Security is always on the minds of Internet users, and it should be. The idea of having your livelihood affected by someone gaining access to your site is understandably terrifying. There are ways to keep prying eyes at bay and secure your site. Of course, you should make sure you have a secure username and password, and that your site is always up to date. If you’ve done all of this and you’re still worried, there is always more you can do. This roundup will help you keep your site secure and prevent any problems from arising in the future. Whether […]
WordPress 4.4.2 Security And Maintenance Update Now Available
WordPress 4.4.2 is now available for download. Users are strongly urged to update as soon as possible! This update addresses two security issues: A possible XSS for certain local URIs and an open redirection attack. According to the announcement, all versions of WordPress preceding 4.4.2 are affected. The issues were reported by Ronni Skansing and Shailesh Suthar, respectively. 4.4.2 also addresses 17 bugs found in 4.4.1 and 4.4 including, wp_list_comments ignores $comments parameter Pagination issue on front page after 4.4.1 ModSecurity2 blocks Potential Obfuscated JavaScript in outbound anomaly You can update to 4.4.2 in the dashboard or download it directly. If your site […]
WordPress 4.4.1 Security And Maintenance Release Now Available
WordPress 4.4.1 shipped today. The announcement says that Crtc4L reported that anything 4.4 or older could be “affected by a cross-site scripting vulnerability that could allow a site to be compromised.” Users are advised to update as soon as possible. WordPress 4.4.1 addresses issues found in older versions of OpenSSL and includes updated emoji support. The update fixes 52 bugs discovered in WordPress 4.4. To see a full list of the fixes, check the Installation/Update information. You can update your site directly on WordPress.org or in your WordPress dashboard.
WP Engine Prompts Customers To Reset Passwords After Security Exposure
WP Engine late Wednesday sent its customers an urgent security notification regarding an “exposure involving some of our customers’ credentials.” The company urged its customers to immediately update the passwords associated with their WP Engine accounts. According to the security notice, there is no evidence to suggest that this information has been used inappropriately. “Out of an abundance of caution, we are proactively taking security measures across our entire customer base. We have begun an investigation, however there is immediate action we are taking. Additionally, there is action that requires your immediate attention.” WP Engine said its customers should update […]
Maybe We Should Just Trust The WordPress Security Team
This year, at WordCamp Miami, I shared an Airbnb with a few other WordPress developers. The door to the place we were staying had a keypad door lock. I guess I’m too dependent on my password manager because I promptly forgot the code. As a result, at the afterparty, when I was about ready to leave I found one of the people I was staying with—Chris Christoff a developer for Awesome Motive and Easy Digital Downloads, and a member of the WordPress core security team—to ask him for the code. As it turned out, I interrupted a discussion he was having […]
2 Comments