Security

WordPress security news and issues.

A critical vulnerability was found in…

Photo of author
Dan Knauss
A critical vulnerability was found in the Ultimate Addons for Elementor and Ultimate Addons for Beaver Builder plugins. Hackers can gain full control of your website through them if you don't apply the security updates.

WordPress 5.2.4 was released to address…

Photo of author
Dan Knauss
WordPress 5.2.4 was released to address at least six security issues. 🔒 The first release candidate for WordPress 5.3 is available now, as well. 🏁 Remember, this release includes and fully supports PHP 7.4! More information about 5.3 continues to…

According to a recent post on…

Photo of author
Dan Knauss
According to a recent post on Google's official security blog, Chrome is being prepared to start blocking all mixed content. As of Chrome 79, the browser "will gradually move to block all mixed content by default." It will auto-upgrade mixed…

WordPress 5.2.3 is out. It’s a…

Photo of author
Dan Knauss
WordPress 5.2.3 is out. It's a security and maintenance release that includes 29 fixes and enhancements, including an update of jQuery for older versions of WordPress. ✨

WordPress 5.2 was released as scheduled…

Photo of author
Dan Knauss
WordPress 5.2 was released as scheduled on Tuesday. Thanks to Site Health, PHP Error Protection, and the minimum PHP version bump (to 5.6.20), this has been one of the best-received updates that I can remember. 🤗 There were over 327…

🎙️ I’ve been out of town…

Photo of author
Dan Knauss
🎙️ I've been out of town recently, so I haven't had the chance to listen to many podcasts. There have been a few standouts, however, that I've got queued up to listen to next: If you're looking for a great…

Justin Tadlock posted an update about…

Photo of author
Dan Knauss
Justin Tadlock posted an update about his focus and direction with Theme Hybrid as he limits his scope to a few key projects: "It’s hard to build truly great products when you can never focus on any given thing at…

The PHP minimum version bump is…

Photo of author
Brian Krogsgard
The PHP minimum version bump is happening! As noted in this Trac ticket, WordPress's support for PHP 5.2 - 5.5 officially ends now, and the minimum required PHP version is 5.6. As Scott Arciszewski explains, the impending release of WordPress…

Felix Arntz explains how the Fatal…

Photo of author
Brian Krogsgard
Felix Arntz explains how the Fatal Error Protection feature had to be dropped from WordPress 5.1 due to several security concerns. It appears error protection is here to stay, however, and Felix goes into detail about the completely new approach…

WordPress 5.1.1 is out as a…

Photo of author
Brian Krogsgard
WordPress 5.1.1 is out as a security and maintenance release. 🔒 The vulnerability fixed in the 5.1.1 is detailed by Simon Scannell of RipsTech, who discovered it. 5.1.1 also includes a new button that hosts can enable to encourage site owners to…

Freemius CEO and cofounder Vova Feldman…

Photo of author
Brian Krogsgard
Freemius CEO and cofounder Vova Feldman shares what others can learn from Freemius' recent experience with a significant security vulnerability. Also from Freemius: how Brexit may affect theme and plugin sellers.

W3C has approved WebAuthn as the…

Photo of author
Dan Knauss
W3C has approved WebAuthn as the web standard for "password-free logins", letting "users log into online accounts using biometrics, mobile devices, and/or FIDO security keys." 🔐 It will be interesting to see how this develops and impacts WordPress. Nearly all browsers…

BuddyPress 4.2.0 is out. This important…

Photo of author
Dan Knauss
BuddyPress 4.2.0 is out. This important maintenance and security release addresses a cross-site scripting (XSS) vulnerability in addition to a privilege escalation vulnerability.
A2 Hosting
Omnisend
WordPress.com