Security News

WordPress forces user conf organizers to share social media credentials, arousing suspicions
2024-10-28 06:27

One told to take down posts that said nice things about WP Engine Organisers of WordCamps, community-organized events for WordPress users, have been ordered to take down some social media posts...

Over 6,000 WordPress hacked to install plugins pushing infostealers
2024-10-21 17:53

WordPress sites are being hacked to install malicious plugins that display fake software updates and errors to push information-stealing malware. [...]

Jetpack fixes 8-year-old flaw affecting millions of WordPress sites
2024-10-18 22:30

Also, new EU cyber reporting rules are live, exploiters hit the gas pedal, free PDNS for UK schools, and more in brief A critical security update for the near-ubiquitous WordPress plugin Jetpack...

WordPress Plugin Jetpack Patches Major Vulnerability Affecting 27 Million Sites
2024-10-15 04:56

The maintainers of the Jetpack WordPress plugin have released a security update to remediate a critical vulnerability that could allow logged-in users to access forms submitted by others on a...

WordPress Security Checklist
2024-10-06 16:00

Stories of virus and malware infections, data loss, system compromises, and unauthorized access dominate headlines, and your WordPress website may be contributing to the problem. Therefore, it is...

WordPress LiteSpeed Cache Plugin Security Flaw Exposes Sites to XSS Attacks
2024-10-04 09:11

A new high-severity security flaw has been disclosed in the LiteSpeed Cache plugin for WordPress that could enable malicious actors to execute arbitrary JavaScript code under certain conditions....

Automattic blocks WP Engine’s access to WordPress resources
2024-09-26 13:51

WordPress.org has banned WP Engine from accessing its resources and stopped delivering plugin updates to websites hosted on the platform, urging impacted users to choose other hosting providers. [...]

WordPress.org denies service to WP Engine, potentially putting sites at risk
2024-09-26 01:45

That escalated quickly WordPress on Wednesday escalated its conflict with WP Engine, a hosting provider, by blocking the latter's servers from accessing WordPress.org resources – and therefore...

WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers
2024-09-12 04:57

WordPress.org has announced a new account security measure that will require accounts with capabilities to update plugins and themes to activate two-factor authentication (2FA) mandatorily. The...

WordPress.org to require 2FA for plugin developers by October
2024-09-11 17:33

Starting October 1st, WordPress.org accounts that can push updates and changes to plugins and themes will be required to activate two-factor authentication (2FA) on their accounts. [...]