Tag: security

  • WordPress Versions 3.7-4.0 No Longer Get Security Updates

    WordPress Versions 3.7-4.0 No Longer Get Security Updates

    In September, WordPress’ Security Team announced it would be dropping support for versions 3.7 through 4.0 by December 1, 2022. Yesterday the final releases for these versions (3.7.41, 3.8.41, 3.9.40, and 4.0.38) were made available to the very small percentage of users who are running ancient versions of WordPress. As part of the final releases,…

  • iThemes Patches Vulnerability in BackupBuddy, Wordfence Tracks 5 Million Exploit Attempts

    iThemes Patches Vulnerability in BackupBuddy, Wordfence Tracks 5 Million Exploit Attempts

    BackupBuddy, a commercial plugin from iThemes that performs scheduled backups with remote storage options, has patched a vulnerability that allowed for arbitrary file download by unauthenticated users. iThemes published an advisory for its users, indicating that the vulnerability affects versions 8.5.8.0 through 8.7.4.1 and is being actively exploited. Wordfence reviewed its data and found that…

  • WordPress To Drop Security Updates for Versions 3.7 Through 4.0 by December, 2022

    WordPress To Drop Security Updates for Versions 3.7 Through 4.0 by December, 2022

    WordPress’ Security Team announced it will be dropping support for versions 3.7 through 4.0 on December 1, 2022. To give some context for how old these versions are, in 2013, WordPress 3.7 introduced automatic background updates and 3.8 updated the admin with a new design based on the MP6 plugin. WordPress’ official policy is that…

  • #35 – Akshat Choudhary on the State of WordPress Security

    #35 – Akshat Choudhary on the State of WordPress Security

    On the podcast today we have Akshat Choudhary. Akshat is the Founder and CEO of BlogVault, MalCare, WP Remote and Airlift. These WordPress plugins allow their customers to build, manage and maintain their WordPress websites. He’s based in Bangalore, India and we begin the podcast talking about the state of the WordPress community there. We…

  • WordPress.org Forces Security Update for Critical Ninja Forms Vulnerability

    WordPress.org Forces Security Update for Critical Ninja Forms Vulnerability

    Late last week, Ninja Forms users received a forced security update from WordPress.org for a critical PHP Object Injection vulnerability. This particular vulnerability can be exploited remotely without any authentication. It was publicly disclosed last week and patched in the latest version, 3.6.11. Patches were also backported to versions 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, and…

  • #20 – Oliver Sild on the State of WordPress Security

    #20 – Oliver Sild on the State of WordPress Security

    On the podcast today we have Oliver Sild from Patchstack. Patchstack is a product which is designed to help you identify plugin vulnerabilities in your WordPress sites. We talk about how, over the past couple of years, Patchstack has released an annual report concerning the state of WordPress security. What are the broad security trends…

  • Patchstack Whitepaper: WordPress Ecosystem Records 150% Increase in Security Vulnerabilities in 2021

    Patchstack Whitepaper: WordPress Ecosystem Records 150% Increase in Security Vulnerabilities in 2021

    Patchstack has published its State of WordPress Security whitepaper with a summary of threats to the WordPress ecosystem recorded in 2021. The whitepaper aggregates data from multiple sources, including the Patchstack Vulnerability Database, the Patchstack Alliance (the company’s bug bounty platform), and publicy reported CVEs from other sources. In 2021, Patchstack recorded nearly 1,500 vulnerabilities,…

  • UpdraftPlus 1.22.3 Patches Severe Vulnerability Through Forced Security Update from WordPress.org

    UpdraftPlus 1.22.3 Patches Severe Vulnerability Through Forced Security Update from WordPress.org

    UpdraftPlus, a plugin that allows users to backup to various cloud providers, has patched a severe security vulnerability that would allow logged-in users to download a site’s latest backups. The patched version (1.22.3) was sent out via a forced auto-update, a measure reserved for severe vulnerabilities that affect a large number of users. UpdraftPlus is active…

  • Essential Addons for Elementor Patches Critical Security Vulnerability

    Essential Addons for Elementor Patches Critical Security Vulnerability

    Essential Addons for Elementor, a popular plugin with more than a million active installs, has patched a critical vulnerability that would allow for a local file inclusion attack. The vulnerability was discovered by security researcher Wai Yan Myo Thet and reported to Patchstack on January 25, 2022. Patchstack customers received a virtual patch the same…

  • All In One SEO Plugin Patches Severe Vulnerabilities

    All In One SEO Plugin Patches Severe Vulnerabilities

    The All In One SEO plugin has patched a set of severe vulnerabilities that were discovered by the Jetpack Scan team two weeks ago. Version 4.1.5.3, released December 8, includes fixes for a SQL Injection vulnerability and a Privilege Escalation bug. Marc Montpas, the researcher who discovered the vulnerabilities, explained how they could be exploited:…

  • GoDaddy Data Breach Exposes 1.2 Million Active and Inactive Managed WordPress Hosting Accounts

    GoDaddy Data Breach Exposes 1.2 Million Active and Inactive Managed WordPress Hosting Accounts

    In a disclosure to the U.S. Securities and Exchange Commission (SEC) that was published today, GoDaddy announced a data security breach impacting its WordPress managed hosting customers. The company discovered unauthorized third-party access to its hosting environment on November 17, 2021, through an exploited vulnerability. GoDaddy’s initial investigations show the attacker gained access using a…

  • Patchstack Releases Free Security Plugin, Its Red Team Found 1,182 Vulnerabilities Since March

    Patchstack Releases Free Security Plugin, Its Red Team Found 1,182 Vulnerabilities Since March

    In September, Patchstack released its six-month report on the vulnerabilities found with WordPress and its extensions. At the time, it listed over 1,000 issues — the company has shared the updated numbers with WP Tavern. It soon followed that up with a free vulnerability-reporting plugin. Under the banner of WebARX, the company launched the first…

  • OptinMonster 2.6.5 Patches Multiple Security Vulnerabilities

    OptinMonster 2.6.5 Patches Multiple Security Vulnerabilities

    In late September, Chloe Chamberland, a researcher at Wordfence, discovered multiple security vulnerabilities in the OptinMonster plugin, which could allow unauthenticated attackers to export sensitive information and inject malicious JavaScript into vulnerable sites. The OptinMonster team promptly patched the plugin and updated the plugin again after more feedback from the Wordfence team. Version 2.6.5 was…

  • WP Fastest Cache Patches Authenticated SQL Injection and Stored XSS Via CSRF Vulnerabilities

    WP Fastest Cache Patches Authenticated SQL Injection and Stored XSS Via CSRF Vulnerabilities

    The Jetpack Scan team has published a summary of two issues recently discovered in the WP Fastest Cache plugin – an Authenticated SQL Injection vulnerability and a Stored XSS Via CSRF vulnerability. “If exploited, the SQL Injection bug could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords),” Automattic…

  • WooCommerce 5.7.0 Patches Security Issue that Could Potentially Leak Analytics Reports

    WooCommerce 5.7.0 Patches Security Issue that Could Potentially Leak Analytics Reports

    WooCommerce shipped version 5.7.0 through a forced update for some users earlier this week. The minor release was not billed as a security update but the following day WooCommerce published a post explaining that the plugin was vulnerable to having analytics reports leaked on some hosting configurations: On September 21, 2021, our team released a…