Your WordPress News Dashboard

Page 13 of 15

Episode 89: Shopify Rogue Employees, Medium and Twitter Vulnerabilities, and Hackers Hiding Out in Corporate Networks - Wordfence Blog

Shopify reports that two rogue employees stole data from 200 merchants on their platform. A security researcher found a vulnerability in the Medium Partner Program could have allowed an attacker to steal writers’ earnings. Symantec reports that a state-sponsored hacking… Continue Reading →

Episode 88: XCloner Vulnerabilities, LokiBot Malware, & a 14 Year Old Nets a $25K Bug Bounty - Wordfence Blog

Our Threat Intelligence team discovered several vulnerabilities present in XCloner Backup and Restore, a WordPress plugin installed on over 30,000 sites. These vulnerabilities could have allowed an attacker to modify arbitrary files, including PHP files. The US government Cybersecurity and… Continue Reading →

Episode 87: Vulnerabilities Affect Discount Rules for WooCommerce Plugin, ModSecurity & Windows - Wordfence Blog

Vulnerabilities were recently patched in the Discount Rules for WooCommerce plugin installed on over 40,000 WordPress sites. Developers from OWASP Core Rule Set said ModSecurity v3 is exposed to denial of service exploits, though the maintainers of ModSecurity reject that… Continue Reading →

Episode 86: War of the Hackers - Wordfence Blog

Millions of attacks have been targeting the recent File Manager plugin zero-day vulnerability discovered last week. Two attackers are vying for control over sites compromised through the vulnerability. A security researcher has revealed that specially crafted Windows 10 themes can… Continue Reading →

Episode 85: 0Day in File Manager Plugin and WordPress 5.5.1 Fixes Broken Sites - Wordfence Blog

Over 700,000 WordPress users were affected by a zero-day vulnerability in the File Manager plugin, and the WordPress 5.5.1 release fixed millions of sites affected by deprecation of jQuery Migrate. SendGrid is under siege from spammers using hacked accounts, and… Continue Reading →

Episode 84: Google Chrome Plans to Implement Insecure Form Warnings - Wordfence Blog

The Google Chrome web browser has a high-severity vulnerability that could be used to execute arbitrary code, which has been fixed in Chrome version 85. Google also announced that Chrome 86 will alert users if a form submission is using… Continue Reading →

Episode 83: 100,000 Sites Impacted by Vulnerabilities in Advanced Access Manager - Wordfence Blog

The Wordfence Threat Intelligence team discovered vulnerabilities in the Advanced Access Manager plugin installed on over 100,000 WordPress sites. A high severity authorization bypass could lead to privilege escalation and site takeover. Critical vulnerabilities found in the Quiz and Survey… Continue Reading →

Episode 82: Important Changes in the WordPress 5.5 Update - Wordfence Blog

WordPress 5.5 was released on August 11 with a number of important updates, including a new feature allowing auto-updates of themes and plugins as well as changes to the block editor. The popular Astra theme was suspended from the repository… Continue Reading →

Episode 81: Critical Vulnerability Exposes over 700,000 Sites Using Divi, Extra, and Divi Builder - Wordfence Blog

Our Threat Intelligence team disclosed numerous vulnerabilities this week, including a critical vulnerability in the Divi and Extra themes as well as the Divi Builder plugin. In total, this vulnerability affected over 700,000 sites. A vulnerability found in The Official… Continue Reading →

Episode 80: Critical File Upload Vulnerability in wpDiscuz Plugin - Wordfence Blog

In this week’s news, our Threat Intelligence team discovered a vulnerability in the wpDiscuz plugin, affecting over 80,000 WordPress sites. A blind SQL injection attack affected analytics service Waydev, exposing OAuth tokens for GitHub repositories for software companies, leading to… Continue Reading →

Episode 79: High Profile Twitter Accounts Compromised in Coordinated Attack - Wordfence Blog

A number of high profile Twitter accounts including those of Elon Musk, Apple, Uber, Bill Gates, Joe Biden and others were compromised as a part of a coordinated bitcoin scam attack. The attack lasted a few hours and netted the… Continue Reading →

Episode 78: Targeted Phishing Bypassing Security Checks and a new DDoS Record - Wordfence Blog

This week, we look at some targeted phishing attacks that are bypassing Microsoft Outlook’s protective filters, and phishing campaigns using calendar invitations to target unsuspecting recipients. We also look at some successful bitcoin scams and a new record for a… Continue Reading →

Episode 77: WordPress 5.4.2 Released, Fake Ransomware Bitcoin Scams - Wordfence Blog

This week, we look at the WP 5.4.2 release and a ransomware bitcoin scam targeting site owners with a “You’ve Been Hacked” email. We also look at an FBI warning about online banking app malware, the Verizon data breach report… Continue Reading →

Episode 76: Ongoing Attacks on WP Growing in Volume Plus Numerous Plugin Vulnerabilities - Wordfence Blog

On this week’s Think Like a Hacker podcast, we cover an active attack campaign targeting WordPress sites and numerous plugin vulnerabilities. This active attack campaign has been ongoing and has outpaced all other attacks on WordPress vulnerabilities. Our threat intelligence… Continue Reading →

Episode 75: The WordPress 5.4.1 Security Release & More Plugin Vulnerabilities - Wordfence Blog

