WordPress 4.7 was released 6 days ago, on December 6th. It includes a REST API that will be used by many WordPress plugins, mobile apps, desktop applications, cloud services and even WordPress core in future. Every site that upgrades to WordPress 4.7 has this API enabled by default.
Showing posts with label Wordpress. Show all posts
Showing posts with label Wordpress. Show all posts
Monday, 12 December 2016
Wednesday, 30 November 2016
Emergency Bulletin: Firefox 0 day in the wild. What to do.
We’re publishing this as an emergency bulletin for our customers and the larger web community. A few hours ago a zero day vulnerability emerged in the Tor browser bundle and the Firefox web browser. Currently it exploits Windows systems with a high success rate and affects Firefox versions 41 to 50 and the current version of the Tor Browser Bundle which contains Firefox 45 ESR.
If you use Firefox, we recommend
Wednesday, 17 August 2016
WP Plugin 404 to 301 - Considered Harmful
Yesterday we received a site cleaning request where one of our customers was seeing spammy links, Payday Loans in this case, injected into their WordPress website page content. The links were only appearing when the site was visited by a search engine crawler. This is common when a site has been hacked.
It turns out that this is not a hacked site. It is content that is injected by a plugin called 404 to 301 plugin which has 70,000 active installs and has a 4.5 star review from 56 reviewers. When you install the plugin it asks you to agree to a long agreement which includes parts of the GNU general public license. But at the end it also includes the following text:
Wednesday, 13 July 2016
New Vulnerability in All in One SEO Pack Plugin 2.3.7 and earlier
Yesterday morning Panagiotis Vagenas, a Wordfence Security Researcher, discovered a new vulnerability in the All in One SEO Pack WordPress plugin. This is in addition to another serious vulnerability we wrote about yesterday morning in the same plugin.
As detailed yesterday, All in One SEO Pack is an extremely popular plugin with over 1,000,000 active installs. Both free and Premium Wordfence users with the firewall enabled had partial protection at the time we discovered this new vulnerability.
Friday, 6 May 2016
Vulnerability in Yoast SEO 3.2.4 for WordPress
Saturday, 9 April 2016
Panama Papers: How they hacked!
Email Hackable via WordPress, Docs Hackable via Drupal
The Mossack Fonseca (MF) data breach, aka Panama Papers, is the largest data breach to journalists in history and includes over 4.8 million emails.
Yesterday we broke the story that MF was running WordPress with a vulnerable version of Revolution Slider and the WordPress server was on the same network as their email servers when the breach occurred.
Wednesday, 24 February 2016
WordPress delivered Ransomware and Hacked Linux Distributions
In a rather unfortunate turn of events earlier this month, the Hollywood Presbyterian Medical Center was infected with ransomware. Ransomware, if you’re unfamiliar with it, encrypts everything on your workstation and then tells you to pay an attacker to decrypt your system and regain access to your information.
In the case of Presbyterian, they had to pay 40 bitcoins or the equivalent of $17,000 to regain access to their systems. The ransomware attack affected CT scans, documentation, lab work, pharmacy functions and their email went down. Last week they paid the attacker the $17,000 and their systems were decrypted and they’re back online.
Tuesday, 26 January 2016
WordPress Security: Core XSS and 4 Plugin vulnerabilities
This has certainly been an eventful month in WordPress security. January 6th saw a WordPress core security update. Upgrade immediately to version 4.4.1 of WordPress core if you haven’t already.
The vulnerability that WordPress 4.4.1 fixes is a cross site scripting or XSS vulnerability.
Saturday, 18 July 2015
Theme Translations and Language Packs are Coming to WordPress.org
WordPress.org will soon support translations and language packs for themes hosted in the official directory. In Matt Mullenweg’s Q&A at WordCamp Europe 2015, he emphasized the importance of having better language support for themes and plugins and identified this as a high priority for continued improvements to WordPress.org.
