Uncategorized

New to Monitoring Your Site for Bad Behavior and are Startled by the Numbers? Don’t Panic!

I have many years of working with clients and one of the most common concerns that comes up after putting security in place is regarding the startling number of how many baddies are constantly attacking their site, especially on WordPress. Over the years, I’ve been asked dozens of times questions like: “I see hundreds of

New to Monitoring Your Site for Bad Behavior and are Startled by the Numbers? Don’t Panic! Read More »

UpdraftPlus WordPress plugin vulnerability

A new vulnerability has been discovered in the popular plugin UpdraftPlus. The plugin has more than 3 millon active installations currently and the vulnerability has a CVE identifier reserved as CVE-2022-23303. The developers behind updraftplus has made an announcement: “an update was pushed to Premium users within the hour”. Marc-Alexandre Montpas the cyber security researcher

UpdraftPlus WordPress plugin vulnerability Read More »

Security flaw in WP Statistics Plugin

Cyber Security Researcher Cyku Hong from the Taiwan-based company DEVCORE has found a serious security vulnerability in the WordPress plugin WP Statistics. This plugin is installed on over 600,000 websites and the flaw makes it possible for an attacker to conduct an SQL-injection attack. The SQL-injection attack can be used to read sensitive information such as

Security flaw in WP Statistics Plugin Read More »

Essential Addons for Elementor has a critical security hole

A critical security vulnerability was recently discovered in the Essential Addons for Elementor, a plugin that has over a million active installations on the WordPress plugin repository.  The plugin is used to “enhance your Elementor page building experience with 80+ creative elements and extensions“. One of those “creative elements” is the dynamic and product gallery

Essential Addons for Elementor has a critical security hole Read More »

AccessPress hack underlines the importance of core file monitoring

AccessPress hack underlines the importance of core file monitoring Core file integrity monitoring is when a tool is in place that ensures WordPress application files are changed only during an actual WordPress upgrade. Plugins, themes or other 3rd party code should never alter core files. The Jetpack security team discovered that 93 AccessPress WordPress add-ons

AccessPress hack underlines the importance of core file monitoring Read More »

Protecting WordPress with Open Source Web Application Firewall ModSecurity

Update: A new CRS 4 has been released. These instructions are for CRS 3 and no longer work. In CRS 4, exclusion lists have been replaced with plugins. In this guide, you will learn how to install and protect WordPress using the Open Source Web Application Firewall (WAF) ModSecurity. We will also install the latest

Protecting WordPress with Open Source Web Application Firewall ModSecurity Read More »

WooCommerce Unauthenticated SQL Injection Vulnerability

WooCommerce Unauthenticated SQL Injection Vulnerability

On 15th July 2021, news was going around regarding an unauthenticated SQL Injection in WooCommerce. WooCommerce released a blog post about the vulnerabilities here: https://woocommerce.com/posts/critical-vulnerability-detected-july-2021/#. The vulnerabilities were detected on the 13th of July and fixed in WooCommerce versions 3.3.6 to 5.5.1 and WooCommerce Blocks versions 2.5.16 to 5.5.1. This blog post is a short

WooCommerce Unauthenticated SQL Injection Vulnerability Read More »