Month: April 2015

  • XSS Vulnerability Affects More Than a Dozen Popular WordPress Plugins

    XSS Vulnerability Affects More Than a Dozen Popular WordPress Plugins

    For the past week, security firm Sucuri has worked with the WordPress core security team to address a cross site scripting vulnerability discovered in more than a dozen popular WordPress plugins. The vulnerability stems from the improper use of the add_query_arg() and remove_query_arg() functions. Inaccurate information within the WordPress Codex lead many developers to assume…

  • WordCamp Belgrade Will Be Streaming Live Saturday, April 18

    WordCamp Belgrade Will Be Streaming Live Saturday, April 18

    WordCamp Belgrade will take place this weekend, April 18-19. Two years ago the WordPress community in Serbia was virtually non-existent but has grown rapidly and is now large enough to host the very first WordCamp in Belgrade. Registration kicks off at 8AM tomorrow morning where organizers will debut Wapuujlo, the official mascot of the event.…

  • Confessions of a WordPress Trac Ticket Lobbyist

    Confessions of a WordPress Trac Ticket Lobbyist

    This post was contributed by Robert Dall. Studying web design in college, he stumbled upon WordPress.com early in his career. Dall made the natural progression from WordPress.com to the self-hosted version of WordPress. Since then, he’s worked almost exclusively with WordPress using it as a blog, CMS, portfolio, and e-commerce. He’s also an avid photographer. Coming…

  • BuddyPress 2.3 Will Improve Avatar Uploads with the New BP Attachments API

    BuddyPress 2.3 Will Improve Avatar Uploads with the New BP Attachments API

    BuddyPress contributors are polishing up new and existing APIs for the upcoming 2.3 release. For the past several months, core developer Mathieu Viet (@imath) has been spearheading the effort to get the new Attachments API ready for 2.3 with the help of contributions and feedback from the core team. The Attachments API is a new…

  • VersionPress 1.0 Sees the Light of Day

    VersionPress 1.0 Sees the Light of Day

    In mid 2014, Borek Bernard and Jan Voráček from the Czech Republic, launched a crowdfunding campaign to fund the development of VersionPress. VersionPress is a version control plugin for WordPress. It keeps the whole site in a Git repository enabling things like site-wide reverts, safe updates, and easy staging. Despite not reaching their funding goal,…

  • Documentation Post Type: A WordPress Plugin for Documenting Products

    Documentation Post Type: A WordPress Plugin for Documenting Products

    A product’s documentation is usually a strong indicator of its quality, but creating docs is often the least exciting aspect of launching something new. Products that lack documentation can create a greater support burden, forcing you to write docs as a defensive measure after the fact. The free Documentation Post Type plugin may be just…

  • Cloudup Refreshes Its Web Interface and OSX 10.10 Desktop App

    Cloudup Refreshes Its Web Interface and OSX 10.10 Desktop App

    Cloudup, the file storage and sharing service acquired by Automattic in 2013, has refreshed its web interface. Many of the changes are subtle and place more emphasis on your content. Stats and FAQ links have been moved under the account menu. On the desktop and mobile versions of the site, the add new file button…

  • WPWeekly Episode 188 – The Nearly Perfect WordPress Role Model

    WPWeekly Episode 188 – The Nearly Perfect WordPress Role Model

    Marcus Couch and I didn’t have a guest on this week’s episode, so we used the time to get you caught up on the week’s headlines. We discussed the release of WordPress 4.2 RC1 and if all goes well, expect to see the release of 4.2 next Wednesday. If you use iThemes Security, you’ll want…

  • Banking on WordPress: Matt Mullenweg Weighs in on Security Concerns

    Banking on WordPress: Matt Mullenweg Weighs in on Security Concerns

    If you follow WordPress topics on Quora, you may have noticed a popular question making the rounds regarding security. The question has been viewed more than 30,000 times: I am powering a bank’s website using WordPress. What security measures should I take? Ordinarily, such a question is a magnet for trollish responses and uninformed WordPress…

  • Easy Digital Downloads Turns 3 Years Old

    Easy Digital Downloads Turns 3 Years Old

    Pippin Williamson, founder of Easy Digital Downloads, looks back on three years of building an e-Commerce product for WordPress. Williamson describes the last three years as containing some of the highest and lowest points of his life. Williamson acknowledged that without his dedicated team, the product wouldn’t be anywhere close to what it is today.…

  • WooCommerce Dominates Global E-Commerce Platforms, Passes 7 Million Downloads

    WooCommerce Dominates Global E-Commerce Platforms, Passes 7 Million Downloads

    Last week WooCommerce announced that the plugin had passed 7 million downloads and the WordPress.org plugin directory reports that it is currently in use on over a million websites. WooCommerce is not only head of the pack when it comes to WordPress e-commerce solutions, the plugin is also the global leader among e-commerce platforms. According…

  • Group and Filter Plugins by Functionality with Plugin Groups by CalderaWP

    Group and Filter Plugins by Functionality with Plugin Groups by CalderaWP

    Plugins such as WooCommerce and Ninja Forms have a lot of extensions available to add functionality and each extension is usually a separate plugin. Depending on the functionality you need, extensions can add several additional plugins to the plugin management page in the backend of WordPress. Plugin Groups is a free new plugin by CalderaWP…

  • iThemes Patches Vulnerability that Affects All Versions of the iThemes Security Plugin

    iThemes Patches Vulnerability that Affects All Versions of the iThemes Security Plugin

    iThemes has released new versions of iThemes Security and iThemes Security Pro to address a critical security vulnerability. Every version of both plugins is at risk, including Better WP Security 3.0. The vulnerability allowed potentially dangerous JavaScript to run when viewing 404 logs. When the 404 Detection feature is enabled, data about requests for non-existent…

Newsletter

Subscribe Via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.