Security News

WordPress 5.2 Brings New Security Features
2019-05-08 16:36

WordPress released version 5.2 of the popular content management system (CMS) this week, which includes new security and stability features.  Named “Jaco,” the update is already available in the...

WordPress updates are digitally signed at last!
2019-05-08 11:28

WordPress 5.2 is out and brings a number of functional improvements, but the great news for those who are worried about the security of their installation is the implementation of digital signing...

WP Live Chat WordPress Plugin Re-Patches File Upload Flaw
2019-05-06 21:42

After researchers were able to bypass a file upload validation flaw patch in WP Live Chat, a new patch has been issued.

Users Urged to Disable WordPress Plugin After Unpatched Flaw Disclosed
2019-04-26 19:44

Yet another WordPress plugin vulnerability has put thousands of websites at risk.

Critical Unpatched Flaw Disclosed in WordPress WooCommerce Extension
2019-04-26 11:33

If you own an eCommerce website built on WordPress and powered by WooCommerce plugin, then beware of a new, unpatched vulnerability that has been made public and could allow attackers to...

Hackers Actively Exploiting Widely-Used Social Share Plugin for WordPress
2019-04-23 19:18

Hackers have been found exploiting a pair of critical security vulnerabilities in one of the popular social media sharing plugins to take control over WordPress websites that are still running a...

Exploits for Social Warfare WordPress Plugin Reach Critical Mass
2019-04-23 17:30

More and more attacks taking advantage of a XSS and RCE bug in the popular plugin have cropped up in the wild.

WordPress Yellow Pencil Plugin Flaws Actively Exploited
2019-04-12 14:13

Yet another Wordpress plugin, Yellow Pencil Visual Theme Customizer, is being exploited in the wild after two software vulnerabilities were discovered.

WordPress Urges Users to Uninstall Yuzo Plugin After Flaw Exploited
2019-04-11 17:19

A vulnerability in the Yuzo Related Posts WordPress plugin, used by 60,000 websites, is being exploited in the wild.

WordPress iOS App Bug Leaked Secret Access Tokens to Third-Party Sites
2019-04-03 14:48

If you have a "private" blog with WordPress.com and are using its official iOS app to create or edit posts and pages, the secret authentication tokens for your admin account might have...