Wordfence Research and News

Blog icon
Category: Learning
Featured Image showcases an explorer in a futuristic jungle with a CRT screen / console with the words Local File Inclusion in red.
Newest

How to Find Local File Inclusion (LFI) Vulnerabilities in WordPress Plugins and Themes

Learn how to find LFI vulnerabilities in WordPress plugins and themes and earn cash bounties through the Wordfence Bug Bounty Program.

WordPress Security Research Series: Setting Up Your Research Lab

Welcome to Part 3 of the WordPress Security Research Beginner Series!
WordPress Security Architecture Featured Image

WordPress Security Research Series: WordPress Security Architecture

Learn how WordPress security works from the inside out. A guide for vulnerability researchers on identifying flaws in WordPress core, plugins, and themes.

Live Event: Wordfence Central Official Launch and Demo

Today we are very excited to announce the launch of Wordfence Central.

Three Incident Response Preparations You Should Be Making

In the context of cybersecurity, the adage “An ounce of prevention is worth a pound of cure” is a massive understatement.

PSA: Lessons From The Atlanta Ransomware Situation

In the past few days the City of Atlanta has been hit with a ransomware attack.

Staying Safe: The Wordfence Cyber Security Survival Guide

Occasionally at Wordfence we publish posts that are public service announcements that help the broader online community including your team, friends and relatives.

Gravatar Advisory: How to Protect Your Email Address and Identity

Update: We’ve added comments at the end of the post pointing out that the National Institute of Standards and Technology (NIST) considers an email address to be personally identifiable information or PII.

Avoid Malware Scanners That Use Insecure Hashing

In this post I’m going to discuss a major problem that exists with several WordPress malware scanners: The use of weak hashing algorithms for good and bad file identification. 

What Hackers Do With Compromised WordPress Sites

We often talk to site owners who are surprised that their sites are targeted by attackers.