Security News

Unpatched WordPress Flaw Gives Attackers Full Control Over Your Site
2018-06-27 09:33

Last week we received a tip about an unpatched vulnerability in the WordPress core, which could allow a low-privileged user to hijack the whole site and execute arbitrary code on the server....

Two Bugs in WordPress Tooltipy Plugin Patched
2018-06-13 20:55

The bugs include a reflected cross-site scripting glitch and a cross-site request forgery vulnerability.

WordPress Disables Plugins That Expose e-Commerce Sites to Attacks
2018-06-01 12:55

Researchers discovered vulnerabilities in ten WordPress plugins made by a company for e-commerce websites powered by the WooCommerce platform. WordPress disabled many of them after the developer...

WordPress Users Warned of Malware Masquerading as ionCube Files
2018-02-27 19:52

Researchers have found sneaky encoded malware targeting WordPress and Joomla sites that pretends to be ionCube files.

WordPress Update Breaks Automatic Update Feature—Apply Manual Update
2018-02-09 12:18

WordPress administrators are once again in trouble. WordPress version 4.9.3 was released earlier this week with patches for a total 34 vulnerabilities, but unfortunately, the new version broke the...

One Computer Can Knock Almost Any WordPress Site Offline
2018-02-06 16:07

As if there aren't enough ways to attack a WordPress site, an Israeli researcher has published details of how almost anyone can launch a denial of service (DoS) attack against almost any WordPress...

Unpatched DoS Flaw Could Help Anyone Take Down WordPress Websites
2018-02-05 11:48

A simple yet serious application-level denial of service (DoS) vulnerability has been discovered in WordPress CMS platform that could allow anyone to take down most WordPress websites even with a...

Nearly 2000 WordPress Websites Infected with a Keylogger
2018-01-29 12:48

More than 2,000 WordPress websites have once again been found infected with a piece of crypto-mining malware that not only steals the resources of visitors' computers to mine digital currencies...

Keylogger Campaign Returns, Infecting 2,000 WordPress Sites
2018-01-26 19:32

Over 2,000 WordPress sites are infected as part of a keylogger campaign that leverages an old malicious script.

Backdoored Captcha Plugin Hits 300,000 WordPress Sites
2017-12-20 18:55

Yet another plugin was removed from the WordPress repository afte read more