Security News

Updated your WordPress plugins lately? Here are 320,000 auth-bypassing reasons why you should
2020-01-15 00:15

A pair of widely used WordPress plugins need to be patched on more than 320,000 websites to close down vulnerabilities that can be exploited to gain admin control of the web publishing software. The team at WebArx, a security firm specializing in WordPress and other CRM and publishing platforms, took credit for discovering and reporting the flaws in WP Time Capsule and InfiniteWP. Both plugins were patched earlier this month by the developer, and updates should be applied.

Critical Bug in WordPress Plugins Open Sites to Hacker Takeovers
2019-12-13 18:33

One flaw found in WordPress plugins Ultimate Addons for Beaver Builder and Ultimate Addons for Elementor is actively being exploited.

Flaw in Elementor and Beaver Addons Let Anyone Hack WordPress Sites
2019-12-13 02:25

Attention WordPress users! Your website could easily get hacked if you are using "Ultimate Addons for Beaver Builder," or "Ultimate Addons for Elementor" and haven't recently updated them to the...

Critical Bug Patched in Popular Jetpack WordPress Plugin
2019-11-21 19:03

An update for the popular WordPress plugin Jetpack addresses a critical security flaw that has existed for more than two years.  With over 5 million installations to date, Jetpack provides...

WordPress sites hit by malvertising
2019-11-07 14:01

An old piece of malware is storming the WordPress community, enabling its perpetrators to take control of sites and inject code of their choosing.

WordPress 5.2.4 Patches Six Vulnerabilities
2019-10-16 14:06

WordPress 5.2.4, which WordPress developers released this week, patches six vulnerabilities, including cross-site scripting (XSS), unauthorized access, server-side request forgery (SSRF), and...

Hackers are infecting WordPress sites via a defunct plug-in
2019-09-26 10:37

If you're a Wordpress admin using a plug-in called Rich Reviews, you'll want to uninstall it. Now.

Unpatched Bug Under Active Attack Threatens WordPress Sites with XSS
2019-09-25 16:28

The issue in the Rich Reviews plugin is being actively exploited.

WordPress XSS Bug Allows Drive-By Code Execution
2019-09-13 20:52

Sites that use the Gutenberg (found in WordPress 5.0 to 5.2.2) are open to complete takeover.

WordPress 5.2.3 fixes new clutch of security vulnerabilities
2019-09-09 10:31

WordPress version 5.2.3 has just appeared on the download pipe featuring half a dozen security fixes and software enhancements.