On Tuesday, Sucuri reported a large-scale concerted attack injecting malware into WordPress sites, causing them to break. Upon further investigation, Sucuri researchers discovered that the exploitation is happening through a recent vulnerability found in the popular WordPress plugin MailPoet. In Sucuri’s blog post, Daniel Cid, CTO and Founder of Sucuri, stated, To be clear, the MailPoet vulnerability is the entry point, it doesn’t mean your website has to have it enabled or that you have it on the website; if it resides on the server, in a neighboring website, it can still affect your website. Even sites within the same […]
Sucuri Reports Malware Infection Targeting WordPress Sites
Earlier today, Sucuri reported a malware infection targeting WordPress sites! The announcement indicates: The last few days has brought about a massive influx of broken WordPress websites. What makes [this infection] so unique is that the malicious payload is being blindly injected which is causing websites to break. The malware targets WordPress sites through vulnerabilities such as weak admin passwords and outdated plugins. According to Sucuri, upon infiltration the infector PHP corrupts WordPress core files, as well as theme and plugin files—leaving PHP errors displayed in the place of content throughout the infected site. Sucuri is continuing to investigate and will provide details as […]
On the WordPress Content Modeling Problem
Last week, there was a bit of a stir regarding WordPress’s upcoming 4.0 release. Raelene Wilson started it off with a post about the “underwhelming” nature of the newest release, especially when looked at from the point of view of an average user. Pippin Williamson rebutted with a post on the importance of refinement in WordPress development, getting features 100% of the way there. Then came a sort of response from Chris Knowles outlining a roadmap of potentially more ambitious features. Many oft-cited questions came up again. Should WordPress remain backwards compatible? Does WordPress need a more refined vision? Is WordPress moving […]
DradCast Episode 051: Captial_Pippin_Dangit
[y=qGCavUwFl7A height=400] Show Notes Host Pippin Williamson is the developer and founder of some great WordPress plugins like Restrict Content Pro and Easy Digital Downloads. He is known for his ninja-like ability to produce amazing plugins at the drop of a hat. In addition to producing hundreds of plugins, Pippin also speaks at WordCamps and consults. You can find Pippin online at Easy Digital Downloads and on Twitter @pippinsplugins. Sippin’ On Brad – Scotch Dre – Canada Dry Pippin – Flemmish Sour from Belgium Pressing Topics WordPress 4.0 Beta 1 4.0 beta 1 was just released. WordPress.org has the details of the release in their post. Critical Security […]
The Ultimate Guide to Updating Your WordPress Site
WordPress is constantly evolving. With the help of trusty developers and the constant feedback from the community, the platform is frequently updated. Besides new features, updates address security vulnerabilities, and generally improve the overall WordPress experience. Keeping your site updated with the newest version will give you the latest and greatest that WordPress has to offer. However, staying up to date can be tedious. Unforeseen hiccups, compatibility issues with plugins, and other unfortunate consequences are not unheard of. More than a few users have had their site break, experienced downtime, or lost data due to problems with the update process. Of […]

1 Comment