Security News

WordPress Plugin WP Statistics Patches XSS Flaw
2019-07-05 19:27

A cross-site scripting vulnerability in WordPress plugin WP Statistics could have enabled full website takeover.

How to solve the dreaded Wordpress site maintenance error
2019-06-19 15:41

If your Wordpress site is stuck in maintenance mode, there's a simple fix.

Irked Researcher Discloses Facebook WordPress Plugin Flaws
2019-06-17 22:07

Researchers at Plugin Vulnerabilities cite grudge and irresponsibly disclose bugs in two WordPress plugins from Facebook.

New Flaw in WordPress Live Chat Plugin Lets Hackers Steal and Hijack Sessions
2019-06-11 10:33

Security researchers have been warning about a critical vulnerability they discovered in one of a popular WordPress Live Chat plugin, which, if exploited, could allow unauthorized remote attackers...

WordPress Sites Worldwide Hit with ‘Call-Girl’ Search-Engine Pollution
2019-06-10 21:14

A web spam campaign targeting Koreans is affecting non-hacked websites worldwide.

Attackers are exploiting WordPress plugin flaw to inject malicious scripts
2019-05-30 11:28

Attackers are leveraging an easily exploitable bug in the popular WP Live Chat Support plugin to inject a malicious JavaScript in vulnerable sites, Zscaler warns. The company has discovered 47...

WordPress Plugin Has Unpatched Privilege Escalation Flaw, Warn Researchers
2019-05-29 16:01

Researchers are warning of flaws in two WordPress plugins - Slick Popup and WP Database Backup - including one that remains unpatched.

Joomla and WordPress Found Harboring Malicious Redirect Code
2019-05-24 17:48

New .htaccess injector threat on Joomla and WordPress websites redirects to malicious websites.

WordPress plugin sees second serious security bug in six weeks
2019-05-21 09:58

Researchers have uncovered another serious bug in WP Live Chat that could lead to the mass compromise of websites.

WordPress WP Live Chat Support Plugin Fixes XSS Flaw
2019-05-17 19:28

A cross-site scripting flaw in a popular WordPress plugin enables an unauthenticated attacker to insert JavaScript payloads into impacted websites.