Plugins

  • WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

    WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

    Patchstack is reporting an Insecure Direct Object References (IDOR) vulnerability in WooCommerce Stripe Gateway, the most popular WooCommerce Stripe payment plugin with more than 900,000 active users. It was discovered by Patchstack researcher Rafie Muhammad on April 17, 2023, and patched by WooCommerce on May 30, 2023, in version 7.4.1. The security advisory describes the…

  • WordPress.org Enables Commercial and Community Filters on Plugin and Theme Directories

    WordPress.org Enables Commercial and Community Filters on Plugin and Theme Directories

    During the 2022 State of the Word, Matt Mullenweg announced a plan to add new “Community” and “Commercial” taxonomies for the theme and plugin directories that would help users more quickly ascertain the purpose of the extensions they are considering. Shortly after the announcement, instructions were published for theme and plugin authors to opt into…

  • MariaDB Health Checks Plugin Now Available on WordPress.org

    MariaDB Health Checks Plugin Now Available on WordPress.org

    A new MariaDB Health Checks plugin is now available on WordPress.org, thanks to the efforts of contributors involved in the 2023 CloudFest Hackathon which took place in Germany. MariaDB is a popular open source database used by those looking to further scale their websites, as it is generally faster than MySQL with better support for…

  • ACF Plugin’s Reflected XSS Vulnerability Attracts Exploit Attempts Within 24 Hours of Public Announcement

    ACF Plugin’s Reflected XSS Vulnerability Attracts Exploit Attempts Within 24 Hours of Public Announcement

    On May 5, Patchstack published a security advisory about a high severity reflected cross-site scripting (XSS) vulnerability in ACF (Advanced Custom Fields), potentially affecting more than 4.5 million users. WP Engine patched the vulnerability on May 4, but the Akamai Security Intelligence Group (SIG)  is reporting that attackers began attempting to exploit it within 24…

  • ACF Launches New Annual Survey

    ACF Launches New Annual Survey

    WP Engine has launched an annual survey for Advanced Custom Fields (ACF), one of the plugins it acquired from Delicious Brains in 2022. ACF reports more than 4.5 million active users, including PRO site installs, and WP Engine Product Manager Iain Poulson reports that the plugin is “growing in every way since the acquisition.” ACF…

  • Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

    Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

    Essential Addons for Elementor, a plugin with more than a million active installs, has patched an unauthenticated privilege escalation vulnerability in version 5.7.2. The vulnerability was discovered on May 8, 2023, and reported by Patchstack researcher Rafie Muhammad. It was given a 9.8 (Critical severity) CVSS 3.1 score and is not yet known to have been…

  • Advanced Custom Fields Plugin Patches Reflected XSS Vulnerability

    Advanced Custom Fields Plugin Patches Reflected XSS Vulnerability

    Advanced Custom Fields (ACF) has patched a reflected XSS vulnerability that affects versions 6.1.5 and below of ACF and ACF Pro, potentially impacting more than 2+ million users. It was discovered by Patchstack researcher Rafie Muhammad in May 2, 2023, and patched by ACF developers in version 6.1.6 on May 4, 2023. Patchstack published a security…

  • Periodic Table of WordPress Plugins Showcases 108 Most Popular Plugins

    Periodic Table of WordPress Plugins Showcases 108 Most Popular Plugins

    WordPress core committer Pascal Birchler has published a Periodic Table of WordPress Plugins to celebrate the software’s upcoming 20th anniversary. The table showcases 108 of the most popular free plugins on WordPress.org. Ten years ago Birchler created a website that showed the most popular plugins in a similar table layout, ranking them by number of…

  • Newly Rewritten WordPress SQLite Database Integration Plugin Needs Testing

    Newly Rewritten WordPress SQLite Database Integration Plugin Needs Testing

    WordPress contributors are making progress on officially supporting SQLite in core, a project that would benefit less complex sites (small to medium sites and blogs) that don’t necessarily require WordPress’ standard MySQL database. In a recent update, Yoast-sponsored core contributor Ari Stathopoulos said the SQLite Database Integration feature plugin has been rewritten, with the help…

  • Yoast SEO 20.5 Drops Support for PHP 5.6, 7.0, and 7.1

    Yoast SEO 20.5 Drops Support for PHP 5.6, 7.0, and 7.1

    Yoast SEO 20.5 was released this week with several security fixes and an improved Google SERP preview. The preview shows mobile and desktop snippets with Google’s current styling so users can see exactly how their snippets will look and tweak how they optimize them for Google Search results. Another highlight of this release is that…

  • ACF 6.1 Adds Support for Registering Custom Post Types and Taxonomies

    ACF 6.1 Adds Support for Registering Custom Post Types and Taxonomies

    ACF (Advanced Custom Fields) version 6.1 was released this week with support for creating Custom Post Types and Taxonomies. This is a long-awaited feature that users have been asking for since the earliest days of the plugin when it was still developed by its original author, Elliot Condon. When Delicious Brains acquired the plugin, the…

  • Twitter Suspends WordPress.com’s Access to Twitter API, Breaking Jetpack Social Sharing

    Twitter Suspends WordPress.com’s Access to Twitter API, Breaking Jetpack Social Sharing

    Twitter suspended WordPress.com’s access to the Twitter API without notice yesterday. Representatives at WordPress.com do not know why their access is currently blocked but are working to regain it. The API enables features like Jetpack Social’s Twitter connection. Users who rely on this Jetpack module to auto-tweet their published posts will see errors in the…

  • Navigating the New Era of AI-Assisted Code Generation in WordPress

    Navigating the New Era of AI-Assisted Code Generation in WordPress

    The world is learning new ways of moving faster with the help of AI, as the increased availability of the technology is poised to transform the way humans work. Generitive AI is decades old but recent advances and new tools like DALL-E (launched in January 2021) have made AI more accessible to the public. When…

  • Admin Menu Tree Page View 2.8 Now Supports All Public Post Types 

    Admin Menu Tree Page View 2.8 Now Supports All Public Post Types 

    The Admin Menu Tree Page View plugin, which adds a tree-view layout of content in the WordPress admin, has been refactored to support more content types. The plugin is an admin utility similar to Hierarchy or the commercial OrganizeWP plugin that reworks the CMS to show content in one place, but it offers a simpler…