Critical Vulnerability Patched in GiveWP Plugin

GiveWP, a popular donation plugin for WordPress, has patched an unauthenticated PHP Object Injection to Remote Code Execution vulnerability that could be exploited to execute arbitrary code remotely and delete files. This plugin from the Liquid Web family of products has 100k+ active installs.  villu164 (Villu Orav) reported the vulnerability through the Wordfence Bug Bounty Program and netted a bounty …

Wordfence Launches WordPress Superhero Challenge with Big Rewards

Wordfence has introduced an exciting new initiative, the WordPress Superhero Challenge, as part of its ongoing Bug Bounty Program. Running until October 14th, this challenge exclusively targets plugins and themes with over 5 million active installations, a category that demands a high level of expertise due to the extensive testing these products undergo before reaching production. Chloe Chamberland, the Threat …

Gutenberg 19.0 Introduces Two New Experimental Features

Gutenberg 19.0 has arrived with two exciting experimental features, along with various feature enhancements and bug fixes. The Gutenberg team is actively seeking user feedback on these experimental additions. The first experimental feature is the highly anticipated UI prototype for connecting blocks and custom fields. To try it out, you can enable the “UI to create block bindings” experiment by …