Security News

Critical WordPress Plugin Flaw Allows Complete Website Takeover
2019-02-12 20:29

Users of the popular plugin, Simple Social Buttons, are encouraged to update to version 2.0.22.

Stealthy Malware Disguises Itself as a WordPress License Key
2019-01-30 16:59

A spam injector hides in plain site within WordPress theme files.

Zero-Days in WordPress Plugin Actively Exploited
2019-01-28 18:33

The commercial Total Donations plugin for WordPress is impacted by multiple zero-day vulnerabilities that are being actively exploited in attacks, Wordfence security researchers report.  read more

WordPress Users Urged to Delete Zero-Day-Ridden Plugin
2019-01-28 14:39

The development team of the vulnerable Total Donations plugin appears to have abandoned it, and did not respond to inquiries from researchers.

Former Employee Hacks Popular WordPress Plugin’s Website
2019-01-21 15:55

The website for a popular WordPress plugin was hacked over the weekend, when a former employee abused a previously implemented backdoor to take over the domain. read more

WordPress to Warn on Outdated PHP Versions
2019-01-16 15:41

In an effort to improve the security of websites, WordPress will display a warning starting in April 2019 when encountering outdated PHP versions. In December last year, the free and open-source...

ThreatList: WordPress Vulnerabilities Tripled in 2018
2019-01-09 18:27

Despite fewer plugins being added to Wordpress last year, the CMS saw an astounding tripling of vulnerabilities in its platform in 2018.

WordPress users beware: These 10 plugins are most vulnerable to attacks
2019-01-09 16:31

WordPress vulnerabilities tripled over the past year, more than any other CMS, according to an Imperva report.

WordPress Targeted with Clever SEO Injection Malware
2018-12-18 17:09

The malware does its best to obfuscate SEO injection in WordPress and evade notice from web admins.

WordPress Patches Privilege Escalation Vulnerabilities
2018-12-18 14:51

Privilege escalation vulnerabilities in WordPress allow attackers to access features that were intended for administrators only, RIPS Tech security researchers say.  read more