iThemes Patches Vulnerability in BackupBuddy, Wordfence Tracks 5 Million Exploit Attempts

BackupBuddy, a commercial plugin from iThemes that performs scheduled backups with remote storage options, has patched a vulnerability that allowed for arbitrary file download by unauthenticated users. iThemes published an advisory for its users, indicating that the vulnerability affects versions 8.5.8.0 through 8.7.4.1 and is being actively exploited. Wordfence reviewed its data and found that attackers began targeting this vulnerability …

Gutenberg Contributors Make Progress on Distraction Free Mode

During last week’s Editor chat meeting, Automattic-sponsored Gutenberg contributor Andrei Draganescu reported that he is “slowly but definitely going to introduce distraction free mode,” a project he has been working on since early explorations began in February. The PR he referenced (#41740) is an extension of those explorations that takes the mode even further towards the objective of removing visual clutter …