Security News

Hidden Backdoor Found In WordPress Captcha Plugin Affects Over 300,000 Sites
2017-12-20 10:03

Buying popular plugins with a large user-base and using it for effortless malicious campaigns have become a new trend for bad actors. One such incident happened recently when the renowned...

Keylogger Found on 5,500 WordPress Sites
2017-12-07 19:02

Thousands of WordPress sites have been infected with a piece of malware that can log user input, Sucuri warns. read more

WordPress Sites Exposed to Attacks by 'Formidable Forms' Flaws
2017-11-15 19:06

Vulnerabilities found by a researcher in a popular WordPress plugin can be exploited by malicious actors to gain access to sensitive data and take control of affected websites. read more

WordPress site admins: Update immediately!
2017-11-02 15:31

If you’re running your website on WordPress and you haven’t yet upgraded to version 4.8.3, you should do so without delay. The advice comes from the WordPress Foundation and Anthony Ferrara, VP of...

WordPress Delivers Second Patch For SQL Injection Bug
2017-11-01 18:35

A bug exploitable in WordPress 4.8.2 and earlier creates unexpected and unsafe conditions ripe for a SQL-injection attack.

Serious SQL Injection Flaw Patched in WordPress
2017-11-01 09:00

A serious SQL injection vulnerability was patched on Tuesday by WordPress developers with the release of version 4.8.3. read more

Websites Hacked via Zero-Day Flaws in WordPress Plugins
2017-10-03 07:50

Zero-day flaws affecting several WordPress plugins have been exploited by malicious actors to plant backdoors and take control of vulnerable websites. The attacks have been spotted by Wordfence, a...

Backdoor Masquerades as Popular WordPress Plugin
2017-09-29 14:10

A fake WordPress plugin containing a backdoor attempts to trick users into believing it is a version of a popular plugin that has over 100,000 installs. read more

Nine Vulnerabilities Patched in WordPress
2017-09-21 13:18

WordPress 4.8.2 patches nine vulnerabilities affecting version 4.8.1 and earlier, including cross-site scripting (XSS), SQL injection, path traversal and open redirect flaws. read more

200K WordPress Sites Exposed to Rogue Version of ‘Display Widgets’
2017-09-15 19:54

A rogue version of the WordPress plugin called “Display Widget” allowed third-parties to injecting spam advertising content into victims’ sites.