Category: Security Advice

Patching an Arbitrary Plugin Disablement Bug in the “webmaster-tools-verification” Plugin

Published on November 29, 2022

Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repository This post will review the webmaster-tools-verification plugin. This plugin was first created in 2009 and is extremely simple […]

Read more →

Patching Remote Code Execution in the ‘member-hero’ Plugin

Published on November 15, 2022

Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repository Today I will be discussing how to address an unauthenticated remote code execution vulnerability in the member-hero plugin. […]

Read more →

How to Avoid Abandoned WordPress Plugins and Themes

Published on July 15, 2022

Abandonware is a silent security risk. With no developer or project lead to address bugs, especially security bugs, you are running code that has no support. If, or when, a security bug is found in an unsupported or abandoned project, then the users who rely on that project will be left with no recourse. They […]

Read more →

Why Hosting Companies Should Send Out WordPress Security Alerts?

Published on April 29, 2022

This article shares some light on how WordPress hosting companies can increase their recurring revenue by sending out WordPress security alerts. The majority of security vulnerabilities in the WordPress ecosystem originate from plugins and themes. In fact, based on the WordPress security 2021 whitepaper where every known security vulnerability was counted, over 99% originated from […]

Read more →

Is WordPress Secure? 5 Biggest Do’s And Don’ts In WordPress Security

Published on January 1, 2022

In this article, we won’t dive into technical details, but try to address a common misconception instead. We will explain what website security is in general, how to secure WordPress and answer the question – is WordPress secure? As per calculations, approximately 380 new websites are created every minute. However, the actual number of new websites being created every […]

Read more →

An In-Depth Analysis Of The WP-VCD Malware

Published on December 2, 2021

The WP-VCD malware for WordPress has existed for many years. It mainly spreads by injecting itself into legitimate plugins and themes after which it will spread itself on sites that offer downloads to (nulled) WordPress plugins and themes. We noticed that during the corona-virus pandemic, the WP-VCD malware has also started injecting itself into plugins that can […]

Read more →
Previous Page 3 of 6 Next