WordPress security shouldn’t be taken lightly. When your entire livelihood is online, you should be taking every measure to make sure your site is safe. No one knows the state of WordPress security better than Sucuri co-founder Dre Armeda. Two years ago, Armeda left the company to pursue other things. Now he is back and just as passionate about web safety as ever. After being gone for two years, Armeda has fresh eyes on the industry and believes the way forward is to use external services. “If there’s already traffic on your site it’s too late. You need to stop thinking beyond the […]
The Non-Techie’s Guide to Common Security Threats
Security is ongoing discussion for WordPress site owners of all levels of technical expertise, but it can be an especially hard area for newbies to get to grips with. While security insiders are fluent in the differences between common attack vectors, it can often appear as little more than a bewildering sea of hard to grasp threats for the average Joe. In this piece, we’ll be looking to fill in some of those knowledge blanks by briefly breaking down what some of the more common threats out there are actually all about. Rather than blind you with acronyms and white papers, we’ll concentrate on […]
5 Challenges Plaguing The WordPress Security Ecosystem
Last month, more than 2,000 attendees from around the world came together in Vienna at WordCamp Europe to share their affinity for WordPress. As I sat there, sweating profusely and sharing ideas and thoughts with attendees, it hit me that we still have a long way to go with security in the community. I spent the next couple of days thinking through it and decided to share my takeaways in an open forum. This article highlights five issues I believe to be plaguing the WordPress security community and provides some thoughts on how we can work together to overcome them. These thoughts come from […]
Jetpack Update 4.0.4 Fixes Security Vulnerabilities
At the beginning of May, Jetpack released 4.0.3 to fix a security issue. Now, the plugin has offered another update, 4.0.4, targeted at three more vulnerabilities. The changelog notes security fixes to post by email, an XSS vulnerability in the Likes module, and the REST API/Contact form. The update also improved features like developing on Kinsta, Jetpack for multisite, and connection process. There are also a variety of bugs that are taken care of improved compatibility. 4.0.4 also offers better access to customer support. There is now a contact form in admin that goes directly to the customer service team, […]
EWWW Image Optimizer 2.8.5 Patches Critical Security Vulnerability
Wordfence this week disclosed a critical remote code execution vulnerability found in the EWWW Image Optimizer plugin to the plugin’s author Shane Bishop. Bishop yesterday released a fix for the vulnerability, which can be found on WordPress.org. Users running the EWWW Image Optimizer plugin should update to version 2.8.5 immediately as this is a critical security update. According to Wordfence, the vulnerability, which was discovered by Wordfence Senior Developer Sean Murphy, allows hackers to exploit multisite installations to gain total control of a site. “The vulnerability can be exploited in a number of ways including creating a backdoor or taking a site down altogether,” […]
1 Comment