Updates on WordPress security, Wordfence and what we're cooking in the lab today.

Wordfence Blog

Podcast Episode 7: The Tyler Lau Interview, Assange, Thought Experiments, AirBnB Scams and More

This entry was posted in Podcasts on April 17, 2019 by Mark Maunder   3 Replies

 This week we look at the Assange arrest, an irresponsible security researcher affecting the WordPress community and do a bit of a thought experiment. We also look at Google’s Sensorvault and how it’s being used by law enforcement, the fascinating rise and fall of the Bayrob malware gang, and some tips for avoiding a …
Read More

Zero-Day Vulnerability in Yellow Pencil Visual Theme Customizer Exploited in the Wild

This entry was posted in Vulnerabilities, WordPress Security on April 11, 2019 by James   5 Replies

On Monday the WordPress plugin Yellow Pencil Visual Theme Customizer was closed in the WordPress.org plugin repository. The plugin is quite popular, with an active install base of over 30,000 websites. On Tuesday a security researcher made the irresponsible and dangerous decision to publish a blog post including a proof of concept (POC) detailing how …
Read More

Yuzo Related Posts Zero-Day Vulnerability Exploited in the Wild

This entry was posted in Vulnerabilities, WordPress Security on April 10, 2019 by Dan Moen   27 Replies

The Yuzo Related Posts plugin, which is installed on over 60,000 websites, was removed from the WordPress.org plugin directory on March 30, 2019 after an unpatched vulnerability was publicly, and irresponsibly, disclosed by a security researcher that same day. The vulnerability, which allows stored cross-site scripting (XSS), is now being exploited in the wild. These …
Read More

Podcast Episode 6: The Brandy Lawson Interview, The News and Facebook Rants

This entry was posted in Podcasts on April 10, 2019 by Mark Maunder   2 Replies

 This week we follow up on two stories from last week, the Pipdig P3 plugin and Jetpack suggestions found within the WordPress plugin dashboard. We also take a look at quite a few privacy concerns with Grammarly, malware in the healthcare industry, and we discuss privacy concerns with Facebook. I also talk to Brandy …
Read More

Podcast Episode 5: The Raquel Landefeld Interview & The Pipdig Story

This entry was posted in Podcasts on April 02, 2019 by Mark Maunder   2 Replies

This week I chat about the Pipdig controversy in full with Mikey Veenstra and Kathy Zant. Kathy and I cover the news. And we have an amazing interview with Raquel Landefeld who is a community organizer for WordPress, co-founder of agency Mode Effect and a well known and loved personality in the WordPress community. Raquel …
Read More

Pipdig Update: Dishonest Denials, Erased Evidence, and Ongoing Offenses

This entry was posted in Research, Vulnerabilities on April 02, 2019 by Mikey Veenstra   25 Replies

In last week’s post, we reported on some concerning code identified in the Pipdig Power Pack (P3) plugin. The plugin, which is installed alongside WordPress themes sold by Pipdig, was found to contain a number of suspicious or malicious features. Among these features were a remote “killswitch” Pipdig could use to destroy sites, an obfuscated …
Read More

Peculiar PHP Present In Popular Pipdig Power Pack (P3) Plugin

This entry was posted in Research, WordPress Security on March 29, 2019 by Mikey Veenstra   36 Replies

This week, our team was notified of suspicious code present in a plugin offered alongside themes sold by Pipdig, a UK-based web development team. The user, who wishes to remain anonymous, reached out to us with concerns that the plugin’s developer can grant themselves administrative access to sites using the plugin, or even delete affected …
Read More

Podcast Episode 4: The Aaron Campbell Interview and the Social Warfare Saga

This entry was posted in Podcasts on March 26, 2019 by Mark Maunder   1 Reply

This week we have an update on the Social Warfare plugin vulnerability, how it was more serious than originally thought, and a feud that has broken out between a security researcher and forum moderators. We also have some interesting data on how WordPress will become more secure soon with code signing. And along with several …
Read More

Recent Social Warfare Vulnerability Allowed Remote Code Execution

This entry was posted in Vulnerabilities, WordPress Security on March 25, 2019 by Mikey Veenstra   3 Replies

In posts last week, we detailed a vulnerability in the Social Warfare plugin, and discussed the attack campaigns against it. These issues were reported widely as Cross Site Scripting (XSS) flaws, due to an unexpected disclosure and proof of concept released by an unnamed researcher. Our Threat Intelligence team quickly released a firewall rule to mitigate impact …
Read More

Social Warfare Plugin Zero-Day: Details and Attack Data

This entry was posted in Vulnerabilities, WordPress Security on March 21, 2019 by Mikey Veenstra   6 Replies

In our earlier post, we issued a warning to users of the Social Warfare plugin regarding a zero-day vulnerability affecting their sites. At this time, the plugin’s developers have issued a patch for the flaw. All users are urged to update to version 3.5.3 immediately. Vulnerability Details The plugin features functionality that allows users to …
Read More

Follow Us


Protect your websites with the #1 WordPress Security Plugin

Get Premium
Over 100 million downloads

Wordfence Newsletter

Get WordPress Security Alerts and Product Updates