News
Privilege Escalation Vulnerability Patched Promptly in WP Data Access WordPress Plugin
On April 5, 2023 the Wordfence Threat Intelligence team initiated the responsible disclosure process for a vulnerability we discovered in WP Data Access, a WordPress plugin that is installed on over 10,000 sites. This flaw makes it possible for an authenticated attacker to grant themselves administrative privileges via a profile update, if the targeted site […]
Read MoreLimit Login Attempts Vulnerability – Patch Now!
On April 11th, 2023, a software update was released to patch a severe vulnerability within the Limit Login Attempts WordPress security plugin. With over 600,000 installations, it’s among the most popular WordPress plugins in use to help prevent unauthorized access to administrator dashboards. In an ironic twist, this vulnerability may allow attackers to do just […]
Read MoreIs Your Site Acting Strange? 29 Signs A Website Is Hacked
Is your website misbehaving or has it been hacked? It can be difficult to determine the difference between the two. Malware infections are designed to remain hidden for as long as possible, leaving website owners confused about the state of their site. Some malware is even configured to only appear to users coming in from […]
Read MoreUpdate Now! Severe Vulnerability Impacting 600,000 Sites Patched in Limit Login Attempts
On January 26, 2023, the Wordfence team responsibly disclosed an unauthenticated stored Cross-Site Scripting vulnerability in Limit Login Attempts, a WordPress plugin installed on over 600,000 sites that provides site owners with the ability to block IP addresses that have made repeated failed login attempts. The plugin is vulnerable in versions up to, and including, […]
Read MoreWordfence 503: How to Fix Wordfence Blocking You
You’ve been able to log in to this site just fine before, and you probably do it every day. But now, for some random reason, you’re blocked from logging in today. You’re seeing the 503 screen so you know the culprit is Wordfence. We’ll tell you how to log back in and get on with […]
Read MoreFriday Long Read: What To Do About AI
This is a Friday long-read, so grab a warm cup of something and kick back because we’re going to take our time on this. The world is about to profoundly change. I know you’re nervous – perhaps excited and optimistic, but if you’ve been paying attention and have been watching the trajectory of this thing, […]
Read MoreBalada Injector: Synopsis of a Massive Ongoing WordPress Malware Campaign
Our team at Sucuri has been tracking a massive WordPress infection campaign since 2017 — but up until recently never bothered to give it a proper name. Typically, we refer to it as an ongoing long lasting massive WordPress infection campaign that leverages all known and recently discovered theme and plugin vulnerabilities. Other organizations and […]
Read MoreWordfence Intelligence Weekly WordPress Vulnerability Report (Mar 27, 2023 to Apr 2, 2023)
Last week, there were 82 vulnerabilities disclosed in 70 WordPress Plugins and 1 WordPress theme that have been added to the Wordfence Intelligence Vulnerability Database, and there were 34 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with […]
Read MoreHacked Website Threat Report – 2022
Education is crucial in defending your website against emerging threats. That’s why we are thrilled to share our 2022 Website Threat Research Report. Disseminating this information to the community helps educate website owners about the latest trends and threats. This year, we’ve included new insights to highlight the most prevalent tactics and techniques observed in […]
Read More