Elementor Patches XSS Vulnerabilities Affecting 7 Million WordPress Sites

Elementor users who haven’t updated recently will want to get on the latest version 3.1.4 as soon as possible. Researchers at Wordfence disclosed a set of stored Cross-Site Scripting (XSS) vulnerabilities in the plugin to its authors in February, which was partially patched at that time and additional fixes were released the second week of March. Wordfence summarized the vulnerabilities in …

Attackers Continue to Exploit Vulnerabilities in The Plus Addons for Elementor Plugin

Last week, security researchers at Seravo and WP Charged reported a critical zero-day vulnerability in The Plus Addons for Elementor on March 8, 2021. WPScan categorized it as an authentication bypass vulnerability: The plugin is being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the …

Gutenberg Block Manager Plugin Enables Global Block Removal and Recategorization

The world of Gutenberg blocks is expanding. WordPress’ official block directory launched in June 2020 with just 60 single-block plugins. Today, it has grown to more than 480 blocks. As users incorporate more blocks into their websites, the block inserter can become a very long list to scroll when browsing. Block management capabilities were added to Gutenberg in version 5.3, …

New Full Site Editing Testing Challenge: Create a Custom 404 Page

The Full Site Editing (FSE) Outreach program has launched its third testing call, continuing the effort to engage users in a structured testing flow focused on specific practical tasks. Previous rounds had testers building a custom homepage and exploring the distinction between editing modes (template vs page/post). The challenge in round #3 is to create a fun, custom 404 page. …

WordPress.com and Jetpack Launch Story Block for Mobile Apps

Automattic-owned WordPress.com launched its new Story-publishing feature today. Currently, only users with the WordPress for Android or iOS apps can add stories. Self-hosted users with Jetpack-connected sites can publish via the mobile apps too. The development team previewed the Story feature in January, launching a public beta on the Android app. Stories are essentially media and text slideshows. They have …