Tag: security

  • Extendify Patches Vulnerabilities in the Redux Framework Plugin

    Extendify Patches Vulnerabilities in the Redux Framework Plugin

    Wordfence has published two vulnerabilities that affect users of the Redux Framework plugin, which has more recently come to be know as the “Gutenberg Template Library & Redux Framework” on WordPress.org. Extendify purchased the plugin from its creator, Dōvy Paukstys, in November 2020, in a deal that was not highly publicized. It is currently active…

  • Wordfence and WPScan Publish Mid-Year WordPress Security Report

    Wordfence and WPScan Publish Mid-Year WordPress Security Report

    WPScan is on track to post a record-breaking year for WordPress plugin vulnerabilities submitted to its database, according to a collaborative mid-year security report the company published with Wordfence. In the first half of 2021, WPScan has recorded 602 new vulnerabilities, quickly surpassing the 514 reported during all of 2020. The report is based on…

  • WooCommerce Patches Critical Vulnerability, Sending Forced Security Update from WordPress.org

    WooCommerce Patches Critical Vulnerability, Sending Forced Security Update from WordPress.org

    WooCommerce has patched an unspecified, critical vulnerability identified on July 13, 2021, by a security researcher through Automattic’s HackerOne security program. The vulnerability impacts versions 3.3 to 5.5 of the WooCommerce plugin, as well as version 2.5 to 5.5 of the WooCommerce Blocks feature plugin. “Upon learning about the issue, our team immediately conducted a…

  • Wordfence Now Authorized as a CVE Numbering Authority

    Wordfence Now Authorized as a CVE Numbering Authority

    Wordfence has been authorized by the Common Vulnerabilities and Exposures (CVE®) Program as a CNA (CVE Numbering Authority), which allows the company to directly assign CVE numbers for new vulnerabilities in WordPress core, plugins, and themes. The authority is granted by Mitre Corporation, a federally-funded US non-profit that manages research and development centers. Wordfence anticipates…

  • Jetpack 9.8 Introduces WordPress Stories Block Alongside Forced Security Update

    Jetpack 9.8 Introduces WordPress Stories Block Alongside Forced Security Update

    Jetpack 9.8 was released this week, introducing WordPress Stories as the headline feature. The Story block, which allows users to create interactive stories, was previously only available on mobile. It can now be used in the web editor. Stories went into public beta on the Android app in January 2021, and were officially released on the…

  • Patchstack Whitepaper: 582 WordPress Security Issues Found in 2020, Over 96% From Third-Party Extensions

    Patchstack Whitepaper: 582 WordPress Security Issues Found in 2020, Over 96% From Third-Party Extensions

    Patchstack, which recently rebranded from WebARX, released its 2020 security whitepaper. The report identified a total of 582 security vulnerabilities. However, only 22 of the issues came from WordPress itself. Third-party plugins and themes accounted for the remaining 96.22%. “These are all security issues disclosed by the Patchstack internal research team, Patchstack Red Team community,…

  • Zerodium Temporarily Triples Payout to $300K for WordPress Exploits

    Zerodium Temporarily Triples Payout to $300K for WordPress Exploits

    Zerodium, one of the most well-known security vulnerability brokers, announced that it is tripling payouts for remote code execution exploits on default WordPress installations. Payouts are typically $100K but have been temporarily increased to $300K. The company focuses on acquiring original and previously unreported zero-day research. It pays researchers for high-risk vulnerabilities and fully functional…

  • WebARX Rebrands To Patchstack, Combines Services To Focus on WordPress Plugin and Theme Security

    WebARX Rebrands To Patchstack, Combines Services To Focus on WordPress Plugin and Theme Security

    In 2018, WebARX launched the first version of its security platform and grew to 3,000 users. Earlier this month, the company decided to rebrand to Patchstack. Outside of customers getting the name wrong, the company had grown beyond its original SaaS product, providing other services like PlugBounty, an open-source bug-hunting platform. Earlier this year, they…

  • Elementor Patches XSS Vulnerabilities Affecting 7 Million WordPress Sites

    Elementor Patches XSS Vulnerabilities Affecting 7 Million WordPress Sites

    Elementor users who haven’t updated recently will want to get on the latest version 3.1.4 as soon as possible. Researchers at Wordfence disclosed a set of stored Cross-Site Scripting (XSS) vulnerabilities in the plugin to its authors in February, which was partially patched at that time and additional fixes were released the second week of March.…

  • Attackers Continue to Exploit Vulnerabilities in The Plus Addons for Elementor Plugin

    Attackers Continue to Exploit Vulnerabilities in The Plus Addons for Elementor Plugin

    Last week, security researchers at Seravo and WP Charged reported a critical zero-day vulnerability in The Plus Addons for Elementor on March 8, 2021. WPScan categorized it as an authentication bypass vulnerability: The plugin is being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including…

  • WPScan Can Now Assign CVE Numbers for WordPress Core, Plugin, and Theme Vulnerabilities

    WPScan Can Now Assign CVE Numbers for WordPress Core, Plugin, and Theme Vulnerabilities

    WPScan, a security company that maintains a database of WordPress vulnerabilities, has been officially designated as a CVE (Common Vulnerability and Exposures) Numbering Authority (CNA). The company joins 151 organizations from 25 countries that participate in the CVE Program as CNAs. These organizations are authorized to assign CVE Identifiers (CVE IDs) to vulnerabilities within their own distinct scopes of work,…

  • Contact Form 7 Version 5.3.2 Patches Critical Vulnerability, Immediate  Update Recommended

    Contact Form 7 Version 5.3.2 Patches Critical Vulnerability, Immediate Update Recommended

    Contact Form 7 has patched a critical file upload vulnerability in version 5.3.2, released today by plugin author Takayuki Miyoshi. The plugin is installed on more than five million WordPress sites. “An unrestricted file upload vulnerability has been found in Contact Form 7 5.3.1 and older versions,” Miyoshi said. “Utilizing this vulnerability, a form submitter…

  • Easy WP SMTP 1.4.3 Patches Sensitive Data Disclosure Vulnerability

    Easy WP SMTP 1.4.3 Patches Sensitive Data Disclosure Vulnerability

    Easy WP SMTP has patched a vulnerability that allows attackers to capture the password reset link from the plugin’s debug log file and gain unauthorized access to the site. The plugin is used by more than 500,000 WordPress sites to configure and send all outgoing emails via a SMTP server so they are less likely…

  • WooCommerce Patches Vulnerability that Allowed Spam Bots to Create Accounts at Checkout

    WooCommerce Patches Vulnerability that Allowed Spam Bots to Create Accounts at Checkout

    WooCommerce 4.6.2 was released yesterday with a fix for a vulnerability that allowed account creation at checkout, even when the “Allow customers to create an account during checkout” setting is disabled. The WooCommerce team discovered it after several dozen users reported their sites were receiving spam orders, or “failed orders” where the payment details were fake.…

  • Loginizer Plugin Gets Forced Security Update for Vulnerabilities Affecting 1 Million Users

    Loginizer Plugin Gets Forced Security Update for Vulnerabilities Affecting 1 Million Users

    WordPress.org has pushed out a forced security update for the Loginizer plugin, which is active on more than 1 million websites. The plugin offers brute force protection in its free version, along with other security features like two-factor auth, reCAPTCHA, and PasswordLess login in its commercial upgrade. Last week security researcher Slavco Mihajloski discovered an…