Today the WordPress meta team announced that theme translations will soon be available on WordPress.org at translate.wordpress.org. Within the next few days or weeks, all active themes (those updated within the last two years) will have their strings imported.
“This will involve importing ~1500 themes, which, combined, have about 315,000 total strings,” Sam Sidler said in the announcement. “After duplicates, the number drops to only 80,000 unique strings.”
The most exciting change is that themes hosted on WordPress.org will soon be able to take advantage of language packs. Theme authors will have the option to remove translations from their zip file in favor of allowing WordPress.org to deliver the language packs, resulting in smaller download sizes.
“Eventually, we also plan to give priority to localized themes in localized directories; e.g., someone searching the Romanian theme directory will see Romanian themes prioritized over English-only themes,” Sidler said.
Today the WordPress meta team announced that theme translations will soon be available on WordPress.org at translate.wordpress.org. Within the next few days or weeks, all active themes (those updated within the last two years) will have their strings imported.
“This will involve importing ~1500 themes, which, combined, have about 315,000 total strings,” Sam Sidler said in the announcement. “After duplicates, the number drops to only 80,000 unique strings.”
The most exciting change is that themes hosted on WordPress.org will soon be able to take advantage of language packs. Theme authors will have the option to remove translations from their zip file in favor of allowing WordPress.org to deliver the language packs, resulting in smaller download sizes.
“Eventually, we also plan to give priority to localized themes in localized directories; e.g., someone searching the Romanian theme directory will see Romanian themes prioritized over English-only themes,” Sidler said.
Saturday, 23 May 2015
Manage Multiple WordPress Sites Using InfiniteWP
Today we want to introduce you to an really awesome tool we are using to maintain our WordPress Websites as well as the WordPress sites of our Clients.
Is it really that important to keep your WordPress website up to date? The answer to that questions isn’t always “yes”, but in almost all cases, it is important to keep it as up to date as possible. WordPress is an outstanding system for creating a website or blog. And every site needs regular maintenance. The key to maintaining a WordPress website or blog is have a system to make it easy.
Monday, 11 May 2015
How much do I have to pay for my website?
How much do I have to pay for my website?
If you’re thinking about starting a Landing Page, a Blog, a Support Site, a eCommerce site or a Media/Content site based on static HTML or on a CMS like WordPress, one of the first questions you’ll probably ask yourself is “how much does this website cost?”. It’s an important question! Figuring out the best way to start a website early on can save you a ton of money in the long run.
One of the biggest issues with figuring out the price is that web design is a service, but most clients see a website as a ‘product’. Many of them believe that they can walk into a ‘virtual store’ and order a 5 page website for fixed fee. However a website is something that should be created according to your needs!
So, the first question I want to ask you is:
Thursday, 7 May 2015
WordPress 4.2.2 Security Release and Genericons vulnerability
WordPress 4.2.2 has just been released which contains several important security fixes. We recommend you update immediately if you haven't already been automatically upgraded.
The release also fixes 13 other bugs which you can learn more about on the release notes page for 4.2.2.
- The Genericons icon font package, which is used in a number of popular themes and plugins, contained an HTML file vulnerable to a cross-site scripting attack. All affected themes and plugins hosted on WordPress.org (including the Twenty Fifteen default theme) have been updated today by the WordPress security team to address this issue by removing this non-essential file. To help protect other Genericons usage, WordPress 4.2.2 pro-actively scans the wp-content directory for this HTML file and removes it. This was reported by Robert Abela of Netsparker.
- WordPress versions 4.2 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site. WordPress 4.2.2 includes a comprehensive fix for this issue. Reported separately by Rice Adu and Tong Shi.
- The release also includes hardening for a potential cross-site scripting vulnerability when using the visual editor. This issue was reported by Mahadev Subedi.
The release also fixes 13 other bugs which you can learn more about on the release notes page for 4.2.2.
Subscribe to:
Posts (Atom)











