On June 16, 2022, the Wordfence Threat Intelligence team noticed a back-ported security update in Ninja Forms, a WordPress plugin with over one million active installations. We uncovered a code injection vulnerability that made it possible for unauthenticated attackers to call a limited number of methods in various Ninja Forms classes, including a method that unserialized user-supplied content, resulting in Object Injection. This could allow […]
The WordPress plugin UpdraftPlus is vulnerable. If exploited, the vulnerability could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords). Details: https://jetpack.com/2022/02/17/severe-vulnerability-fixed-in-updraftplus-1-22-3/#more-141314 https://www.heise.de/news/WordPress-Plug-in-UpdraftPlus-koennte-Website-Backups-leaken-6510427.html?wt_mc=nl.red.security.security-nl.2022-02-24.link.link
As a reminder if you are having trouble sending or receiving emails. TLS versions 1.0 and 1.1 are no longer supported for email clients and webbrowsers. This can lead to problems receiving and sending emails, if you are still using an email client with an older operating system. To fix these problems, you need to update your operating system and email client software to the […]
WordPress Security The latest WordPress security news, tips and updates: https://ithemes.com/blog/category/wordpress-security/
All shared hosting packages: PHPmyadmin and webmail (Roundcube) were updated to the latest version today.
WordPress Plugin – Critical Vulnerability in Essential Addons for Elementor Plugin Details: https://www.heise.de/news/WordPress-Plug-in-Essential-Addons-for-Elementor-als-Schadcode-Schleuder-6344583.html?wt_mc=nl.red.security.security-nl.2022-02-03.link.link https://patchstack.com/articles/critical-vulnerability-fixed-in-essential-addons-for-elementor-plugin/
Dual stack connections via IPv4 and IPv6 are now available for all new orders (shared hosting). For existing hostings, the host systems Host1 and Host4 have already been equipped with IPv6 & IPv4, support for Host2 and Host3 is coming soon.
Backdoor Found in Themes and Plugins from AccessPress Themes Due to the way the extensions were compromised, we suspected an external attacker had breached the website of AccessPress Themes in an attempt to use their extensions to infect further sites. Details: https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ Please update or remove (un-install completely) the extensions mentioned in the details from the link above. If there are no updates for this […]
In order to avoid blacklisting of our mail servers due to unprotected contact forms & other forms, the forms must be secured with Captcha, e.g. (re-captcha v2) this is required to use PHP mail. If your application does not support PHP mail at the moment, please let us know when a captcha protection has been integrated and therefore the PHP mail function should be activated. […]
4 security issues affect WordPress versions between 3.7 and 5.8. If you haven’t yet updated to 5.8, all WordPress versions since 3.7 have also been updated to fix the security issues. details english: https://wordpress.org/support/wordpress-version/version-5-8-3/ Sicherheitsupdate: Angreifer könnten sich auf WordPress-Websites einnisten. In der aktuellen Version des Content Management System WordPress haben die Entwickler vier Sicherheitslücken geschlossen. details german: https://www.heise.de/news/Sicherheitsupdate-Angreifer-koennten-sich-auf-WordPress-Websites-einnisten-6320363.html?wt_mc=nl.red.security.security-nl.2022-01-10.link.link