Wordfence Research and News

Blog icon
Category: WordPress Security

3 Severe Plugin Vulnerabilities Fixed in the Last 24 Hours

The following three plugins contain severe vulnerabilities that have all been fixed within the past 24 hours. 

WordPress 4.4.2 Security Release – Why you need to update immediately

It’s been a busy morning in WordPress security. Right after we released details of the attack platform we recently analyzed, WordPress released a security update in the form of 4.4.2.

An Attack Platform Infecting WordPress Sites

At Wordfence we frequently investigate hacked customer websites as part of an ongoing R&D effort to improve our core scanning engine.

WordPress Security January Roundup: Core XSS and 4 Plugin vulnerabilities

This has certainly been an eventful month in WordPress security. January 6th saw a WordPress core security update.

WordPress Security for Beginners – Where to Start

One of the reasons that WordPress is so popular, powering 25% of all websites, is how easy it is use.

The 2015 WordPress Security Survey Results are out

To bring a close to 2015 we conducted a WordPress security survey.

Aethra Botnet Attacks WordPress Sites

Exec summary: There is currently a botnet that has been identified that is targeting WordPress websites with a password guessing attack.

Security Concepts: Half of all WordPress Plugin Vulnerabilities are XSS and Securing FTP

We had a lot of fun creating our WordPress Security Learning Center.

Announcing the WordPress Security Learning Center

Dear WordPress Community, Today we have something amazing to share with you.

WPEngine Credentials Exposed

Update 1 (3:10pm CST on Dec 10th): WPEngine is working with federal law enforcement as part of their investigation into the breach.