Record Bounty Awarded as Critical Privilege Escalation Vulnerability Patched in LiteSpeed Cache Plugin

The LiteSpeed Cache Plugin, widely used to enhance the speed and performance of WordPress websites, recently patched a critical unauthenticated privilege escalation vulnerability (CVE-2024-28000). With over 5 million active installations, this plugin is a critical tool for many WordPress users. John Blackbourn, a member of the Patchstack Alliance community, reported the vulnerability and was awarded $14,400, marking the highest bounty …

DEV – I Like My Coffee #000000

Read to the end to see a bunk bed for cats. (Yes, really!) In today’s edition: We get a thrilling affiliate offer we can’t refuse from WP Forms. Twenty Twenty-Five and the like, impermanent beauty of the passage of time, man. How to make sure your WordPress site (and your XML sitemap) doesn’t get lost in translation. Hot Off The …

Jamie Marsland Joins Automattic as Head of WordPress YouTube

Jamie Marsland, a well-known figure in the WordPress community, has officially joined Automattic as the Head of WordPress.org YouTube. Previously, he had collaborated with WordPress.com on a series of YouTube videos titled ‘build and beyond.’ In the official announcement, the Executive Director of WordPress, Josepha Haden Chomphosy, said, “ Jamie’s extensive experience in the WordPress community and his passion for …

WordCamp Asia Extends Speaker Application Deadline to September 8, 2024

The WordCamp Asia organizing team has extended the speaker application deadline to September 8, 2024. This extension aims to give more WordPress enthusiasts the opportunity to apply for the prestigious event. One of the three flagship WordCamps, WordCamp Asia, will be held at the Philippine International Convention Center in Manila, Philippines, from February 20 to 22, 2025. Interested speakers can …

Critical Vulnerability Patched in GiveWP Plugin

GiveWP, a popular donation plugin for WordPress, has patched an unauthenticated PHP Object Injection to Remote Code Execution vulnerability that could be exploited to execute arbitrary code remotely and delete files. This plugin from the Liquid Web family of products has 100k+ active installs.  villu164 (Villu Orav) reported the vulnerability through the Wordfence Bug Bounty Program and netted a bounty …