Tag: security

  • WordPress 4.6.1 Released, Patches Two Security Vulnerabilities

    WordPress 4.6.1 Released, Patches Two Security Vulnerabilities

    WordPress 4.6.1 is available and users are strongly encouraged to update immediately as it patches two security vulnerabilities. The first is a cross-site scripting vulnerability related to image filenames that was reported by Cengiz Han Sahin, a SumOfPwn researcher. The second is a path traversal vulnerability in the upgrade package uploader reported by Dominik Schilling,…

  • Jetpack 4.2 Released with Performance and Security Updates

    Jetpack 4.2 Released with Performance and Security Updates

    Jetpack 4.2 is a combination release with performance improvements and fixes for a couple of security vulnerabilities. These updates secure Contact Form submission exports from potential formula injections and fix a general XSS vulnerability in the misuse of the add_query_arg() function. The majority of enhancements in this release are centered on speeding up communication between…

  • TechCrunch Hacked by OurMine, Attackers Target Weak Passwords

    TechCrunch Hacked by OurMine, Attackers Target Weak Passwords

    TechCrunch is the latest victim in OurMine’s summer hacking rampage. The site, which is powered by WordPress and hosted via WordPress.com VIP, was hacked this morning and defaced with a message from the attackers who identify themselves as an “elite hacker group.” TechCrunch’s news ticker was updated to display: “Hello guys it’s OurMine Team, we…

  • Downtime Expected for Some WP Engine Customers as Linode Patches A Critical Security Vulnerability

    Downtime Expected for Some WP Engine Customers as Linode Patches A Critical Security Vulnerability

    WP Engine customers on legacy Xen Linode host servers are being notified via email and the company’s status blog about impending downtime between July 21st and July 25th. According to an email forwarded to the Tavern from a WP Engine customer, Linode’s legacy Xen host servers contain a critical security vulnerability. We are contacting you today…

  • 18 WordPress Plugins Updated Due to Summer of Pwnage Findings, 40+ Vulnerabilities Still in Reporting Stage

    18 WordPress Plugins Updated Due to Summer of Pwnage Findings, 40+ Vulnerabilities Still in Reporting Stage

    Summer of Pwnage, a Dutch community program for anyone interested in software security, is focusing on WordPress for its current open source security bug hunting event. The community program hosts meetups and workshops on the weekend where anyone from “enthusiastic beginners to the 1337est hackers” is welcome to share findings and demonstrate skills and exploits.…

  • bbPress 2.5.10 Patches Security Vulnerability

    bbPress 2.5.10 Patches Security Vulnerability

    John James Jacoby, lead developer of bbPress, has released bbPress 2.5.10 to patch a security vulnerability in all previous versions of the 2.X branch. This release also contains security hardening improvements where user display names and avatars are commonly displayed together. Jacoby notes that these changes affect bbPress only and don’t impact third-party themes or modifications to the…

  • All in One SEO 2.3.7 Patches Persistent XSS Vulnerability

    All in One SEO 2.3.7 Patches Persistent XSS Vulnerability

    Semper Fi Web Design, the company behind All in One SEO, a popular WordPress SEO optimization plugin that’s active on more than 1M sites, has released 2.3.7 to patch a persistent XSS security vulnerability. According to the plugin’s changelog, 2.3.7 sanitizes the Bad Bots module referer and user agent. While it doesn’t sound significant on the surface, this…

  • WordPress 4.5.3 Fixes 7 Security Issues

    WordPress 4.5.3 Fixes 7 Security Issues

    WordPress 4.5.3 was released today to fix seven important security issues that affect 4.5.2 and prior versions. Automatic background updates are already rolling out and all users are advised to update immediately. The release patches the following security issues: Redirect bypass in the customizer (reported by Yassine Aboukir) Two different XSS problems via attachment names…

  • Jetpack 4.0.4 Released, Patches 3 Security Vulnerabilities

    Jetpack 4.0.4 Released, Patches 3 Security Vulnerabilities

    Jetpack 4.0.4 is available for download and users are encouraged to update as soon as possible. This release contains a number of security fixes, including extra security to post by email, a patched XSS vulnerability in the Likes module, and a fix to ensure that submitted Feedback forms are not publicly available via the REST…

  • Critical Vulnerability Patched in EWWW Image Optimizer Plugin

    Critical Vulnerability Patched in EWWW Image Optimizer Plugin

    Yesterday the security team at Wordfence disclosed a critical remote code execution vulnerability in the EWWW Image Optimizer to Shane Bishiop, the plugin’s author. Bishop acted quickly to patch the plugin and an update was pushed out to WordPress.org users this morning. According to Wordfence, the vulnerability affects multisite WordPress installations, allowing an attacker to…

  • WP Mobile Detector Plugin Patched for Arbitrary File Upload Vulnerability, Exploits Ongoing

    WP Mobile Detector Plugin Patched for Arbitrary File Upload Vulnerability, Exploits Ongoing

    Researchers at Sucuri are reporting that the WP Mobile Detector plugin has been patched for an arbitrary file upload vulnerability that is being actively exploited in the wild. The plugin, which was temporarily removed from the WordPress Plugin Directory, had more than 10,000 active installs before the exploits began. According to Sucuri, the majority of…

  • Jetpack 4.0.3 Patches a Critical XSS Vulnerability

    Jetpack 4.0.3 Patches a Critical XSS Vulnerability

    Jetpack 4.0.3 is a security release that contains an important fix for a critical vulnerability that has been present in the plugin since version 2.0, released in 2012. According to Jetpack team member Sam Hotchkiss, a stored XSS vulnerability was found in the way that some Jetpack shortcodes are processed, which allows an attacker to…

  • WPWeekly Episode 234 – All Things WordCamp with Andrea Middleton

    WPWeekly Episode 234 – All Things WordCamp with Andrea Middleton

    In this episode of WordPress Weekly, Marcus Couch and I are joined by Andrea Middleton, who works at Automattic as a Community Organizer for the WordPress open source project. We discuss a number of topics including, updates to the WordCamp Central website, the for-profit subsidiary, and the experimental WordCamp incubator program. At the conclusion of…

  • Critical Vulnerabilities Found in PhpStorm, Immediate Update Advised

    Critical Vulnerabilities Found in PhpStorm, Immediate Update Advised

    JetBrains announced today that it has released a security update for PhpStorm and all of its other IntelliJ-based IDEs due to a set of critical vulnerabilities: The cross-site request forgery (CSRF) flaw in the IDE’s built-in webserver allowed an attacker to access local file system from a malicious web page without user consent. Over-permissive CORS…

  • WordPress 4.5.2 Patches Two Security Vulnerabilities

    WordPress 4.5.2 Patches Two Security Vulnerabilities

    The WordPress core team has released WordPress 4.5.2 which patches two security vulnerabilities in WordPress versions 4.5.1 and below. The first is a SOME vulnerability (Same-Origin Method Execution) in Plupload, the third-party library WordPress uses for uploading files. The second is a reflected cross-site-scripting vulnerability in MediaElement.js, the third-party library used for media players. Auto…