More than 2,000 WordPress websites are infected with a keylogger

Enlarge / A screenshot showing a keylogger extracting user names and passwords. It’s currently infecting more than 2,000 WordPress websites. (credit: Sucuri) More than 2,000 websites running the open-source WordPress content management system are infected with malware, researchers warned late last week. The malware in question logs passwords and just about anything else an administrator […]

WordPress 4.8 arrives with link boundaries and widget improvements, drops WMV and WMA support

WordPress.org today launched WordPress 4.8, which adds a slew of new features to the blog management tool “to express yourself and represent your brand.” You can download the new release, available in 38 languages, now from WordPress.org/Download (8.5MB). WordPress is a content management system (CMS) that powers 25 percent of the web. The latest version […]

Researchers find “severe” flaw in WordPress plugin with 1 million installs

More than 1 million websites running the WordPress content management system may be vulnerable to hacks that allow visitors to snatch password data and secret keys out of databases, at least under certain conditions. The vulnerability stems from a “severe” SQL injection bug in NextGEN Gallery, a WordPress plugin with more than 1 million installations. […]

Virally growing attacks on unpatched WordPress sites affect ~2m pages

Enlarge (credit: Wordfence) Attacks on websites running an outdated version of WordPress are increasing at a viral rate. Almost 2 million pages have been defaced since a serious vulnerability in the content management system came to light nine days ago. The figure represents a 26 percent spike in the past 24 hours. A rogues’ gallery […]