je.st
news
Tag: wordpress
Hackers exploit critical vulnerability in popular WordPress theme component
2014-09-04 21:15:46| InfoWorld: Top News
Attackers are actively exploiting a critical vulnerability in a WordPress plug-in that's used by a large number of themes, researchers from two security companies warned Wednesday. The vulnerability affects versions 4.1.4 and older of Slider Revolution, a commercial WordPress plug-in for creating mobile-friendly content display sliders. The flaw was fixed in Slider Revolution 4.2 released in February, but some themes -- collections of files or templates that determine the overall look of a site -- still bundle insecure versions of the plug-in.
Tags: popular
theme
critical
component
Thousands of sites compromised through WordPress plug-in vulnerability
2014-07-24 20:22:27| InfoWorld: Top News
A critical vulnerability found recently in a popular newsletter plug-in for WordPress is actively being targeted by hackers and was used to compromise an estimated 50,000 sites so far.
Tags: sites
thousands
wordpress
plugin
WordPress 4.0: The app becomes a platform
2014-07-11 19:21:23| InfoWorld: Top News
Credit: WordPress
Critical vulnerability in WordPress newsletter plug-in endangers many blogs
2014-07-02 16:10:30| InfoWorld: Top News
A critical vulnerability found in a WordPress plug-in that has been downloaded over 1.7 million times allows potential attackers to take complete control of blogs that use it. The flaw is located in the MailPoet Newsletters plug-in, previously known as wysija-newsletters, and was discovered by researchers from Web security firm Sucuri.
Tags: newsletter
blogs
critical
wordpress
Flaws in popular SEO plug-in put WordPress websites at risk
2014-06-02 15:50:47| InfoWorld: Top News
Many WordPress websites could be at risk of compromise if their administrators don't upgrade a popular search engine optimization (SEO) plug-in to a newly released version that fixes serious vulnerabilities. Researchers from Web security firm Sucuri found two flaws in a plug-in called "All in One SEO Pack" that potentially allow attackers with access to non-administrative WordPress accounts to elevate their privileges and inject malicious code into the administration panel.
Tags: popular
put
risk
websites