Tag: security

  • User Role Editor 4.25 Patches Critical Security Vulnerability

    User Role Editor 4.25 Patches Critical Security Vulnerability

    Vladimir Garagulya, developer of the User Role Editor has patched a critical security vulnerability. User Role Editor is used to edit, manage, and create user roles and capabilities and is active on more than 300K sites. User Role Editor 4.24 and below allows any registered user to gain administrator access. Wordfence, a popular security plugin…

  • WPWeekly Episode 225 – Interview With Scott Kingsley Clark Lead Developer of Pods

    WPWeekly Episode 225 – Interview With Scott Kingsley Clark Lead Developer of Pods

    In this episode of WordPress Weekly, Marcus Couch and I interview Scott Kingsley Clark, lead developer of the Pods framework plugin. Clark explains the financial and organizational structure of the Friends of Pods program and how it benefits the plugin’s development. He also explains what the Fields API project is and its significance to WordPress.…

  • Custom Content Type Manager Plugin Update Creates a Security Nightmare

    Custom Content Type Manager Plugin Update Creates a Security Nightmare

    Over the years, we’ve told users that the WordPress plugin directory is the safest place to download and install plugins from. This is due in large part to the dedication of volunteers who act as gatekeepers and review plugins before they’re added to the directory. Plugin updates, however don’t receive the same scrutiny as there’s…

  • Roots Team Releases wp-password-bcrypt Plugin to Improve WordPress Password Security

    Roots Team Releases wp-password-bcrypt Plugin to Improve WordPress Password Security

    This week the Roots development team released wp-password-bcrypt, a plugin that uses bcrypt instead of MD5 password hashing. MD5’s known and exploited weaknesses have rendered it “cryptographically broken and unsuitable for further use,” according to the CMU Software Engineering Institute. In a post announcing the plugin, Scott Walkinshaw explained why WordPress’ default MD5 hashing function…

  • Critical Security Vulnerability Discovered in Elegant Themes Products

    Critical Security Vulnerability Discovered in Elegant Themes Products

    Elegant Themes emailed its customers last night to inform them of a critical security vulnerability affecting a large segment of its product line. An information disclosure vulnerability was found in the Divi Builder (included in our Divi and Extra themes, as well as our Divi Builder plugin) which resulted in the potential for user privilege…

  • WPWeekly Episode 220 – Automattic’s Relationship With WordPress

    WPWeekly Episode 220 – Automattic’s Relationship With WordPress

    In this episode of WordPress Weekly, Marcus Couch and I discuss the latest news in the WordPress ecosystem. On the first episode of 2016, I rant about the conspiracy theorists who believe Automattic owns and controls the WordPress project. I try to set the record straight and explain why it’s not the case. Later in…

  • WordPress 4.4.1 Patches XSS Security Vulnerability

    WordPress 4.4.1 Patches XSS Security Vulnerability

    WordPress 4.4.1 is available for download and includes 52 fixes, one of which patches a cross site scripting vulnerability reported by Crtc4L. This release address two severe bugs and updates the polyfill used for emoji to support Unicode 8. Support for Unicode 8 adds new diversity emoji to WordPress. Other notable changes include the removal…

  • Linode Confirms Data Security Breach That Matches Recent WP Engine Attack

    Linode Confirms Data Security Breach That Matches Recent WP Engine Attack

    Cloud hosting provider Linode has been combatting DDoS attacks since Christmas Day, which have caused multiple disruptions and service outages across its global data centers. The attacks are ongoing and the company is struggling to keep its status blog up to notify customers. In addition to the DDoS attacks, Linode has also confirmed a data…

  • WP Engine Identifies Cloud Infrastructure Provider as Entry Point for Recent Security Breach

    WP Engine Identifies Cloud Infrastructure Provider as Entry Point for Recent Security Breach

    On December 9th, 2015, WP Engine sent out an urgent notice to its customers regarding a security breach wherein customer credentials were exposed. This incident prompted an investigation, which is now complete. According to the most recent and final update, investigators determined that the security exposure came through one of the host’s cloud infrastructure providers.…

  • WP Engine Security Breach: Customer Credentials Exposed

    WP Engine Security Breach: Customer Credentials Exposed

    WP Engine customers received an urgent notification in their inboxes Wednesday evening regarding a security breach. At WP Engine we are committed to providing robust security. We are writing today to let you know that we learned of an exposure involving some of our customers’ credentials. Out of an abundance of caution, we are proactively…

  • Imperva’s Web Application Attack Report Shows Spam Is WordPress’ Largest Security Threat

    Imperva’s Web Application Attack Report Shows Spam Is WordPress’ Largest Security Threat

    Imperva, an international cyber security company founded in 2002, published its 2015 web application attack report. The report includes a thorough analysis of attack data obtained through its WAF or Web Application Firewall. In the report, Imperva’s application defense center group analyzed 297,954 attacks and 22,850,023 alerts on 198 of the applications it protects behind…

  • BuddyPress 2.3.5 Patches Privilege Escalation Issue

    BuddyPress 2.3.5 Patches Privilege Escalation Issue

    BuddyPress 2.3.5 is available and patches a security vulnerability that may allow privilege escalation for logged-in users. BuddyPress 2.3.4 and previous versions are affected however, versions 2.0.4, 2.1.2, and 2.2.4 include the patch. According to the BuddyPress development team, there is no evidence that the bug has been exploited in the wild. If your WordPress…

  • Jetpack 3.7.2 Patches Two Security Vulnerabilities

    Jetpack 3.7.2 Patches Two Security Vulnerabilities

    Jetpack 3.7.2 is available for download and patches two security vulnerabilities. The first is a cross-site scripting vulnerability in the contact form due to improper input sanitation that affects Jetpack 3.7.0 and below. Marc-Alexandre Montpas of Sucuri is credited with responsibly disclosing the vulnerability. The second is an information disclosure vulnerability present in certain hosting…

  • WP Super Cache 1.4.5 Patches XSS Vulnerability

    WP Super Cache 1.4.5 Patches XSS Vulnerability

    If you use WP Super Cache, you should immediately update to version 1.4.5 as it patches a XSS vulnerability in the settings page. This version also prevents PHP object injections. In addition to security patches, 1.4.5 contains a number of bug fixes. Make sure to update your sites as soon as possible to patch the…