WordPress

29 Articles
Critical security flaw could leave over 100,000 WordPress sites at risk
Tech

Critical security flaw could leave over 100,000 WordPress sites at risk

A flaw in TI WooCommerce Wishlist allows threat actors to upload arbitrary files Since the files can be malicious, they could fully take...

Vulnerability that allows full admin takeover found in premium WordPress theme
Tech

Vulnerability that allows full admin takeover found in premium WordPress theme

‘Motors’ allowed threat actors to take over admin accounts This enabled full website takeover The developers released a fix Motors, a premium theme...

WordPress fatigue drives businesses toward simpler, easier-to-manage CMS alternatives
Tech

WordPress fatigue drives businesses toward simpler, easier-to-manage CMS alternatives

Most former WordPress users don’t regret switching to other CMS platforms Switchers report fewer plugin issues and no major increase in cost Migration...

WordPress fatigue drives businesses toward simpler, easier-to-manage CMS alternatives
Tech

WordPress fatigue drives businesses toward simpler, easier-to-manage CMS alternatives

Most former WordPress users don’t regret switching to other CMS platforms Switchers report fewer plugin issues and no major increase in cost Migration...

OttoKit WordPress plugin has a serious security flaw, thousands of users possibly affected
Tech

OttoKit WordPress plugin has a serious security flaw, thousands of users possibly affected

The OttoKit plugin was vulnerable to a critical flaw that allows the creation of new admin accounts It was patched in late April...

WordPress sites targeted by malicious plugin disguised as security tool
Tech

WordPress sites targeted by malicious plugin disguised as security tool

Wordfence researchers uncover a new piece of WordPress malware Threat actors used AI to create legitimate-looking tools The malware pretends to be an...

A huge online fraud operation is hijacking WordPress sites to send out 1.4 billion ad requests per day
Tech

A huge online fraud operation is hijacking WordPress sites to send out 1.4 billion ad requests per day

Researchers found a huge ad fraud scheme called Scallyway The scheme monetizes pirated sites through a series of redirects At its peak, there...

WordPress plugin auth bypass exploited almost immediately after disclosure
Tech

WordPress plugin auth bypass exploited almost immediately after disclosure

A bug in OttoKit allows threat actors to create new admin accounts The bug can lead to full website takeover More than 100,000...

WordPress owner Automattic announces major layoffs
Tech

WordPress owner Automattic announces major layoffs

WordPress.com, Tumblr and WooCommerce owner Automattic is laying off 16% Automattic wants to become more agile and responsive Long-term financial viability and profitability...