Blog Posts

Patchstack Weekly #27: How to Update wp_options Securely.

Published on June 13, 2022

Welcome back to the Patchstack Weekly Security Update! This update is for week 24 of 2022. This week I will cover two high risk unauthenticated vulnerabilities, one could allow attackers to reset an any user’s password (including admin users) and the other could arbitrarily delete files from websites running insecure versions of the plugin. Thankfully […]

Read more →

WordPress Vulnerability News, May 2023

Published on June 13, 2022

WordPress vulnerability news is a weekly digest of highlighted WordPress plugin security vulnerabilities or vulnerability discloses that have been published (there are other, less critical vulnerabilities on smaller plugins that unfortunately don’t make it to the list). Keeping up to date with security vulnerabilities in WordPress and other CMSs is an important part of security. […]

Read more →

Patchstack Weekly, Week 23: What Makes A Good WordPress Community?

Published on June 7, 2022

Welcome back to the Patchstack Weekly security update! This update is for week 23 of 2022. It is the beginning of June, and WordCamp Europe is underway as I write this. WordCamps are the in-person community events for the WordPress community, and WordCamp Europe 2022 is the largest to be run in the last 2 […]

Read more →

Patchstack Weekly, Week 22: How To Create An Incident Response Plan?

Published on May 30, 2022

Welcome back to the Patchstack Weekly security update! This update is for week 22 of 2022. This week there is only one high-risk security bug patched to report on in the vulnerability news. During this week’s knowledge share I will talk about the incident response plan and the importance of having it ready for worst-case […]

Read more →

What’s New In WordPress 6.0?

Published on May 25, 2022

This week was the official release of WordPress 6.0. The release was named after Grammy award-winning Latin jazz and Afro-Cuban jazz musician Arturo O’Farrill, who has a website running none other than WordPress! What a great reminder, of how WordPress powers many independent websites. UI updates in WordPress 6.0 Users who upgrade to WordPress 6.0 […]

Read more →

Patchstack Weekly, Week 20: How To Communicate Security?

Published on May 16, 2022

Welcome back to the Patchstack Weekly security update! This update is for week 20 of 2022. This week I will talk about the importance of communication and how to communicate security when it comes to security issues. Starting from developers needing to communicate security bugs being patched and ending with how Patchstack partners are experiencing […]

Read more →

Winners Of WordPress Bug Hunt 2021

Published on May 11, 2022

In March 2021, we started a bug-hunting program where together with partners, we reward developers and ethical hackers who help us make the WordPress ecosystem more secure. Since then, we have received more than 1000 security reports and paid out $17,450 USD as cash rewards. This is all possible thanks to our dear partners who […]

Read more →

Patchstack Weekly, Week 18: PHP Object Injection aka Insecure Deserialize

Published on May 2, 2022

Welcome back to the Patchstack Weekly Security Update! This update is for week 18 of 2022. This week I will talk about an obscure vulnerability, something that is commonly overlooked and missed by developers, bug bounty hunters, and security researchers alike. PHP Object Injection, also known as Insecure Unserialize. I will get started with this […]

Read more →
Previous Page 27 of 40 (398 total posts) Next