Wordpress Related News

Join the discussions about using Wordpress as a blogging platform and content management system for your website or blog.
Forum rules
Please make yourself familiar with our rules and guidelines before posting.
Accrete
Administrator
Posts: 1786
Joined: Fri Nov 08, 2019 12:44 am
Latest blog post: Have You Read the Webmaster Guidelines Yourself?
Answers: 1
Reputation: 987
Location: Canada
Has thanked: 22 times
Been thanked: 113 times
Contact:

WordPress Injection Anchors Widespread Malware Campaign

Post by Accrete »

Possibly you could check if you have been affected by this using the site operator to find extra pages you did not publish yourself:
Website admins should patch all plugins, WordPress itself and back-end servers as soon as possible.

The downloader malware known as Gootloader is poisoning websites globally as part of an extensive drive-by and watering-hole cybercampaign that abuses WordPress sites by injecting them with hundreds of pages of fake content.

The adversaries have so far delivered the Cobalt Strike intrusion tool, the Gootkit banking trojan or the REvil ransomware, according to a forensic analysis.

Researchers with eSentire spotted a Gootloader campaign in December, infiltrating dozens of legitimate websites involved in the hotel industry, high-end retail, education, healthcare, music and visual arts, among others. All of the compromised sites run on WordPress.
WordPress Injection Anchors Widespread Malware Campaign
March 5, 2021
Yours truly,
Accrete Web Solutions

SEO troubleshooting and review services available. - Pm me.

Accrete
Administrator
Posts: 1786
Joined: Fri Nov 08, 2019 12:44 am
Latest blog post: Have You Read the Webmaster Guidelines Yourself?
Answers: 1
Reputation: 987
Location: Canada
Has thanked: 22 times
Been thanked: 113 times
Contact:

WordPress 5.7 “Esperanza”

Post by Accrete »

As usual, readers are reminded to double check your plugins still work even if you have your Wordpress site set to auto update.
...With this new version, WordPress brings you fresh colors. The editor helps you work in a few places you couldn’t before without getting into code or hiring a pro. The controls you use most are right where you need them. Layout changes that should be simple, are even simpler to make....
WordPress 5.7 “Esperanza”
March 9, 2021
Yours truly,
Accrete Web Solutions

SEO troubleshooting and review services available. - Pm me.

Accrete
Administrator
Posts: 1786
Joined: Fri Nov 08, 2019 12:44 am
Latest blog post: Have You Read the Webmaster Guidelines Yourself?
Answers: 1
Reputation: 987
Location: Canada
Has thanked: 22 times
Been thanked: 113 times
Contact:

Security Hole in Plus Addons for Elementor plugin

Post by Accrete »

So glad I don't use a pile of plugins on a Wordpress site. It's a full time job keeping up with the hacks:
The security hole in the Plus Addons for Elementor plugin was used in active zero-day attacks prior to a patch being issued.

The Plus Addons for Elementor plugin for WordPress has a critical security vulnerability that attackers can exploit to quickly, easily and remotely take over a website. First reported as a zero-day bug, researchers said it’s being actively attacked in the wild.

The plugin, which has more than 30,000 active installations according to its developer, allows site owners to create various user-facing widgets for their websites, including user logins and registration forms that can be added to an Elementor page. Elementor is a site-building tool for WordPress...
Cyberattackers Exploiting Critical WordPress Plugin Bug
March 10, 2021
Yours truly,
Accrete Web Solutions

SEO troubleshooting and review services available. - Pm me.

Accrete
Administrator
Posts: 1786
Joined: Fri Nov 08, 2019 12:44 am
Latest blog post: Have You Read the Webmaster Guidelines Yourself?
Answers: 1
Reputation: 987
Location: Canada
Has thanked: 22 times
Been thanked: 113 times
Contact:

WordPress 5.7.1 Security and Maintenance Release

Post by Accrete »

This security and maintenance release features 26 bug fixes in addition to two security fixes. Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 4.7 have also been updated.

WordPress 5.7.1 is a short-cycle security and maintenance release. The next major release will be version 5.8....
WordPress 5.7.1 Security and Maintenance Release
April 15, 2021
Yours truly,
Accrete Web Solutions

SEO troubleshooting and review services available. - Pm me.

Accrete
Administrator
Posts: 1786
Joined: Fri Nov 08, 2019 12:44 am
Latest blog post: Have You Read the Webmaster Guidelines Yourself?
Answers: 1
Reputation: 987
Location: Canada
Has thanked: 22 times
Been thanked: 113 times
Contact:

ReDi Restaurant Reservation Patches Easy-to-Exploit XSS Bug

Post by Accrete »

Anyone using ReDi Restaurant Reservation Wordpress plugin needs to read this:

A WordPress reservation plugin has a vulnerability that allows unauthenticated hackers to access reservation data stored by site owners.

An easy-to-exploit bug impacting the WordPress plugin ReDi Restaurant Reservation allows unauthenticated attackers to pilfer reservation data and customer personal identifiable information by simply submitting a malicious snippet of JavaScript code into the reservation comment field...
Restaurant Reservation System Patches Easy-to-Exploit XSS Bug
May 24, 2021
Yours truly,
Accrete Web Solutions

SEO troubleshooting and review services available. - Pm me.

Accrete
Administrator
Posts: 1786
Joined: Fri Nov 08, 2019 12:44 am
Latest blog post: Have You Read the Webmaster Guidelines Yourself?
Answers: 1
Reputation: 987
Location: Canada
Has thanked: 22 times
Been thanked: 113 times
Contact:

WordPress 5.8 Tatum

Post by Accrete »

WordPress 5.8 Tatum was released today.
Introducing 5.8 “Tatum”, our latest and greatest release now available for download or update in your dashboard. Named in honor of Art Tatum, the legendary Jazz pianist. His formidable technique and willingness to push boundaries inspired musicians and changed what people thought could be done. ...
WordPress 5.8 Tatum
July 20, 2021
Yours truly,
Accrete Web Solutions

SEO troubleshooting and review services available. - Pm me.

Accrete
Administrator
Posts: 1786
Joined: Fri Nov 08, 2019 12:44 am
Latest blog post: Have You Read the Webmaster Guidelines Yourself?
Answers: 1
Reputation: 987
Location: Canada
Has thanked: 22 times
Been thanked: 113 times
Contact:

XSS Bug in SEOPress WordPress Plugin Allows Site Takeover

Post by Accrete »

If you are using the SEOPress Wordpress plugin you will want to read this:
The bug would allow a number of malicious actions, up to and including full site takeover. The vulnerable plugin is installed on 100,000 websites.

A stored cross-site scripting (XSS) vulnerability in the SEOPress WordPress plugin could allow attackers to inject arbitrary web scripts into websites, researchers said....
XSS Bug in SEOPress WordPress Plugin Allows Site Takeover
Yours truly,
Accrete Web Solutions

SEO troubleshooting and review services available. - Pm me.

Post Reply

Return to “WordPress”

Who is online

Users browsing this forum: No members and 11 guests