Best WordPress Hosting
 

Elementor is Still Providing Access to Security Nonces to WordPress Users Who Shouldn’t Have Them

We are currently in the process of reviewing a partially disclosed possible vulnerability in a 200,000+ install WordPress plugin that extends the 5+ million install plugin Elementor. One issue we found with the possible vulnerability is that the developer is Continue reading Elementor is Still Providing Access to Security Nonces to WordPress Users Who Shouldn’t Have Them

The WordPress 6.4.3 Security Update – What You Need to Know

Today, January 30, 2024, WordPress released version 6.4.3, which contains two security patches for longstanding, albeit minor, security concerns in WordPress Core. The first patch addresses an issue that allows users with Administrator (or Super Administrator on Multisite) privileges to Continue reading The WordPress 6.4.3 Security Update – What You Need to Know

Solid Security: Elevating Your Protection with Improved Firewall Management

Solid Security Pro 8.3.0 is now available for download. This release contains a new feature to the Firewall that provides an easier way to block or authorize IP addresses. You’ll find this feature in the new IP Management tab on Continue reading Solid Security: Elevating Your Protection with Improved Firewall Management

Cloudflare Only Added One Firewall Rule for a WordPress Plugin Vulnerability Last Year and It Was Eight Months Late

We recently ran across a WordPress support service that was making some extraordinary claims about their handling of security. They were not close to true, considering we were visiting their website to try to notify them that they had failed Continue reading Cloudflare Only Added One Firewall Rule for a WordPress Plugin Vulnerability Last Year and It Was Eight Months Late

Vulnerability & Patch Roundup January 2024

Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educate website owners on emerging threats to their environments, we’ve Continue reading Vulnerability & Patch Roundup January 2024

$1,275 Bounty Awarded For Arbitrary File Deletion Vulnerability Patched in MW WP Form WordPress Plugin

Did you know we’re running a Bug Bounty Extravaganza again? Earn over 6x our usual bounty rates, up to $10,000, for all vulnerabilities submitted through February 29th, 2024 when you opt to have Wordfence handle responsible disclosure! On December 5th, Continue reading $1,275 Bounty Awarded For Arbitrary File Deletion Vulnerability Patched in MW WP Form WordPress Plugin

Welcome GrooveHQ to the WPBeginner Growth Fund

Today, I’m extremely excited to announce that WPBeginner Growth Fund has taken an investment stake in GrooveHQ, a top-rated customer support help desk software. Over 2,000+ businesses around the world use Groove’s help desk software to offer best-in-class customer support Continue reading Welcome GrooveHQ to the WPBeginner Growth Fund