The Wordfence Threat Intelligence team unpacked the security updates in WordPress 5.4.1, and they published quite a few blog posts about vulnerabilities in popular plugins like Ninja Forms, LearnPress, and the Real-Time Find and Replace plugin. These plugin vulnerabilities affected… Continue Reading →

Episode 74: Staying Safe When Hackers Use Sophisticated Attacks - Wordfence Blog

Stories this week about targeted attacks using 0days in iPhone and iPad devices and a sophisticated phone scam targeting a security professional that ended with a $9,800 wire transfer underscore what we all know: malicious attacks are becoming increasingly sophisticated…. Continue Reading →

Episode 73: Security News and Success through Processes with Adam Silver - Wordfence Blog

The FTC is reporting numerous scams targeting fears and uncertainty, with over $12 million lost to Coronavirus-related scams. We also cover BBB warnings against oversharing on social media, over 500,000 Zoom credentials found on the dark web, Google’s removal of… Continue Reading →

Episode 72: WordPress 5.4 Released, Zoom Conferencing Safety & Security - Wordfence Blog

This week, we look at the WordPress 5.4 release which includes turning distraction free editing on by default. We also look at new plugin vulnerabilities discovered by the Wordfence Threat Intelligence team, including those found in Rank Math and a… Continue Reading →

Episode 71: Hackers Targeting COVID-19 Fears - Wordfence Blog

With many of us under either lockdown or shelter-in-place orders due to the COVID-19/Corona virus, fear and stress are rampant. This additional stress lowers our critical thinking capabilities and increases our vulnerability. Hackers targeting these human vulnerabilities are using the… Continue Reading →

Episode 70: Customer Education and Agency Resiliency with Jon Bius - Wordfence Blog

We chat with Jon Bius, a web developer at Biz Tools One, an agency in Fayetteville, NC, about how they use customer education to build relationships and differentiate their business. Jon has been helping customers build websites for over two… Continue Reading →

Episode 69: The Meteoric Growth of Elementor with Kfir Bitton - Wordfence Blog

On February 26, WordPress page building platform Elementor announced that they had received $15 million in venture funding. After topping 4 million installations of their plugin in January, it appears that Elementor is on a path to do some big… Continue Reading →

Episode 68: More Plugin Vulnerabilities and Active Attack Campaigns - Wordfence Blog

This week, we review numerous plugin vulnerabilities in popular WordPress plugins and the attacks that are targeting them. We also review the Duplicator vulnerability affecting over 1 million sites, and Chloe Chamberland’s discovery of multiple vulnerabilities in the Pricing Table… Continue Reading →

Episode 67: Avoiding Common Vulnerabilities When Developing WordPress Plugins - Wordfence Blog

Almost every week, a new vulnerability is discovered in a popular WordPress plugin or theme, leaving developers scrambling to fix it before it’s widely exploited. Surprisingly, almost all critical vulnerabilities boil down to a few common mistakes. In this talk… Continue Reading →

Episode 66: New Plugin Vulnerabilities & Succeeding as a Digital Nomad with Chloe at WCPHX - Wordfence Blog

It has been a busy week in WordPress security with active attacks on a number of plugins including ThemeRex Addons and Theme Grill Demo Importer plugins. In this week’s Think Like a Hacker, we look at what’s happening, review what… Continue Reading →

Episode 65: WordCamp Asia Cancellation Prompts Community Support - Wordfence Blog

WordCamp Asia was cancelled this week due to concerns of COVID-19/coronavirus in the region. This week, Wordfence CEO Mark Maunder talks about the decision to offer the WordCamp Asia Cancellation Fee Assistance Package to attendees, volunteers, organizers, and speakers that… Continue Reading →

Podcast Episode 64: Backdoors, Webshells, and the Growing Risks of Leaks & Breaches - Wordfence Blog

We take a look at the annual hacked site report from GoDaddy’s Sucuri Security and the types of malware they found in various CMS and shopping cart applications. Microsoft reports they’re finding 77k webshells daily, and WP Scan’s roundup lists… Continue Reading →

Podcast Episode 63: Succeeding as a Remote Working Nomad with Chloe Chamberland - Wordfence Blog

Chloe Chamberland never wanted to get into security, and yet in the last three years, she has emerged as one of our most effective and prolific threat researchers. Not only does she find vulnerabilities in numerous popular plugins, she also… Continue Reading →

Episode 62: 2019 Think Like a Hacker Highlights - Wordfence Blog

We’ve had quite a year with Think Like a Hacker, the podcast about WordPress, security and innovation. For this end of year episode, we take a look back at a few of our favorite interviews and news stories. We review… Continue Reading →

Episode 61: Improving Website Performance and User Experiences with Dave Ryan - Wordfence Blog

With Google Chrome experimenting with a badge of shame for websites that load slowly in Chrome, there is a new urgency for high performance interfaces for web users. Gatsby, Gridsome and other static site interfaces are hot in the development… Continue Reading →

Podcast Episode 60: Top WordPress Influencer Lists & Chrome Password Security Improvements - Wordfence Blog

A small furor erupted over a top influencers in WordPress list that neglected to show the diverse nature of the WordPress community. We talk about the impossibility of making an accurate list that reflects the true nature of WordPress influence… Continue Reading →

« Older posts Newer posts »

© 2025 WP News Desk — Powered by WordPress and WP RSS Aggregator | Hosted by WP Engine

Up ↑