PSA: Zero-Day Vulnerability in WPGateway Actively Exploited in the Wild! On September 8, 2022, the Wordfence Threat Intelligence team became aware of an actively exploited zero-day vulnerability being used to add a malicious administrator user to sites running the WPGateway plugin. Details https://www.wordfence.com/blog/2022/09/psa-zero-day-vulnerability-in-wpgateway-actively-exploited-in-the-wild/
WordPress 6.0.2 Security and Maintenance Release This security and maintenance release features 12 bug fixes on Core, 5 bug fixes for the Block Editor, and 3 security fixes. Because this is a security release, it is recommended that you update your sites immediately. https://www.heise.de/news/Sicherheitsupdate-Angreifer-koennten-WordPress-Websites-attackieren-7249431.html?wt_mc=nl.red.security.security-nl.2022-09-01.link.link
A NEWLY FOUND EXPLOIT COULD ALLOW REMOTE ATTACKERS TO TAKE CONTROL OF YOUR SHOP. Attackers have found a way to use a security vulnerability to carry out arbitrary code execution in servers running PrestaShop websites. For details, please read the entire article. Details: https://build.prestashop.com/news/major-security-vulnerability-on-prestashop-websites/ Please Update now!
On June 16, 2022, the Wordfence Threat Intelligence team noticed a back-ported security update in Ninja Forms, a WordPress plugin with over one million active installations. We uncovered a code injection vulnerability that made it possible for unauthenticated attackers to call a limited number of methods in various Ninja Forms classes, including a method that unserialized user-supplied content, resulting in Object Injection. This could allow […]
The WordPress plugin UpdraftPlus is vulnerable. If exploited, the vulnerability could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords). Details: https://jetpack.com/2022/02/17/severe-vulnerability-fixed-in-updraftplus-1-22-3/#more-141314 https://www.heise.de/news/WordPress-Plug-in-UpdraftPlus-koennte-Website-Backups-leaken-6510427.html?wt_mc=nl.red.security.security-nl.2022-02-24.link.link
As a reminder if you are having trouble sending or receiving emails. TLS versions 1.0 and 1.1 are no longer supported for email clients and webbrowsers. This can lead to problems receiving and sending emails, if you are still using an email client with an older operating system. To fix these problems, you need to update your operating system and email client software to the […]
WordPress Security The latest WordPress security news, tips and updates: https://ithemes.com/blog/category/wordpress-security/
All shared hosting packages: PHPmyadmin and webmail (Roundcube) were updated to the latest version today.
WordPress Plugin – Critical Vulnerability in Essential Addons for Elementor Plugin Details: https://www.heise.de/news/WordPress-Plug-in-Essential-Addons-for-Elementor-als-Schadcode-Schleuder-6344583.html?wt_mc=nl.red.security.security-nl.2022-02-03.link.link https://patchstack.com/articles/critical-vulnerability-fixed-in-essential-addons-for-elementor-plugin/
Dual stack connections via IPv4 and IPv6 are now available for all new orders (shared hosting). For existing hostings, the host systems Host1 and Host4 have already been equipped with IPv6 & IPv4, support for Host2 and Host3 is coming soon.