Skip to main content Skip to footer
HomeAboutContact
WPDaily.NewsWPDaily.News
On SaleTag Cloud
Wordpress Org Banner

All Plugin Releases Being Reviewed

David Perex @ make.wordpress.org • 4 days ago

An update on automatic security reviews for plugins on the WP plugin directory.

  • Announcement
  • Security
WordPress vulternatbility reports climb

WordPress Core Inundated with Vulnerability Reports

Rae Morey @ therepository.email  • 2 weeks ago

The WordPress security team received 773 reports of security vulnerabilities in August, up from around 20-30 a month last year. The team starts to put some new limitations on what they will accepts via the HackerOne disclosure program.

  • Security
  • WordPress Core
sql injection aio wp migration

SQL Injection Vulnerability in All in One WP Migration and Backup Plugin

Istvan Marton @ wordfence.com • 2 weeks ago

If I was reading this correctly, the payload is planted using a ping-back. I wonder how many of these types of holes there are?

  • Security
  • All in One WP Migration
another pods security release

Another Pods Security Release

Scott Kingsley Clark @ pods.io • 2 weeks ago

It looks like more vulnerabilities were found after the team patched Pods earlier in the mont

  • Security
  • Pods
bot traffic on kernel org

AI Bot Scrapers Gone Amuck

Konstantin Ryabitsev @ people.kernel.org • 2 weeks ago

Konstantin Ryabitsev from the Linux Kernel team reports on their fight with AI bots. The current situation doesn’t seem sustainable.

  • Security
  • AI
rank math security issue

Rank Math Giving Itself Admin Access

Roger Montti @ searchenginejournal.com • 2 weeks ago

Surprisingly there is nothing on the plugin page on WP org about Rank Math creating unauthorized admin access. I would expect that Rank Math would be suspended, at least until fixed, if not for longer. Roger Montti’s report helps to get the word out about this bad behavior.

  • Security
  • Rank Math
breakdance secuirty release

Security Releases: Oxygen 6.1.2 and Breakdance 2.8.2

Elijah Mills @ breakdance.combreak • 2 weeks ago

These are both security releases to patch access control issues in the Design Library endpoints which were reachable without authentication.

  • Security
  • Breakdance
  • Oxygen
fluentforms strengthens security posture

Fluent Forms Upgrades Its Security Posture

Shahjahan Jewel @ fluentforms.com • 3 weeks ago

The WPManage team is now digitally signing their plugins to close loops in possible supply chain attacks. They have also had an independent security audit by Patchstack for FluentForms. I appreciate seeing developers being proactive about security.

  • Security
  • Fluent Forms
  • WPManageNinja
elementor pro vulnerability

Elementor Pro Security Vulnerability Update

Oliver Sild @ patchstack.com • 4 weeks ago

If you haven’t updated your Elementor Pro site to version 4.2.2 or greater then best to do so now. The vulnerability allows for a remote code execution, but requires Elementor Pro (not free) and a form widget with a file upload field. Details in the report.

  • Security
  • Elementor

Copyright © 2024 WebTNG | Privacy Policy

The WordPress® trademark is the intellectual property of the WordPress Foundation, and the Woo® and WooCommerce® trademarks are the intellectual property of WooCommerce, Inc. Uses of the WordPress®, Woo®, and WooCommerce® names in this website are for identification purposes only and do not imply an endorsement by WordPress Foundation or WooCommerce, Inc. WPDaily.New is not endorsed or owned by, or affiliated with, the WordPress Foundation or WooCommerce, Inc.