Tag: security

  • WPWeekly Episode 262 – Interview With Morten Rand-Hendriksen

    WPWeekly Episode 262 – Interview With Morten Rand-Hendriksen

    On this episode, Marcus Couch and I are joined by Morten Rand-Hendriksen to discuss his WordPress Telemetry proposal. We discuss the potential benefits of having an opt-in usage data collection system that could help core developers and others make informed decisions. Rand-Hendriksen also shares what he’s learned from teaching WordPress at Lynda.com, on how difficult…

  • WP Super Cache 1.4.9 Patches Multiple XSS Vulnerabilities

    WP Super Cache 1.4.9 Patches Multiple XSS Vulnerabilities

    WP Super Cache is a nearly 10-year-old plugin that is maintained by Donncha Ó Caoimh and is actively installed on more than a million sites. Releases have been far and few between, but Ó Caoimh has released WP Super Cache 1.4.9 that patches cross-site-scripting vulnerabilities on the settings page. “Those pages are only accessible by admin…

  • WPWeekly Episode 261 – WordPress for Schools With Cameron Barrett

    WPWeekly Episode 261 – WordPress for Schools With Cameron Barrett

    In this episode, Marcus Couch and I are joined by Cameron Barrett, founder of SchoolPresser, LLC. Barrett explains how he negotiated and helped migrate Newark New Jersey’s public school system from a proprietary CMS to WordPress. He shares the pitfalls he experienced and the amount of money the district is saving since making the switch.…

  • Aaron D. Campbell Replaces Nikolay Bachiyski as WordPress’ Security Czar

    Aaron D. Campbell Replaces Nikolay Bachiyski as WordPress’ Security Czar

    Aaron D. Campbell, WordPress Core Contributor at GoDaddy, is replacing Nikolay Bachiyski as WordPress’ Security Czar or WordPress Core Security Team Lead. The role was created in 2015 to provide more structure and focus around incident responses. “The responsibilities of the position include, organizing the security team and making sure all security concerns and reports…

  • WordPress 4.7.1 Fixes Eight Security Issues

    WordPress 4.7.1 Fixes Eight Security Issues

    WordPress 4.7.1 is available for download and fixes eight security issues that affect WordPress 4.7 and below. The PHPMailer library was updated to patch a remote code execution (RCE) vulnerability. WordFence reported the vulnerability last month as critical and that it affects WordPress core. However, in the announcement post for 4.7.1, Aaron Campbell, WordPress’ new…

  • BuddyPress 2.7.4 Patches Security Vulnerability That Could Allow Arbitrary File Deletion

    BuddyPress 2.7.4 Patches Security Vulnerability That Could Allow Arbitrary File Deletion

    The BuddyPress development team has released BuddyPress 2.7.4 to address a security vulnerability that affects all versions back to 2.0. According to John James Jacoby, lead developer of BuddyPress, “This version patches a vulnerability to the BuddyPress core attachments API that could allow arbitrary file deletion on certain installation configurations.” The vulnerability was responsibly disclosed by…

  • WPWeekly Episode 256 – Interview With Tony Perez, CEO and Co-Founder of Sucuri

    WPWeekly Episode 256 – Interview With Tony Perez, CEO and Co-Founder of Sucuri

    In this episode of WordPress Weekly, Marcus Couch and I are joined by Tony Perez, co-founder and CEO of Sucuri. It’s easy to tell from this episode that Perez is extremely passionate about web security. We discussed a wide range of topics related to security including, trends involving WordPress, the FUD factor, messaging surrounding HTTPS,…

  • WP eCommerce 3.11.4 Patches SQL Injection Vulnerability

    WP eCommerce 3.11.4 Patches SQL Injection Vulnerability

    Over the weekend, the WP eCommerce team released version 3.11.4 of its e-commerce plugin. The update patches an SQL injection vulnerability that was responsibly disclosed by Mika Epstein, a member of the WordPress.org plugin review team. According to Justin Sainton, lead developer of WP eCommerce, the team was notified of the vulnerability on November 11th and patched within…

  • High Risk XSS Vulnerability Discovered in W3 Total Cache Plugin

    High Risk XSS Vulnerability Discovered in W3 Total Cache Plugin

    WP Media is reporting a high risk XSS vulnerability in W3 Total Cache that the company learned about from El Rincón de Zerial’s security blog. The plugin is currently active on more than one million WordPress sites. This particular vulnerability is found within the plugin’s support form that is embedded in the admin, according to…

  • ManageWP Launches Automated Security Scanning

    ManageWP Launches Automated Security Scanning

    When ManageWP allowed users to perform security scans of websites through the Orion interface in December of 2015, a feature commonly requested by customers was the ability to automate the scans. Nine months after implementing security checks for customers, ManageWP has added automated security scans to its assortment of features. The automated security scans are a premium feature…

  • WordPress 4.6.1 Released, Patches Two Security Vulnerabilities

    WordPress 4.6.1 Released, Patches Two Security Vulnerabilities

    WordPress 4.6.1 is available and users are strongly encouraged to update immediately as it patches two security vulnerabilities. The first is a cross-site scripting vulnerability related to image filenames that was reported by Cengiz Han Sahin, a SumOfPwn researcher. The second is a path traversal vulnerability in the upgrade package uploader reported by Dominik Schilling,…

  • Jetpack 4.2 Released with Performance and Security Updates

    Jetpack 4.2 Released with Performance and Security Updates

    Jetpack 4.2 is a combination release with performance improvements and fixes for a couple of security vulnerabilities. These updates secure Contact Form submission exports from potential formula injections and fix a general XSS vulnerability in the misuse of the add_query_arg() function. The majority of enhancements in this release are centered on speeding up communication between…

  • TechCrunch Hacked by OurMine, Attackers Target Weak Passwords

    TechCrunch Hacked by OurMine, Attackers Target Weak Passwords

    TechCrunch is the latest victim in OurMine’s summer hacking rampage. The site, which is powered by WordPress and hosted via WordPress.com VIP, was hacked this morning and defaced with a message from the attackers who identify themselves as an “elite hacker group.” TechCrunch’s news ticker was updated to display: “Hello guys it’s OurMine Team, we…