Uncategorized

Discovering Vulnerabilities in WordPress Plugins at Scale

Author: Luke (@hakluke) Stephens It always blows me away to think that WordPress runs 43% of all websites, including those without a content management system (CMS) 🤯. A single open source project is responsible for such a huge part of the internet! It’s interesting to think about what might happen if a severe vulnerability was …

Discovering Vulnerabilities in WordPress Plugins at Scale Read More »

New to Monitoring Your Site for Bad Behavior and are Startled by the Numbers? Don’t Panic!

I have many years of working with clients and one of the most common concerns that comes up after putting security in place is regarding the startling number of how many baddies are constantly attacking their site, especially on WordPress. Over the years, I’ve been asked dozens of times questions like: “I see hundreds of …

New to Monitoring Your Site for Bad Behavior and are Startled by the Numbers? Don’t Panic! Read More »

UpdraftPlus WordPress plugin vulnerability

A new vulnerability has been discovered in the popular plugin UpdraftPlus. The plugin has more than 3 millon active installations currently and the vulnerability has a CVE identifier reserved as CVE-2022-23303. The developers behind updraftplus has made an announcement: “an update was pushed to Premium users within the hour”. Marc-Alexandre Montpas the cyber security researcher …

UpdraftPlus WordPress plugin vulnerability Read More »

Security flaw in WP Statistics Plugin

Cyber Security Researcher Cyku Hong from the Taiwan-based company DEVCORE has found a serious security vulnerability in the WordPress plugin WP Statistics. This plugin is installed on over 600,000 websites and the flaw makes it possible for an attacker to conduct an SQL-injection attack. The SQL-injection attack can be used to read sensitive information such as …

Security flaw in WP Statistics Plugin Read More »

Essential Addons for Elementor has a critical security hole

A critical security vulnerability was recently discovered in the Essential Addons for Elementor, a plugin that has over a million active installations on the WordPress plugin repository.  The plugin is used to “enhance your Elementor page building experience with 80+ creative elements and extensions“. One of those “creative elements” is the dynamic and product gallery …

Essential Addons for Elementor has a critical security hole Read More »