Outdated WordPress Plug-ins, Themes Distribute Backdoors For Potential Supply Chain Attack, Jetpack Says

[ad_1]

WordPress themes and plug-ins became the latest target of suspicious attackers, according to Jetpack. For those who are using the older versions of these features, there is a possibility that you might compromise your system through their backdoors without your notice.

JetPack Spots WordPress Backdoors

Outdated WordPress Plug-ins, Themes Distribute Backdoors For Potential Supply Chain Attack, Jetpack Says

(Photo : Stephen Phillips – Hostreviews.co.uk from Unsplash)
WordPress themes and plug-ins became the latest target of suspicious attackers, according to Jetpack.

According to a report by PC Mag, the cybersecurity team JetPack spotted some problems…

[ad_2]
More Info

Supply chain attack used legitimate WordPress add-ons to backdoor sites

[ad_1]

Supply chain attack used legitimate WordPress add-ons to backdoor sites

Getty Images

Dozens of legitimate WordPress add-ons downloaded from their original sources have been found backdoored through a supply chain attack, researchers said. The backdoor has been found on “quite a few” sites running the open source content management system.

The backdoor gave the attackers full administrative control of websites that used at least 93 WordPress plugins and themes downloaded from AccessPress Themes. The backdoor was discovered by security researchers from JetPack, the maker of security…

[ad_2]
More Info

Supply chain attack used legitimate WordPress add-ons to backdoor sites

[ad_1]

Supply chain attack used legitimate WordPress add-ons to backdoor sites

Getty Images

Dozens of legitimate WordPress add-ons downloaded from their original sources have been found backdoored through a supply chain attack, researchers said. The backdoor has been found on “quite a few” sites running the open source content management system.

The backdoor gave the attackers full administrative control of websites that used at least 93 WordPress plugins and themes downloaded from AccessPress Themes. The backdoor was discovered by security researchers from JetPack, the maker of security…

[ad_2]
More Info

20K WordPress Sites Exposed by Insecure Plugin REST-API – Threatpost

[ad_1]

wordpress plugin

The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS.

More than 20,000 WordPress sites are vulnerable to malicious code injection, phishing scams and more as the result of a high-severity cross-site scripting (XSS) bug discovered in the WordPress Email Template Designer – WP HTML Mail, a plugin for designing custom emails.

The new vulnerability (CVE-2022-0218, CVSS score 8.3) was found by Wordfence researcher Chloe…

[ad_2]
More Info

Over 90 WordPress themes, plugins backdoored in supply chain attack

[ad_1]

chain

A massive supply chain attack compromised 93 WordPress themes and plugins to contain a backdoor, giving threat-actors full access to websites.

In total, threat actors compromised 40 themes and 53 plugins belonging to AccessPress, a developer of WordPress add-ons used in over 360,000 active websites.

The attack was discovered by researchers at Jetpack, the creators of a security and optimization tool for WordPress sites, who discovered that a PHP backdoor had been added to the themes and plugins.

Jetpack believes an external threat actor breached the AccessPress website to compromise the…

[ad_2]
More Info

4 Top-Rated WordPress Designers Share Web Design Tips for 2022 [DesignRush QuickSights] | News

[ad_1]

NEW YORK, Jan. 21, 2022 /PRNewswire-PRWeb/ — WordPress currently powers 38% of the entire Internet and owns over 64% of the CMS market. The popularity of WordPress boils down to its intuitive UI, integration capabilities and scalability that makes it suitable for businesses of all sizes and profiles.

DesignRush, a B2B marketplace connecting brands with agencies, leveraged its 11,000-agencies-strong network for quick insights – or “QuickSights” – on…

[ad_2]
More Info

Create Todo and Checklists in the WordPress Editor With New Plugin – WP Tavern

[ad_1]

Todo lists. Checklists. While there are differences in their purposes, their output is essentially the same. They are lists of items with boxes to tick off, and a plugin like David Towoju’s Todo Block allows users to create them.

I first downloaded and installed the plugin two weeks ago, but it had a problem. It did not seem to add any blocks at all. This was likely some mistake with porting the plugin over from its development repository. I have been testing it since its update a few days ago and like where it is headed.

Technically, the plugin has two blocks. One exists for…

[ad_2]
More Info

Create Todo and Checklists in the WordPress Editor With New Plugin – WP Tavern

[ad_1]

Todo lists. Checklists. While there are differences in their purposes, their output is essentially the same. They are lists of items with boxes to tick off, and a plugin like David Towoju’s Todo Block allows users to create them.

I first downloaded and installed the plugin two weeks ago, but it had a problem. It did not seem to add any blocks at all. This was likely some mistake with porting the plugin over from its development repository. I have been testing it since its update a few days ago and like where it is headed.

Technically, the plugin has two blocks. One exists for…

[ad_2]
More Info

WordPress Plugins for E-Commerce | HTMLGoodies.com

[ad_1]

Nearly half of the world’s websites are powered by the WordPress content management system (CMS) platform. While it can be used to build several types of sites, many use WordPress to construct their online stores for eCommerce.

How do you make a WordPress eCommerce site better than it already is? By extending its functionality via plugins. Keep reading to find out which WordPress plugins for eCommerce can help upgrade your online store.

The Top eCommerce Plugins For WordPress

WordPress eCommerce plugins can ramp up your site’s capabilities in various ways. Some plugins can help…

[ad_2]
More Info

Why Aren’t More WordPress Theme Authors Creating Block Themes? – WP Tavern

[ad_1]

Block themes are trickling into the official WordPress Themes Directory at a slow rate ahead of full-site editing’s debut in WordPress 5.9. There are now 39 themes that support site editing features, up from 28 in December 2021, when Matt Mullenweg commented on it during the State of the Word address.

“That needs to be 5,000,” Mullenweg said. Later during the presentation he said he hopes that WordPress will “have 300 or ideally 3,000 of these block themes” before entering the Collaboration phase of the Gutenberg project.

Why the strong push towards kickstarting the…

[ad_2]
More Info