Wordfence Research and News

Blog icon
Category: Wordfence

Vulnerability Roundup: 3 Vulnerable WP Plugins and Update Your Joomla

It’s been a tough week for the WP Statistics plugin. Last Friday, Sucuri (now owned by GoDaddy) discovered a SQL injection vulnerability in the WP Statistics plugin version 12.0.7 and older.

The 2017 WordPress Security Half-Time Report

2017 has been a remarkable year so far for Wordfence and our customers.

New in Wordfence 6.3.11: Abandoned and Removed Plugin Alerts

On Thursday of last week, we released Wordfence 6.3.11 which included a really exciting new feature: we are now alerting you if you are running a plugin that either appears to be abandoned or has been removed from the WordPress.org plugin directory.

Wordfence Launches WordPress Security Audit Service

This morning I am very excited to announce that Wordfence is officially launching a WordPress Security Audit service.

22 Abandoned WordPress Plugins with Vulnerabilities

As an interesting research project, Pan Vagenas, one of our researchers, took a closer look at abandoned plugins in the WordPress repository.

The April 2017 WordPress Attack Report

Today we are releasing the WordPress Attack Report for April, 2017.

Home Router Botnet Shut Down in Past 72 Hours. Who did it?

On April 11th, 3 weeks ago, we published a story discussing routers at a specific set of ISPs that have been hacked.

20 Minutes to a Secure WordPress Website

Securing WordPress has become easy thanks to the amazing work the WordPress team continuously do to fix vulnerabilities and improve the security of the platform.

Wordfence Site Cleaning Customer Reviews

In June last year we officially launched the Wordfence site cleaning service.

IP Blacklist Update: The Launch and Evolution of The Wordfence IP Blacklist

One of our passion projects at Wordfence has been to find a way to create and run an IP blacklist.