Wordpress News

Drag and Drop Nav Menu Items in WordPress – WordPress Tavern

Earlier this week, Sajjad Hossain Sagor released the first version of his Drag & Drop Menu Items plugin in the WordPress plugin repository. The plugin is a one-off, single-use plugin that does exactly what its name describes — it allows end-users to drag menu items from the meta boxes on the nav menu screen to the menu they are currently editing. Sagor is a freelance web developer from Bangladesh. Drag & Drop Menu Items is the latest of his 18 contributions to the free plugin directory. The plugin is simple in nature and does its one job well. To use it, users merely need to… More Info

Read More »

Malvertising Attackers Target 900,000 WordPress Sites | Avast

Wordfence, the security plugin for WordPress sites, reported in its blog this week that its Threat Intelligence Team observed a single malware campaign target more than 900,000 WordPress sites over the past month, with over half of the attacks occurring on May 3. The researchers clocked over 24,000 distinct IP addresses launching the mammoth attack, which takes advantage of previously known vulnerabilities. While fixes have already been developed for the flaws – some from years ago – the attackers are banking on the notion that many WordPress site owners have still not updated.  More Info

Read More »

Critical WordPress plugin bug lets hackers take over 1M sites

Hackers are actively exploiting two security vulnerabilities in the Elementor Pro and Ultimate Addons for Elementor WordPress plugins with the end goal of remotely executing arbitrary code and fully compromising unpatched targets. Reports of threat actors attempting to abuse the two bugs in ongoing attacks have surfaced on May 6th as reported by Wordfence’s Threat Intelligence team today. Attackers can wipe sites after successful exploitation Elementor Pro is a paid plugin with an estimated number of over 1 million active installations that helps users to easily create WordPress… More Info

Read More »

Google Site Kit WordPress Plugin Vulnerability

A vulnerability was discovered in Google’s Site Kit WordPress plugin and subsequently patched. The vulnerability allows an attacker to escalate site privileges and attack a victims search visibility,  alter site maps and more. Google Site Kit WordPress Plugin The vulnerability affects Site Kit by Google. Google Site Kit is a Google WordPress. Google Site Kit displays information about your site within the WordPress Admin dashboard. It aggregates information from Google Search Console (GSC), Google Analytics, AdSense, Page Speed Insights and other Google tools. Researchers at WordFence ( More Info

Read More »

Nearly a million WordPress sites targeted in extensive attacks

A threat actor is actively trying to insert a backdoor into and compromise WordPress-based sites to redirect visitors to malvertising. “While our records show that this threat actor may have sent out a smaller volume of attacks in the past, it’s only in the past few days that they’ve truly ramped up, to the point where more than 20 million attacks were attempted against more than half a million individual sites on May 3, 2020,” Wordfence analysts discovered. “Over the course of the past month in total, we’ve detected over 24,000 distinct IP addresses sending requests… More Info

Read More »

Nearly 900,000 WordPress Sites Targeted in a Hacking Campaign

Threat actors tried to hack nearly one million WordPress sites in the last week, according to a security alert issued by cybersecurity firm Wordfence. The threat intelligence team at Wordfence stated that hackers launched attacks from 24,000 different IP addresses and tried to break into more than 900,000 WordPress sites. It was found that since April 28, 2020, unknown hackers engaged in this massive campaign that caused a 30 times increase in the volume of attack traffic. The attacks peaked on May 3, 2020, when the group launched more than 20 million hacking attempts… More Info

Read More »

Jetack 8.5 Adds New Podcast Player Block – WordPress Tavern

Jetpack 8.5 was released today with a new podcast player block for sharing audio content. Configuring the block is as simple as entering the podcast RSS feed URL. This will automatically bring in the cover art and recent episodes. Block options allow for further customization of the display, including the number of episodes, colors, and the ability to show/hide cover art and episode descriptions. Jetpack’s new podcast player has arrived just in time, as podcasting has gotten a little boost in recent months due to the large numbers of people under stay-at-home orders…. More Info

Read More »

A hacker group tried to hijack 900,000 WordPress sites over the last week

A hacker group has attempted to hijack nearly one million WordPress sites in the last seven, according to a security alert issued today by cyber-security firm Wordfence. The company says that since April 28, this particular hacker group has engaged in a hacking campaign of massive proportions that caused a 30x uptick in the volume of attack traffic Wordfence has tracking. “While our records show that this threat actor may have sent out a smaller volume of attacks in the past, it’s… More Info

Read More »

Find My Blocks Plugin Shows All Blocks in Use on a WordPress Site – WordPress Tavern

How do you know what blocks are in use on a WordPress site? I recently saw a tweet asking this question in regards to knowing whether it is safe to turn off a plugin. This seems like it could become a common question, especially for those who have hundreds or thousands of blog posts as well as those using WordPress as a CMS. How hard would it be to create a plugin that let’s me know how many and which blocks I’m using site wide? Sometimes I wonder if I can deactivate a block plugin but I don’t know if I’m using a block it provides. — Nick Hamze (@NickHamze) April 23,… More Info

Read More »

Researchers Discover Multiple WordPress Security Exploits In Popular E-Learning Platforms

As the coronavirus pandemic continues around the world, everyone’s lives have changed. The way we work and learn is significantly different now than it was only a few months ago as people shelter in place, and offices and schools around the globe have been forced to move to a distance model. Teaching from home has forced educational institutions everywhere to quickly move to online learning and to implement new systems to support the shift. Security researchers at Check Point Research decided to audit the security of several of the most popular Learning Management Systems (LMS) that are… More Info

Read More »