WordPress 4.2.3 is now available. This update addresses a cross-site scripting vulnerability and contains fixes for 20 bugs found in 4.2. Users are urged to update their sites immediately. You can download WordPress 4.2.3 directly here, or navigate to Dashboard > Updates, and click “Update Now.” The XSS vulnerability, reported by Jon Cave, allows users with the Contributor or Author user role to potentially compromise a site. Another issue was identified and addressed in this update “where it was possible for a user with Subscriber permissions to create a draft through Quick Draft. Reported by Netanel Rubin from Check Point Software Technologies.” You can view the […]
WordPress Security: 13 Steps to Make Your Website Bulletproof
Let me just say it: WordPress is awesome. Millions of people have flocked to the platform and use it in their daily business. However, there’s a dark side to the growing popularity of WordPress: Because it powers more and more websites, the number of hackers and other shady individuals who target WordPress is also steadily growing. As a consequence, security is an increasing concern for all WordPress users. Yet, at the same time, it is a much neglected topic, because, quite frankly, many find it boring. You know what else is boring? Health insurance. But just like WordPress security measures, you are glad […]
Stronger together, learning from WordPress security vulnerabilities
Last week two very popular plugins, WooCommerce and WordPress SEO, identified, fixed, and disclosed security issues. The details of these vulnerabilities are now publicly available, which allows other developers to learn from their mistakes. In a previous article for Torque, I discussed the importance of responsibly disclosing security issues. To get a better understanding of this in relation to the recent vulnerabilities I reached out to James Golovich, a WordPress developer who recently discovered security issues in WP All Import, Easy Digital Downloads, and IgnitionDeck as well as several other plugins and themes, which he details on his highly informative blog. […]
5 of the best WordPress security plugins
Contrary to what you may have heard, the core WordPress software is very secure. So why do you hear about other people’s WordPress sites being hacked? Perhaps even you’ve been hacked yourself. These security breaches occur not because of a vulnerability in the WordPress software, but because of weak user passwords, vulnerabilities in plugins or themes, and not keeping the software up to date. Still, in today’s world, when big companies like Sony and Apple are getting hacked, nothing is ever 100% secure. So we want to take steps to make our websites as secure as possible. I’ve gathered 5 of the […]
11 simple tips to boost your website’s security
When launching a new website it’s easy to get carried away with crafting the perfect design and adding great content. For many, including myself, security is merely an afterthought. However, every year attacks on WordPress websites are growing in-line with the platforms popularity. More worryingly, 70% of WordPress websites have vulnerabilities that hackers could exploit. With minimal protection, that means your precious website could be a hacker’s next play-thing – scary, right? Today I want to help you boost your WordPress website’s security with eleven simple tips you can implement right away. If you want to build a successful, sustainable […]
No Comments