Remote Code Execution Vulnerability Patched in WPML WordPress Plugin

The popular WordPress Multilingual plugin, WPML, which is installed on over 1,000,000 websites, has patched a Remote Code Execution (RCE) vulnerability (CVE-2024-6386) that researchers have classified as “Critical,” with a CVSS score of 9.9. Users are strongly advised to update their websites to the patched version, WPML 4.6.13. Security researcher Mat Rollings (stealthcopter) discovered and reported the vulnerability through the …

WordPress Community Team to Retire CrowdSignal for Jotform

The WordPress Community Team has announced plans to retire CrowdSignal in September 2024 in favor of Jotform for post-event attendee surveys. Automattic-sponsored Community Engagement Specialist Isotta Peira has shared more details about the decision and the future plans.  Why the Change? CrowdSignal (previously Polldaddy), owned by Automattic, has been used by the community to collect responses, including at large events …

Better Compression with Brotli

Pssst… have you noticed your site loading a bit faster than usual? It’s not your imagination! We’re happy to let you know that we’ve rolled out Brotli to all of your WPMU DEV hosted sites, giving you on average 11.62% better compression than before (and faster sites as a result!) It’s a change that’ll make a big difference particularly if …

Record Bounty Awarded as Critical Privilege Escalation Vulnerability Patched in LiteSpeed Cache Plugin

The LiteSpeed Cache Plugin, widely used to enhance the speed and performance of WordPress websites, recently patched a critical unauthenticated privilege escalation vulnerability (CVE-2024-28000). With over 5 million active installations, this plugin is a critical tool for many WordPress users. John Blackbourn, a member of the Patchstack Alliance community, reported the vulnerability and was awarded $14,400, marking the highest bounty …