Blog Posts

Multiple MainWP Vulnerabilities Affecting Its Extensions

Published on January 17, 2023

Introduction to MainWP vulnerabilities At Patchstack we accept vulnerability reports from individual researchers but also do our own research – often by randomly selecting a plugin. This time it happens that, during a quick inspection of a MainWP extension, we found a vulnerability. This led us to perform the same inspection in the other MainWP […]

Read more →

Patchstack Weekly #55: How To Choose a Secure Web Hosting Provider?

Published on January 16, 2023

In the dynamic world of web hosting, the foundation of your WordPress website’s security lies in the choice of your hosting provider.  When it comes to your WordPress site, security isn’t merely an option – it’s an absolute necessity. A secure web hosting environment forms the bedrock of your site’s defense against an ever-evolving landscape […]

Read more →

Patchstack Weekly #53: Security Best Practice – Rotate Your Passwords

Published on January 3, 2023

Welcome to the Patchstack Weekly Security Update, Episode 53! This update is for the first week of 2023. I will start by wishing you a Happy New Year – and thank you for listening/reading! 2023’s first week’s news will include an update related to the LastPass compromise from last summer. The cloud-based password vault vendor […]

Read more →

Patching an XSS Security Bug in “add-comments” Plugin

Published on December 22, 2022

Accepting your mistakes. The human experience is full of mistakes, failures, and folly. I would say this is “the truth” but this statement itself may be wrong, and I accept that .. but I’m saying this first to make my next point. Mistakes make the world go round. We can observe a fault and learn […]

Read more →

Patchstack Weekly #52: Will AI Change Web Security?

Published on December 21, 2022

Welcome to the Patchstack Weekly Security Update, Episode 52! This update is for week 51 of 2022 and this is planned to be the last Patchstack Weekly of the year. This week’s news is about some interactions I had with an AI chatbot called ChatGPT. I will share this chatbot’s amazing ability to write code, […]

Read more →

Most Common WordPress Vulnerabilities & How to Fix Them

Published on December 13, 2022

The purpose of this article is to provide information to developers and researchers regarding how vulnerabilities can exist in their plugins or themes and how these vulnerabilities can get patched up in order to increase the safety of the world-wide-web in general. Note that we will only provide basic information about these vulnerabilities. There is […]

Read more →

Patching an Arbitrary User Creation Security Bug in “thecartpress” Plugin

Published on December 12, 2022

When people come together, contribute to a like-minded goal. Great things can happen. Community is inherent in any successful open source project. The good news is, connecting with others is something humans are good at doing. The bad news is, not all open source projects benefit from this. Connection and community are powerful tools for […]

Read more →

Patchstack Weekly #51: How One Vulnerability Affects Many

Published on December 12, 2022

Welcome to the Patchstack Weekly Security Update, Episode 51! This update is for week 50 of 2022. This week’s knowledge share is about a recent influx of patched security bugs affecting a single vendor. Don’t panic though, the bugs are low risk. The noteworthy part is the number of products affected by the same bug. […]

Read more →
Previous Page 22 of 40 (398 total posts) Next