Security News

WP Engine launches Global Edge Security for WordPress with Cloudflare
2018-09-05 15:00

WP Engine announced the launch of Global Edge Security, an enterprise-class security solution built from Cloudflare’s Internet performance and security solutions. Global Edge Security integrates...

So phar, so FUD: PHP flaw puts WordPress sites at risk of hacks
2018-08-20 12:40

But claims of 'complete system compromise' are a little extreme Bsides Manchester A newly discovered WordPress flaw has left installs of the ubiquitous content management system potentially...

Severe PHP Exploit Threatens WordPress Sites with Remote Code Execution
2018-08-17 18:03

The issue impacts several content management systems, including Typo3 and WordPress, as well as widely-used PDF generation library TCPDF.

Busting the security myth: Should I use WordPress for my website?
2018-08-17 11:45

WordPress has been around for 15 years. Today it powers around 30% of the top 10 million websites on the internet. Being such a popular platform, WordPress has been in the limelight quite a few...

New PHP Code Execution Attack Puts WordPress Sites at Risk
2018-08-17 09:33

Sam Thomas, a security researcher from Secarma, has discovered a new exploitation technique that could make it easier for hackers to trigger critical deserialization vulnerabilities in PHP...

How hack on 10,000 WordPress sites was used to launch an epic malvertising campaign
2018-07-30 15:03

Crooks exploited legit web ad ecosystem – researchers Security researchers at Check Point have lifted the lid on the infrastructure and methods of an enormous "malvertising" and banking trojan campaign.…

WP Security Audit Log: Keeping a watchful eye on your WordPress sites
2018-07-09 12:15

WordPress is, without a doubt, the most popular website management system in use. The latest statistics put the number of websites running on WordPress over 60 million, and those include many...

Unpatched WordPress Flaw Leads to Site Takeover, Code Execution
2018-06-27 11:25

A file deletion vulnerability that remains unpatched 7 months after being reported allows for the complete takeover of WordPress sites and for arbitrary code execution. read more

Unpatched WordPress Flaw Gives Attackers Full Control Over Your Site
2018-06-27 09:33

Last week we received a tip about an unpatched vulnerability in the WordPress core, which could allow a low-privileged user to hijack the whole site and execute arbitrary code on the server....

Two Bugs in WordPress Tooltipy Plugin Patched
2018-06-13 20:55

The bugs include a reflected cross-site scripting glitch and a cross-site request forgery vulnerability.