Wordfence Research and News

Blog icon
Category: Wordfence

Top 50 Most Attacked WordPress Plugins This Week

Last week we shared the top 20 most attacked WordPress themes and an explanation of why many of them are targeted.

This Week’s Top 20 Attacked Themes and Who is Attacking Them

Today we’re publishing statistics on the attacks we are seeing on themes across the WordPress ecosystem.

Profile of a Russian Attack IP

At Wordfence we track attacks across all our customer sites, both free and paid to learn more about attacker tactics, techniques and procedures (TTP’s).

New Vulnerability in All in One SEO Pack Plugin 2.3.7 and earlier

Yesterday morning Panagiotis Vagenas, a Wordfence Security Researcher, discovered a new vulnerability in the All in One SEO Pack WordPress plugin.

Serious Vulnerability in All in One SEO Pack Plugin 2.3.6.1 and earlier

There is a serious stored cross site scripting (XSS) vulnerability in All in One SEO Pack Plugin versions 2.3.6.1 and older.

2 Vulnerabilities in Squirrly SEO plugin 6.1.4 and older

Today the Squirrly SEO team released version 6.1.5 of their WordPress plugin, fixing two security vulnerabilities.

Vulnerability in Profile Builder plugin 2.4.0 and older

Wordfence Security Researcher Panagiotis Vagenas recently discovered a privilege escalation vulnerability in the Profile Builder WordPress plugin, which has over 40,000 active installs according to wordpress.org.

3 Vulnerabilities in WP Maintenance Mode plugin 2.0.6 and older

This morning an update to the WP Maintenance Mode plugin, version 2.0.7, was released which included fixes for 3 security vulnerabilities.

An Interview with a Wordfence Senior Security Analyst

Colette Chamberland is one of our two Senior Security Analysts who mentor and guide the rest of our team of analysts.

8 Reasons Why You Should Choose Wordfence to Clean Your Hacked Site

At Wordfence we know you have a choice between site cleaning vendors.