Wordfence Research and News

Blog icon
Category: Wordfence

Hacking 27% of the Web via WordPress Auto-Update

At Wordfence, we continually look for security vulnerabilities in the third party plugins and themes that are widely used by the WordPress community.

Revslider, MailPoet, GravityForms Exploits Bypass Cloudflare WAF

Update: We have received reports from a plugin vendor that there may be some confusion about whether or not the plugins referred to in this post are still vulnerable.

Endpoint vs Cloud Security: The Cloud WAF User Identity Problem

Imagine you’re a security guard at the entrance to a high security facility.

We are removing Falcon Cache from Wordfence. Here’s what you need to know.

Version 6.2.1 of Wordfence was just released and you may have noticed in the changelog that we’ve announced that we will be removing Falcon from Wordfence.

Endpoint vs Cloud Security: The Cloud WAF Bypass Problem

Earlier this year at Black Hat 2016 there was a lot of buzz around “endpoint security”. 

18X Speedup in Wordfence Scan

Wordfence 6.2.0 was released yesterday and it includes something really special: a huge improvement in scan performance.

Interview with Security Researcher Pan Vagenas

At Wordfence I’m really proud of the team we have. Our team are all amazing people who work hard every day to help secure WordPress websites.

Wordfence Integrates Malware Scan Into Firewall

If you’ve been using the Wordfence Firewall for a while, you may have noticed that our firewall ruleset has been growing steadily over the past few months.

Malware: 139,000 WordPress Sites Saved in 30 Days

Wordfence provides two core security capabilities to the websites we protect. 

We will always put our customers and community first

On Tuesday we published a blog post about the 404 to 301 plugin inserting ad links into page content that only search engines could see.