Major WordPress Security Vulnerabilities Found: You MUST Update

2 days ago, WordPress released what they called a “critical security release” for all previous versions. This new release patches a vulnerability that was found in the commenting of WordPress which would allow a potential hacker access to your site.

This comes on the heels of several other vulnerabilities found in a whole list of popular plugins. They known plugins are below:

  • Jet Pack (Many hosts preinstall this plugin for you!)
  • All In one SEO
  • WordPress SEO
  • Google Analytics by Yoast
  • Ninja Forms
  • Revolutions Slider (This plugin comes prepackaged with a lot of premade themes so you may not be aware that you are using it. It’s security flaw was released earlier in the year, but is quite nasty and still prevalent.)
  • WP-E-Commerce
  • Gravity Forms
  • Broken-Link-Checker
  • Multiple Plugins from Easy Digital Downloads
  • UpdraftPlus
  • WPTouch
  • Download Monitor
  • Related Posts for WordPress
  • My Calendar
  • P3 Profiler
  • Give
  • Multiple iThemes products including Builder and Exchange

The vulnerability uses a WordPress function to access your site. While security teams checked the majority of the popular plugins, they were not able to check all. Likely this list is not exhaustive.

What can you do?

Screen Shot 2015-04-29 at 1.33.20 PM
1. Update All Plugins. If you are running any of these plugins, update immediately. In fact, you should update all plugins whether they are on this list or not. You can do so within your WordPress backend under the tab called “Plugins -> Installed Plugins”. Any plugin that is not a custom plugin should be updated.

Note: If you have done any SEO on your site, you are likely running Yoast and All in One SEO. They are the two most popular SEO plugins. If your site is hosted on the KL Creative servers, these plugins have already been updated for you (by your friendly WP elves).

2. Update WordPress
You should also update to the newest version of WordPress. To find out if you are running the newest version of WordPress, click on “Dashboard” on the top left navigation. All the way on the bottom right corner of the page it will tell you your version number. The most current release is 4.2.1. If you are not running 4.2.1, you should receive a notice along the top asking you to update. If you do not, but the version number is still wrong, give us a call and we will take a look for you for free.

If you have any questions about the updating process, give us a call and we would be happy to take a look for you.

More Info…

Up Next

Related Insights

How To Take Better Photos For Your Website & Social Media

Here are some photography tips specifically tailored toward business leaders who use iPhones! High-quality photography is important for every website and social media page, but what exactly makes incredible iPhone photography? Although mastering photographic moments is something that challenges even the most experienced professionals on a day-by-day basis, business leaders...

Client Email Communications & How To Update Your Email Security

Several Tandem Design Lab clients have recently experienced email difficulties, so here’s how to fix these issues! We’ve recently been hearing from some of our clients about how their email accounts are rejecting other people’s emails and kicking messages back to senders. This is an unfortunate communication mishap for any...

Colorado’s New Accessibility Compliance Law

The state of Colorado is leading the way in website accessibility. Colorado is taking the right to equal access to web content seriously by making it easier to prosecute agencies that don’t provide equal access to the information or services obtained on the internet.