Category: Featured

Nearly 1000 Plugins Closed During WordPress Security Cleanup

Published on November 13, 2024

Patchstack is always looking for new ways to make the WordPress ecosystem safer by organizing various events for ethical hackers and security researchers. Our experiments sometimes lead to unexpected results. Also, these events sometimes uncover issues that were overlooked before. Our latest experiment took place in October. We announced a special event for our Bug […]

Read more →

Rare Case of Privilege Escalation Patched in LiteSpeed Cache Plugin

Published on October 29, 2024

The vulnerability in the LiteSpeed Cache plugin was originally reported by Patchstack Alliance community member TaiYou to the Patchstack bug bounty program for WordPress. We are collaborating with the researcher to release the content of this security advisory article. This blog post is about the LiteSpeed plugin vulnerability. If you’re a LiteSpeed user, please update […]

Read more →

Security implications of WordPress repository access restrictions and plugin closures

Published on October 18, 2024

Over the past couple of weeks, we’ve noticed an increasing number of plugins not receiving updates through WordPress.org. Some have been banned and others cannot log in to their WordPress.org accounts due to the new login requirement under the checkbox “I am not affiliated with WP Engine in any way, financially or otherwise.“. It seems […]

Read more →

Unauthenticated Stored XSS Vulnerability in LiteSpeed Cache Plugin Affecting 6+ Million Sites

Published on October 2, 2024

This blog post is about the LiteSpeed Cache plugin vulnerability which is originally reported by TaiYou to the Patchstack bug bounty program for WordPress. We are collaborating with the researcher to release the content of this security advisory article. If you’re a LiteSpeed Cache user, please update the plugin to at least version 6.5.1. If […]

Read more →
Previous Page 3 of 16 Next