Security News

WordPress Sites Exposed to Attacks by 'Formidable Forms' Flaws
2017-11-15 19:06

Vulnerabilities found by a researcher in a popular WordPress plugin can be exploited by malicious actors to gain access to sensitive data and take control of affected websites. read more

WordPress site admins: Update immediately!
2017-11-02 15:31

If you’re running your website on WordPress and you haven’t yet upgraded to version 4.8.3, you should do so without delay. The advice comes from the WordPress Foundation and Anthony Ferrara, VP of...

WordPress Delivers Second Patch For SQL Injection Bug
2017-11-01 18:35

A bug exploitable in WordPress 4.8.2 and earlier creates unexpected and unsafe conditions ripe for a SQL-injection attack.

Serious SQL Injection Flaw Patched in WordPress
2017-11-01 09:00

A serious SQL injection vulnerability was patched on Tuesday by WordPress developers with the release of version 4.8.3. read more

Websites Hacked via Zero-Day Flaws in WordPress Plugins
2017-10-03 07:50

Zero-day flaws affecting several WordPress plugins have been exploited by malicious actors to plant backdoors and take control of vulnerable websites. The attacks have been spotted by Wordfence, a...

Backdoor Masquerades as Popular WordPress Plugin
2017-09-29 14:10

A fake WordPress plugin containing a backdoor attempts to trick users into believing it is a version of a popular plugin that has over 100,000 installs. read more

Nine Vulnerabilities Patched in WordPress
2017-09-21 13:18

WordPress 4.8.2 patches nine vulnerabilities affecting version 4.8.1 and earlier, including cross-site scripting (XSS), SQL injection, path traversal and open redirect flaws. read more

200K WordPress Sites Exposed to Rogue Version of ‘Display Widgets’
2017-09-15 19:54

A rogue version of the WordPress plugin called “Display Widget” allowed third-parties to injecting spam advertising content into victims’ sites.

Backdoored Plugin Impacts 200,000 WordPress Sites
2017-09-14 12:22

Around 200,000 WordPress websites were impacted after a plugin they were using was updated to include malicious code, Wordfence reports. read more

Reflected XSS Bug Patched in Popular WooCommerce WordPress Plugin (Threatpost)
2017-08-31 13:30

Automattic has patched a reflected cross-site scripting vulnerability in the WooCommerce WordPress plugin.