WooThemes Security Patch – Critical Update

woo-themes

WooThemes released a security patch today for their theme framework. The vulnerability is related to a preview function and allows visitors to run and to see the output of any shortcodes used by your theme. Unfortunately, the vulnerability is now widely known (having been published on the Internet before the theme developers were notified), which [...]

Warning: TimThumb.php Vulnerability in WordPress Themes and Plugins

TimThumb.php vulnerability in WordPress themes and plugins

TimThumb.php found with zero-day vulnerability! Update Now. TimThumb is PHP script for image cropping, zooming and resizing. This script is commonly included in many WordPress themes and plugins. Unfortunately, without removing or updating the timthumb.php script, your site is at risk of being hacked. Sites have been maliciously hacked with eval(base64_decode(‘..long string of malicious encrypted [...]

Google Analytics for WordPress Plugin Vulnerability Fixed

google-analytics-for-wordpress-plugin-vulnerability

The Google Analytics for WordPress plugin was found with a XSS scripting vulnerability, if the track outbounds clicks option was selected. This issue was found by David Whitehouse and James Slater of DavidNaylor.co.uk  and notified the develop right away. The developer, Joost de Valk took immediate action and got this security issue fixed. On July 20, 2011, this plugin was updated [...]

WP-phpMyAdmin Plugin Hacked — Backdoor Vulnerability

WP-phpMyAdmin Plugin Vulnerable

WordPress Security Alert: Hacked WP-phpMyAdmin plugin — found vulnerable backdoor. Remove it! Over the past few weeks, I have been cleaning several hacked WordPress sites for clients and found a commonality, the WP-phpMyAdmin plugin. This caught my eye because I don’t see this plugin being used very often. I began to wonder, is the WP-phpMyAdmin [...]

Warning: Backdoor in AddThis, WPtouch and W3 Total Cache plugins

Backdoor in AddThis, WPtouch and W3 Total Cache plugins

On June 21, 2011, Matt Mullenweg reported on WordPress.org that the popular WordPress plugins, AddThis, WPtouch and W3 Total Cache were found with cleverly disguised backdoors. These security vulnerabilities were discovered inside the WordPress.org repository and it is at no fault of the plugin developers (authors) themselves. However, it is unclear how the cyber attackers [...]

Report WordPress Bugs and Vulnerabilities

WordPress 3.3 Released

The developers of WordPress.org work proactively to provide you with safe open-source publishing software. As critical bugs and vulnerabilities are reported, the WordPress developers work diligently to fix them and release maintenance versions. They do take WordPress security seriously. For example… On December 18, 2009, WordPress version 2.9 “Carmen” was released. Fix #1 — WordPress [...]