WordPress
Recently a new customer came to us needing their website cleaned up after a hack, as part of the cleanup we found an interesting little malicious WordPress plugin, called "WP Security", that was being used to encrypt blog post content. The website owner complained of a newly installed and activated plugin on their website that was rendering their original content unreadable. The hack The plugin...
Read More WordPress 5.2 “Jaco” – Keeping Sites Safer
WordPress 5.1 "Jaco" is now available! Update now to keep your website current, secure, and benefit from the latest feature enhancements. Keeping Your Site Safe WordPress 5.2 gives you even more robust tools for identifying and fixing configuration issues and fatal errors. Whether you are a developer helping clients or you manage your site solo, these tools can help get you the right information...
Read More Update Easy WP SMTP – Vulnerability affecting thousands of sites across the internet discovered
The Easy WP SMTP plugin authors have released a new update, fixing a very critical 0day vulnerability. When leveraged, this vulnerability gives unauthenticated attackers the power to modify any options of an affected site — ultimately leading to a complete site compromise. The vulnerability, found only in version 1.3.9, has been seen exploited in the wild and impacts thousands of sites. The...
Read More WordPress now powers over a third of the top 10 million websites
Our content management system of choice, WordPress, now powers over a third of the top 10 million sites on the web according to W3Techs. WordPress' market share has been growing steadily over the past few years, going from 29.9% just one year ago to 33.4% now. Stats in review In 2005, WordPress were celebrating 50,000 downloads. Six years later, in January 2011, WordPress was powering 13.1% of...
Read More WordPress 5.1.1 Patches Critical Vulnerability
WordPress 5.1.1 was released yesterday evening with an important security update for a critical cross-site scripting vulnerability found in 5.1 and prior versions. The release post credited Simon Scannell of RIPS Technologies for discovering and reporting the vulnerability. Scannell published a post summarizing how an unauthenticated attacker could take over any WordPress site that has comments...
Read More Contact Form 7 switching to reCAPTCHA v3 for invisible spam protection
Google's reCAPTCHA service protects your website against spam and other types of automated abuse. With Contact Form 7’s reCAPTCHA integration module, you can block abusive and junk contact form submissions and login attempts by spam bots that target pretty much any WordPress website on the internet. The latest version of the reCAPTCHA API is v3. Contact Form 7 5.1 and later uses reCAPTCHA...
Read More WordPress 5.1 will replace “blogging” references with “publishing”
WordPress 5.1 will replace the “Happy blogging” language in wp-config-sample.php with “Happy Publishing.” The next major release also cleans up a few other “blog” references by replacing them with the word “site.” A lot of tutorials and documentation will need to be updated. WordPress contributors are continuing to fine-tune the wording in various files to reflect its expanded...
Read More Contact Form 7 abandons Google ReCaptcha V2, adopts Google ReCatpcha V3, causes SPAM chaos
On Thursday, December 13, 2018 there was a new version (5.1) of Contact Form 7, one of the most popular WordPress plugins with over 5 million installations, released. The author/developer, Takayuki Miyoshi, decided to abandon Google ReCaptcha V2 and adopt Google ReCatpcha V3. You can learn about the versions here https://developers.google.com/recaptcha/docs/versions. This implementation forced...
Read More 4 Steps to Take Before Updating to WordPress 5.0
The major change in WordPress 5.0 is the introduction of the Gutenberg editor. Gutenberg is a drag-and-drop interface that dramatically changes how posts and pages are built. You can choose to disable the Gutenberg editor and install the Classic editor plugin, if you want to maintain the same editing experience you’re used to. However, it’s still important to know how the Gutenberg editor...
Read More WordPress 5.0, named “Bebo”, was officially released on December 6
In the biggest news in a long time, WordPress 5.0, named "Bebo", was officially released on December 6. As such, the new Gutenberg block editor is officially part of the WordPress core. Be careful about updating and if possible test your site for compatibility before upgrading your live/production website, also consider using the official Classic Editor plugin if you're not ready to move to the...
Read More