Wordfence Research and News

Blog icon

Announcing Wordfence 6.3.0 – Exciting Improvements

This morning I’m very excited to announce the release of Wordfence 6.3.0.

How the Wordfence Firewall Works

In April of 2016 Wordfence launched a full featured WordPress firewall.

Revslider, MailPoet, GravityForms Exploits Bypass Cloudflare WAF

Update: We have received reports from a plugin vendor that there may be some confusion about whether or not the plugins referred to in this post are still vulnerable.

Endpoint vs Cloud Security: The Cloud WAF Bypass Problem

Earlier this year at Black Hat 2016 there was a lot of buzz around “endpoint security”. 

18X Speedup in Wordfence Scan

Wordfence 6.2.0 was released yesterday and it includes something really special: a huge improvement in scan performance.

Interview with Security Researcher Pan Vagenas

At Wordfence I’m really proud of the team we have. Our team are all amazing people who work hard every day to help secure WordPress websites.

Wordfence Integrates Malware Scan Into Firewall

If you’ve been using the Wordfence Firewall for a while, you may have noticed that our firewall ruleset has been growing steadily over the past few months.

Top 50 Most Attacked WordPress Plugins This Week

Last week we shared the top 20 most attacked WordPress themes and an explanation of why many of them are targeted.

XSS Vulnerability in Wordfence 6.1.1 to 6.1.6. Severity: 6.1 (Medium)

An hour ago a security researcher, Kacper Szurek, reported a reflected XSS vulnerability in the current version of Wordfence.

Wordfence 2015 Update and Three Plugin Vulnerabilities You Should Know About

2015 is going to be an exciting year for WordPress publishers.