Best WordPress Hosting
 

Hackers Actively Exploiting Unpatched Privilege Escalation Vulnerability in Ultimate Member Plugin

WPScan is reporting a hacking campaign actively exploiting an unpatched vulnerability in the Ultimate Member plugin, which allows unauthenticated attackers to create new user accounts with administrative privileges and take over the site. The vulnerability has been assigned a CVSSv3.1 Continue reading Hackers Actively Exploiting Unpatched Privilege Escalation Vulnerability in Ultimate Member Plugin

WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

Patchstack is reporting an Insecure Direct Object References (IDOR) vulnerability in WooCommerce Stripe Gateway, the most popular WooCommerce Stripe payment plugin with more than 900,000 active users. It was discovered by Patchstack researcher Rafie Muhammad on April 17, 2023, and Continue reading WooCommerce Stripe Gateway Plugin Patches Security Vulnerability in 7.4.1

WordPress.org Enables Commercial and Community Filters on Plugin and Theme Directories

During the 2022 State of the Word, Matt Mullenweg announced a plan to add new “Community” and “Commercial” taxonomies for the theme and plugin directories that would help users more quickly ascertain the purpose of the extensions they are considering. Continue reading WordPress.org Enables Commercial and Community Filters on Plugin and Theme Directories

ACF Plugin’s Reflected XSS Vulnerability Attracts Exploit Attempts Within 24 Hours of Public Announcement

On May 5, Patchstack published a security advisory about a high severity reflected cross-site scripting (XSS) vulnerability in ACF (Advanced Custom Fields), potentially affecting more than 4.5 million users. WP Engine patched the vulnerability on May 4, but the Akamai Continue reading ACF Plugin’s Reflected XSS Vulnerability Attracts Exploit Attempts Within 24 Hours of Public Announcement

Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

Essential Addons for Elementor, a plugin with more than a million active installs, has patched an unauthenticated privilege escalation vulnerability in version 5.7.2. The vulnerability was discovered on May 8, 2023, and reported by Patchstack researcher Rafie Muhammad. It was given Continue reading Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

Periodic Table of WordPress Plugins Showcases 108 Most Popular Plugins

WordPress core committer Pascal Birchler has published a Periodic Table of WordPress Plugins to celebrate the software’s upcoming 20th anniversary. The table showcases 108 of the most popular free plugins on WordPress.org. Ten years ago Birchler created a website that Continue reading Periodic Table of WordPress Plugins Showcases 108 Most Popular Plugins

Newly Rewritten WordPress SQLite Database Integration Plugin Needs Testing

WordPress contributors are making progress on officially supporting SQLite in core, a project that would benefit less complex sites (small to medium sites and blogs) that don’t necessarily require WordPress’ standard MySQL database. In a recent update, Yoast-sponsored core contributor Continue reading Newly Rewritten WordPress SQLite Database Integration Plugin Needs Testing