Security

WordPress security news and issues.

Call a Vulnerability a Vulnerability Roger…

Photo of author
Dan Knauss
Call a Vulnerability a Vulnerability Roger Montii reporting for SEJ looks at an Authenticated Stored XSS vulnerability in the WPBakery Page Builder plugin. The vulnerability was discovered by Wordfence and fixed through their collaboration with WPBakery in a recent update.…

Joe Howard explains at Torque how…

Photo of author
Dan Knauss
Joe Howard explains at Torque how to begin developing headless WordPress sites. The main advantages are flexibility and control, easier multi-channel content publishing, and better security and speed. 👤🪓 Joe names three tools to help you get started: GraphQL API,…

PHP 8 is in feature freeze,…

Photo of author
Dan Knauss
PHP 8 is in feature freeze, and Beta 1 has been released. There are also new security releases for stable PHP versions 7.2.33, 7.3.21 and 7.4.9. 🔒

WordPress 5.4.2 is a security and…

Photo of author
Dan Knauss
WordPress 5.4.2 is a security and maintenance release that rolled out on June 10. It features 23 bugfixes and enhancements. Make sure your sites are updated if that hasn't happened automatically. One maintenance update was also deployed back to versions…

Matt Shaw explains how the JavaScript…

Photo of author
Dan Knauss
Matt Shaw explains how the JavaScript FileReader API can be used to upload large files in chunks and avoid server limits. The API has major browser support now, including Chrome, Firefox, Safari, and Internet Explorer 10. Matt notes, "If you’re…

WordPress 5.4.1 dropped this week. It’s…

Photo of author
Dan Knauss
WordPress 5.4.1 dropped this week. It's a short-cycle security and maintenance release focused on seven security issues that affected WordPress 5.4 and earlier versions. If you haven’t yet updated to 5.4, all WordPress versions since 3.7 have also been updated.…

We’re wishing Tony Perez all the…

Photo of author
Dan Knauss
We're wishing Tony Perez all the best as he leaves GoDaddy and explores full-time work on his projects CleanBrowsing (a DNS-based content filtering service) and ColdPath (a security consulting company). 🛅

Gus Luxton talks about some easy…

Photo of author
Dan Knauss
Gus Luxton talks about some easy ways you can improve the security of your SSH model without needing to deploy a new application or make any huge changes to user experience. 🔒

Big news! Github has acquired npm,…

Photo of author
Dan Knauss
Big news! Github has acquired npm, Inc. the company behind the Node package manager registry. 📦 Github claims npm will "always be available and free." They will integrate GitHub and npm to "improve the security of the open-source software supply…

A critical security update was recently…

Photo of author
Brian Krogsgard
A critical security update was recently issued for Duplicator that Wordfence reported as affecting over a million WordPress sites. 🔓 Duplicator users should update to version 1.3.28 as soon as possible.

If you use the Demo Importer…

Photo of author
Dan Knauss
If you use the Demo Importer or a commercial theme from ThemeGrill, you should be aware of a security issue that can potentially let attackers wipe out your sites! There is an update available to address this exploit. 😲 Last…

Cody Landefeld has put together a…

Photo of author
Dan Knauss
Cody Landefeld has put together a handy SEO guide for WooCommerce users. Cody advises you to start with the Yoast WooCommerce SEO Plugin, but there are many tips about speed and security too. 🛒
A2 Hosting
Omnisend
WordPress.com