Security

WordPress security news and issues.

Pentesting as Contributing

Photo of author
Dan Knauss
Robert Rowley at Patchstack explains what I believe is the first-ever reported vulnerability in Gutenberg (the plugin, not in WordPress core) to make the National Vulnerability Database. Robert has opened an issue for discussion in the Gutenberg GitHub repo that…

Nulled Themes and Plugins

Photo of author
Dan Knauss
My first experiences with "nulled" (or back in the day "cracked") software date back to the golden days of the Atari 8-bit and Commodore Amiga. Blank floppy disks were cheap, and like most kids, I did not have a lot…

Post Status Picks for the Week of July 18

Photo of author
Dan Knauss
Your Post Status Podcast Picks of the week include Seeking Satisfaction with Victor Ramirez on the importance of networking, managing anxiety, and rethinking the way websites are built. WP Coffee Talk features the woman with the best personal Wapuu, Michelle Frechette, talking with Mark Westguard, founder of the WS Form plugin about his work, the love and opportunity in the WordPress community, and more.

Join the Incident Response Team

Photo of author
Dan Knauss
The now-forming Incident Response Team (IRT) is a community-led effort to help us all build and sustain a culture around WordPress that is healthy, inclusive, and safe. Angela Jin is calling for your nominations for a diverse group of people who can contribute by serving on the IRT.

The scariest thing I’ve seen in a long time

Photo of author
Dan Knauss
Thomas Nachbar of the University of Virginia School of Law writes in "Why We Can’t Disconnect Russia From the Internet" how he would really like to do so — and more: In the heady early days of the internet, the…

Open Secrets: Forced Updates in WordPress

Photo of author
Dan Knauss
We've seen forced updates become increasingly common and less controversial over time. But who decides, and how is that decision made? Are there unofficial channels and processes, like a decision tree, for escalating to a forced update?

Post Status Notes #498

Photo of author
David Bisset
Are we up or down? What should happen when a license expires? Is the block protocol worth it? Driesnote 2022. WP Engine expands. Becoming a better writer. Best backup solutions. Define your role. Reaktiv wins a spot in Inc's Best Workplaces. Open Source JobHub. Our passwordless future.
A2 Hosting
Omnisend
WordPress.com