news

WP File Manager

WordPress plugin WP File Manager actively exploited

WordPress is a huge platform that powers a large number of websites. This service makes it easy for both programmers and non-programmers to develop different websites. With WordPress, there are different kinds of themes, plugins and more. However, since most of these things are created by third-party developers, there are chances that there will be …

WordPress plugin WP File Manager actively exploited Read More »

WordPress to add auto-update feature for themes and plugins

When it comes to WordPress, keeping your theme, plugins, and WordPress core is one of the most important tasks you have as a website owner. However, most website owners are often guilty of not applying updates and running with outdated versions of their themes and plugins.  Needless to say, this leaves your website vulnerable to …

WordPress to add auto-update feature for themes and plugins Read More »

Dozens of File Upload Vulnerabilities Found in Web Apps

Dozens of File Upload Vulnerabilities Found in Web Apps

When it comes to content management systems such as WordPress, hackers will often exploit file upload mechanisms to distribute malicious files which can be used to execute malicious code on a website, infect other websites, and allow hackers to gain full control over a server where your website is hosted.  In an effort to prevent …

Dozens of File Upload Vulnerabilities Found in Web Apps Read More »

CVE-2020-9334: Stored XSS vulnerability in Popular Gallery Plugin for WordPress

A high-severity Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2020-9334, exists in a popular WordPress plugin called Envira Photo Gallery, rendering over 100,000 websites vulnerable to phishing attacks, stealing administrator’s session tokens, etc. In this Blog-post, we will cover what caused the flaw, an example Proof-Of-Concept showing exploitation in a sandbox environment, and mitigation steps. What is the Envira …

CVE-2020-9334: Stored XSS vulnerability in Popular Gallery Plugin for WordPress Read More »

WordPress to Show Warnings on Servers Running Outdated PHP Versions

The WordPress open-source content management system, CMS, will indicate warning in its backend admin panel whenever the site is being run on an out-of-date PHP version. The plan in place is to make the warnings display for sites making use of a PHP version preceding the 5.6.x branch (<=5.6). There will be an inclusion of …

WordPress to Show Warnings on Servers Running Outdated PHP Versions Read More »