Updates on WordPress security, Wordfence and what we're cooking in the lab today.

Wordfence Blog

Vulnerabilities Patched in WP Cost Estimation Plugin

This entry was posted in Research, Vulnerabilities, WordPress Security on February 13, 2019 by Mikey Veenstra   2 Replies

At the end of January, Wordfence security analysts identified attackers exploiting vulnerabilities in outdated versions of the commercial plugin WP Cost Estimation & Payment Forms Builder, or WP Cost Estimation for short. These flaws were found and patched by the developer a few months ago, but no official public disclosure was made at the time. Following …
Read More

Live Event: Wordfence Central Official Launch and Demo

This entry was posted in Ask Wordfence, Learning, Wordfence on February 06, 2019 by Mark Maunder   5 Replies

Today we are very excited to announce the launch of Wordfence Central. Our team has been working hard for almost a year on this ground-breaking project. Wordfence Central gives you the power of a security events and information manager for WordPress. Join me for a live event starting at 8am Pacific time, 11am EST where …
Read More

Introducing Wordfence Central

This entry was posted in Wordfence on February 06, 2019 by Dan Moen   19 Replies

Over the last several months, we have been focused on making Wordfence a better option for organizations with a large number of WordPress sites to protect. To start, we added the ability to secure your staging and development environments with a single Wordfence premium license, something you should take advantage of if you haven’t already. …
Read More

WordPress Sites Compromised via Zero-Day Vulnerabilities in Total Donations Plugin

This entry was posted in Research, Vulnerabilities, WordPress Security on January 25, 2019 by Mikey Veenstra   6 Replies

The Wordfence Threat Intelligence team recently identified multiple critical vulnerabilities in the commercial Total Donations plugin for WordPress. These vulnerabilities, present in all known versions of the plugin up to and including 2.0.5, are being exploited by malicious actors to gain administrative access to affected WordPress sites. We have reserved CVE-2019-6703 to track and reference these vulnerabilities …
Read More

Analyzing a Week of Blocked Attacks

This entry was posted in Wordfence, WordPress Security on January 22, 2019 by Dan Moen   13 Replies

If you’ve never taken a few minutes to look at the information available in the Wordfence Live Traffic feature, I strongly recommend it. It gives you a detailed look at what attackers are trying to do to break into your site, and how Wordfence is blocking them. For today’s post we analyzed all of the …
Read More

A Tale of Two Vulnerabilities: Using Commercial Plugins Responsibly

This entry was posted in Vulnerabilities, WordPress Security on January 18, 2019 by Mikey Veenstra   10 Replies

As the most popular CMS on the market, one of the major draws of WordPress is a rich ecosystem of plugins made available by the community. The WordPress.org plugin repository makes the process of installing and updating plugins a seamless experience in the dashboard of a site, and a team of volunteers works to maintain …
Read More

WordPress 5.0.1 Security Release – Immediate Update Recommended

This entry was posted in WordPress Security on December 13, 2018 by Dan Moen   12 Replies

WordPress 5.0.1 was released Wednesday night, less than a week after the much anticipated release of WordPress 5.0. This security release fixes seven security vulnerabilities, a few of which are quite serious. Sites running versions in the 4.x branch of WordPress core are also impacted by some of the issues. WordPress 4.9.9 was released along …
Read More

WordCamp US Recap

This entry was posted in Miscellaneous on December 13, 2018 by Mark Maunder   6 Replies

WordCamp US was held in Nashville, Tennessee this year. We sponsored the event, had a booth and of course provided lock picking lessons, as has become our tradition at WordCamps. Our goal is to get you to think like a hacker, so that you can better secure your sites. Picking a lock really gets you …
Read More

How We Think About WordPress Security and Research

This entry was posted in General Security, Wordfence, WordPress Security on December 10, 2018 by Mark Maunder   3 Replies

This weekend I had a really fun conversation with Doc Pop from Torque Magazine. Torque is a great news source for WordPress news. They are part of WP Engine, but maintain editorial independence. I chatted with Doc in Nashville, in the Music City Center where WordCamp US was being held. Music City Center is an …
Read More

Botnet of Infected WordPress Sites Attacking WordPress Sites

This entry was posted in Research, Wordfence, WordPress Security on December 05, 2018 by Mikey Veenstra   17 Replies

The Defiant Threat Intelligence team recently began tracking the behavior of an organized brute force attack campaign against WordPress sites. This campaign has created a botnet of infected WordPress websites to perform its attacks, which attempt XML-RPC authentication to other WordPress sites in order to access privileged accounts. Between Wordfence’s brute force protection and the premium real-time …
Read More


Protect your websites with the #1 WordPress Security Plugin

Get Premium
Over 100 million downloads

Wordfence Newsletter

Get WordPress Security Alerts and Product Updates