#WordPress-Plug-in #TranslatePress ermöglicht Übernahme bei 400.000 Installationen | Security heise.de/news/… #WordPRessPlugIn #Patchday #CMS #ContentManagementSystem
wordpress
Follow from the Fediverse
Follow #wordpress from Mastodon or any other Fediverse app and its public posts arrive in your timeline. No vutuv account needed.
@wordpress@tags.vutuv.de
The most endorsed users with this tag
Posts with this tag
11 posts
Filters
WordPress-Plug-in TranslatePress ermöglicht Übernahme bei 400.000 Installationen
Eine Lücke im Plug-in TranslatePress für WordPress gefährdet 400.000 Instanzen. Angriffe laufen derweil auf miniOrange SAML.
Klick auf gefälschtes #Captcha führt zu #Malware-Download - inside-it[.]ch inside-it.ch/klick-auf-gefaelschtes-cap… #Patchday #WP2Shell #CMS #ContentManagementSystem #WordPress #WordPressPlugIn
Lücke in WordPress-Plug-in Elementor Pro: 6 Millionen Webseiten gefährdet
Eine kritische Sicherheitslücke im WordPress-Plug-in Elementor Pro ermöglicht die komplette Übernahme von WordPress.
WordPress-Plug-in Forminator Forms: Kritische Lücke erlaubt Codeschmuggel
Das WordPress-Plug-in Forminator Forms enthält eine kritische Schadcode-Lücke. Zudem sind Royal Elementor Addons löchrig.
This is my whole #WordPress story on the HeroPress web site. Both English and Italian.
My first intention was to talk about my MARS (Multilingual Accessible Rudimental System) WordPress plugin project , built using Chat GPT 5.6Sol model. Day by day, sharing here all developments. But it is so unpredictable, yesterday at 9:30 pm I assumed I had fixed all regression but a sudden one took my time until 40 past midnight.
So I just share the fact I’m building, but the complete experience will come when the structure is stable enough (for blind and sighted).
I’m planning not to publish it on WordPress plugin repository as, not being a coder myself, AI could generate both dirty and vulnerable code without me realizing it. So, it’ll be my site’s experience, maybe a github or forgejo repo, an experiment by a blind person trying to cover their own needs with the aid of technology.
I think everyone working for the web, should remember that all 5 senses, physical and cognitive abilities, are TEMPORARY. No money-filled privileged leader should have the right to stop #accessibility initiatives.
This Mullenweg guy is becoming toxic for the #WordPress surviving itself.
Accessibility Team Initiative “Permanently Delayed” as Matt Mullenweg Declares Team Has “Overstepped Its Authority” - The Repository therepository.email/accessibility-team-…
An deiner Webseite fehlt die Klingel
Gestern Abend habe ich meine eigene Seite aufgerufen und eine Fehlerseite bekommen: keine security.txt. Bei 98 von hundert deutschen Webseiten fehlt diese Klingel, also die Datei, die sagt, an wen man sich wendet, wenn man eine Sicherheitslücke gefunden hat. Zehn Minuten Arbeit. Reden wir drüber!
“Offiziell gekauft” ist bei WordPress-Themes ungefähr so eine Qualitätsgarantie wie “TÜV-geprüft” bei einem Temu-Toaster vom Flohmarkt.
Ein Kundenprojekt, ein verschwundenes Elementor-Widget, eine kryptische JavaScript-Fehlermeldung - und am Ende der Spur: ein simpler Tippfehler in einer kommerziell verkauften Plugin-Datei, der seit vermutlich Jahren unentdeckt im Code schlummert.
Im neuen Blogpost zeigen wir, warum weder das offizielle WordPress.org-Repository noch Marktplätze wie ThemeForest eine funktionale Fehlerfreiheit garantieren - und was das für euer nächstes Projekt bedeutet.