…

  • WP eCommerce 3.11.4 Patches SQL Injection Vulnerability

    WP eCommerce 3.11.4 Patches SQL Injection Vulnerability

    Over the weekend, the WP eCommerce team released version 3.11.4 of its e-commerce plugin. The update patches an SQL injection vulnerability that was responsibly disclosed by Mika Epstein, a member of the WordPress.org plugin review team. According to Justin Sainton, lead developer of WP eCommerce, the team was notified of the vulnerability on November 11th and patched within…

  • High Risk XSS Vulnerability Discovered in W3 Total Cache Plugin

    High Risk XSS Vulnerability Discovered in W3 Total Cache Plugin

    WP Media is reporting a high risk XSS vulnerability in W3 Total Cache that the company learned about from El Rincón de Zerial’s security blog. The plugin is currently active on more than one million WordPress sites. This particular vulnerability is found within the plugin’s support form that is embedded in the admin, according to…

  • ManageWP Launches Automated Security Scanning

    ManageWP Launches Automated Security Scanning

    When ManageWP allowed users to perform security scans of websites through the Orion interface in December of 2015, a feature commonly requested by customers was the ability to automate the scans. Nine months after implementing security checks for customers, ManageWP has added automated security scans to its assortment of features. The automated security scans are a premium feature…