Watch out — hackers can exploit this plugin to gain full control of your WordPress site

An older version of LiteSpeed Cache, a popular plugin for the WordPress website builder, is vulnerable to a high-severity flaw that hackers have been increasingly exploiting. The flaw is described as an unauthenticated cross-site scripting vulnerability, and tracked as CVE-2023-40000. It carries a severity score of 8.8.  By adding malicious JavaScript code directly into WordPress … Read more

Hackers attempt to hijack a major WordPress plugin that could allow for site takeovers

A critical vulnerability recently discovered in a popular WordPress plugin, is being actively abused in the wild, researchers have said, with hackers potentially able to use the flaw to fully take over a victim’s website. WordPress security firm Patchstack first discovered an SQL injection (SQLi) vulnerability in the WP‑Automatic plugin, in mid-March 2024.  WP-Automatic is … Read more

A critical security flaw could affect thousands of WordPress sites

Hundreds of thousands of WordPress websites are vulnerable to a critical severity flaw which allows threat actors to upload malware to the site through a bug in a plugin.  As reported by BleepingComputer, Japan’s CERT recently found a critical severity flaw (9.8) in the Forminator plugin, built by WPMU DEV. The flaw, now tracked as … Read more

Beeper App That Created Workaround for iMessage on Android Acquired by WordPress Owner Automattic

Automattic, the company behind popular web management system WordPress, has purchased Beeper and will absorb Beeper’s 27 employees. Beeper made headlines back in December for Beeper Mini, an app that brought iMessage to Android devices. Beeper Mini used reverse engineered iMessage protocols and encryption, taking advantage of Apple’s own iMessage servers to let Android users … Read more

Another top WordPress plugin has a serious security flaw — patch now to keep your website safe

Another major WordPress plugin was found vulnerable to a high-severity flaw which allowed malicious actors to steal sensitive information from the website, including password hashes. LayerSlider has published a new security advisory, saying the product is now in version 7.10.1, but adding, “This update includes important security fixes.” While the announcement does not detail the … Read more

Deals: WP Buzz Managed WordPress Hosting: 3-Yr Subscription

Have you ever wished for a hosting platform that’s specifically designed for WordPress, one that offers enhanced speed, performance, and security? Well, your wish has just come true. Introducing the WP Buzz Premium Managed WordPress hosting platform. This platform is not just another hosting service, it’s a game-changer. WP Buzz is a platform that’s been … Read more