Updates on CyberSecurity, WordPress and what we're cooking in the lab today.

Category Archive: WordPress Security

Ask Wordfence: How to Limit Security Risks From Plugins

This entry was posted in Ask Wordfence, WordPress Security on November 8, 2017 by Dan Moen   11 Replies

This is the fourth installment in a new series we started last month. You can access previous posts here....read more

The October 2017 WordPress Attack Report

This entry was posted in Monthly Attack Activity Report, WordPress Security on November 6, 2017 by Dan Moen   3 Replies

This month's WordPress Attack Report is a continuation of a series we have been publishing since December 2016. Reports from the previous months can be found here....read more

Cryptocurrency Miners Exploiting WordPress Sites

This entry was posted in Research, WordPress Security on October 26, 2017 by Brad Haas   11 Replies

During the last month, the information security media has paid a lot of attention to cryptocurrency mining malware. The Wordfence team has been monitoring the situation, and we are now starting to see attacks attempting to upload mining malware, and site cleaning customers that are already infected....read more

Ask Wordfence Episode 3: Should You Hide Your WordPress Login Page?

This entry was posted in Ask Wordfence, WordPress Security on October 25, 2017 by Mark Maunder   131 Replies

In today's episode of Ask Wordfence, I answer a common question we receive from customers: Should I hide my WordPress login page?...read more

Zero Day Vulnerability Fixed in Ultimate Form Builder Lite

This entry was posted in Vulnerabilities, WordPress Security on October 23, 2017 by Brad Haas   2 Replies

Last month, we identified three plugins with critical object injection vulnerabilities, all being exploited in the wild. We deployed new and improved firewall rules to block that kind of exploit....read more

New Attacker Scanning for SSH Private Keys on Websites

This entry was posted in General Security, WordPress Security on October 18, 2017 by Mark Maunder   21 Replies

Wordfence is seeing a significant spike in SSH private key scanning activity. We are releasing this advisory to ensure that our customers and the broader WordPress community are aware of this new activity and of the risk of making private SSH keys public, and to explain how to avoid this problem....read more

12.8% of Sites Have Sensitive File Disclosure Vulnerabilities

This entry was posted in Vulnerabilities, WordPress Security on October 12, 2017 by Dan Moen   5 Replies

As you probably know we launched Gravityscan this May. Gravityscan is a security scanner for any website that serves as a great complement to Wordfence. Yesterday we were analyzing aggregate scan result data from Gravityscan, and we noticed data that surprised us: 12.8% of sites we scan have at least one sensitive file visible to anyone on the internet....read more

Postman SMTP Plugin With Unpatched Vulnerability Removed From Directory

This entry was posted in Vulnerabilities, Wordfence, WordPress Security on October 6, 2017 by Dan Moen   24 Replies

We have received a number of questions regarding the Postman SMTP plugin which was removed from the WordPress.org directory this week. According to an archived snapshot, the plugin is installed on over 100,000 websites. We assume it was removed because it contains a publicly known reflected cross-site scripting (XSS) vulnerability that has not been fixed. Both Wordfence Free and Premium users who have the firewall enabled have been protected against attempts to exploit this vulnerability from day one. In addition, we alerted all Wordfence users who have the plugin installed when it was removed from the plugin directory....read more

The September 2017 WordPress Attack Report

This entry was posted in Monthly Attack Activity Report, WordPress Security on October 6, 2017 by Dan Moen   5 Replies

This edition of the WordPress Attack Report is a continuation of the monthly series we've been publishing since December 2016. Reports from the previous months can be found here....read more

Ask Wordfence Episode 1: Setting Up Minimum Viable WordPress Security

This entry was posted in Ask Wordfence, Videos, WordPress Security on October 3, 2017 by Mark Maunder   28 Replies

Last week we emailed a small group of our customers asking them to contribute questions for a series of videos we will be running. We received questions from many of you, so thank you very much for participating!...read more

Get the latest WordPress security updates and news

Sign up for WordPress security alerts, Wordfence product updates and security news via email.