Showing posts with label WordPress. Show all posts
Showing posts with label WordPress. Show all posts

Thursday, March 17, 2022

WordPress 5.9.2 Released

There has been released a new version of WordPress (blogging tool and content management system) which contains also patches to three security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.9.2

More information can be read from the WordPress blog.

Monday, January 10, 2022

WordPress 5.8.3 Released

There has been released a new version of WordPress (blogging tool and content management system) which contains also patches to four security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.8.3

More information can be read from the WordPress blog.

Saturday, November 13, 2021

New WordPress Version Released

There has been released a new version of WordPress (blogging tool and content management system) which contains also patches to three security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.8.2

More information can be read from the WordPress blog.

Monday, September 13, 2021

New WordPress Version Released

There has been released a new version of WordPress (blogging tool and content management system) which contains also patches to three security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.8.1

More information can be read from the WordPress blog.

Friday, April 16, 2021

New WordPress Version Released

There has been released a new version of WordPress (blogging tool and content management system) which contains also patches to two security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.7.1

More information can be read from the WordPress blog.

Monday, November 2, 2020

New WordPress Version Released

There has been released a new version of WordPress (blogging tool and content management system) which contains also patches to ten security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.5.2

More information can be read from the WordPress blog.

Wednesday, August 12, 2020

Vulnerability In Newsletter Plugin Fixed

There has been released an update to Newsletter, a WordPress plugin. This plugin is used in over 300000 installations. Fix includes patch to security vulnerabilities.

Affected versions:
Newsletter WordPress plugin versions earlier than 6.8.2

More information in Wordfence blog

Vulnerability in Divi, Extra and Divi Builder Fixed

There have been released updates to two themes by Elegant Themes, Divi and Extra and also to Divi Builder which is a WordPress plugin. Together these products are used on aproximately 700000 sites. The vulnerability gives authenticated attackers, with contributor-level or above capabilities, the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable site’s server.

Affected versions:
Divi versions between 3.0 and 4.5.2
Extra versions between 2.0 and 4.5.2
Divi Builder versions between 2.0 and 4.5.2

More information in Wordfence blog.

Sunday, August 2, 2020

wpDiscuz Vulnerability Fixed

There has been released an update to wpDiscuz which is a WordPress plugin with over 80000 installations. The updated version fixes a critical categorized security vulnerability. The vulnerability gives unauthenticated attackers the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable site’s server.

Affected versions:
wpDiscuz versions between 7.0.0 and 7.0.4

More information in Wordfence blog here.

Wednesday, July 22, 2020

All In One SEO Pack Vulnerability Fixed

There has been released an update to All In One SEO Pack which is a WordPress plugin with over 2 million installations. The updated version fixes a medium categorized security vulnerability.

Affected versions:
All In One SEO Pack versions earlier than 3.6.2

More information in Wordfence blog here.

Tuesday, June 16, 2020

WordPress 5.4.2 Released

There has been released a new version of WordPress (blogging tool and content management system). Version 5.4.2 fixes security bugs.

Affected versions:
WordPress versions earlier than 5.4.2

More information can be read from the WordPress blog.

Saturday, May 2, 2020

Ninja Forms Vulnerability Fixed

There has been released an update to Ninja Forms which is a WordPress plugin with over 1 million installations. The updated version fixes a Cross-Site Request Forgery (CSRF) vulnerability (CVE-2020-12462).

Affected versions:
Ninja Forms versions earlier than 3.4.24.2

More information in Wordfence blog here.

WordPress 5.4.1 Released

There has been released a new version of WordPress (blogging tool and content management system). Version 5.4.1 fixes security bugs.

Affected versions:
WordPress versions earlier than 5.4.1

More information can be read from the WordPress blog.

Saturday, December 21, 2019

WordPress 5.3.2 Released

There has been released a new version of WordPress (blogging tool and content management system). Version 5.3.2 fixes a few high severity bugs that were found after the version 5.3.1 release (it contained also fixes to security vulnerabilities).

Affected versions:
WordPress versions earlier than 5.3.2

More information can be read from the WordPress blog.

Thursday, October 17, 2019

New WordPress Version Released

There has been released a new version of WordPress (blogging tool and content management system) which contains patches to security vulnerabilities too. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.2.4

More information can be read from the WordPress blog.

Tuesday, September 10, 2019

New WordPress Version Released

There has been released a new version of WordPress (blogging tool and content management system) which contains patches to security vulnerabilities too. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.2.3

More information can be read from the WordPress blog.

Thursday, March 14, 2019

New WordPress Version Released

There has been released a new version of WordPress (blogging tool and content management system) which contains also patches to two security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 5.1.1

More information can be read from the WordPress blog.

Monday, September 10, 2018

Vulnerability In WordPress

There has been found an unpatched vulnerability (CVE-2018-1000773) in WordPress. The vulnerability is due to insufficient sanitization of user-supplied input submitted to the affected software. The vulnerability may allow an attacker to execute arbitrary code in target system. To exploit the vulnerability the attacker must have user-level access to the target system.

Affected versions:
WordPress 4.9.8 and earlier versions


Cisco's multivendor vulnerability alert can be read here.

Friday, July 6, 2018

WordPress 4.9.7 Released

There has been released a new version of WordPress (blogging tool and content management system) which contains updates to security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 4.9.7

More information can be read from the WordPress blog.

Friday, April 6, 2018

WordPress 4.9.5 Released

There has been released a new version of WordPress (blogging tool and content management system) which contains updates to security vulnerabilities. It's also recommended to check if there are any updates available for WordPress extensions in use. Also, it's recommended to disable those extensions that are not needed.

Affected versions:
WordPress versions earlier than 4.9.5

More information can be read from the WordPress blog.