Over one million WordPress sites receive forced update to security plugin after severe vulnerability discovered

Loginizer, a popular plugin for protecting WordPress blogs from brute force attacks, has been found to contain its own severe vulnerabilities that could be exploited by hackers. The flaw, discovered by vulnerability researcher Slavco Mihajloski, opened… Continue reading Over one million WordPress sites receive forced update to security plugin after severe vulnerability discovered

Problem with Google OAuth 2 authorization and enabling SSL certificate on my wordpress website [closed]

I have a wordpress website. I was using Google login (OAuth 2 authentication) but I had no SSL certificate but Google login was doing pretty well.
But after enabling my SSL certificate (after like 3 or 4 hours) I try to login using Google … Continue reading Problem with Google OAuth 2 authorization and enabling SSL certificate on my wordpress website [closed]

Dreamhost hosted wordpress site attacked – SSH password was changed – Need help assesing attack vector

My client had his wordpress site attacked, his site is not a juici target, the attack consisted in redirecting the site to another site.
That in itself is no surprise, the weird thing is that both the SSH (For context, the site is on a vps… Continue reading Dreamhost hosted wordpress site attacked – SSH password was changed – Need help assesing attack vector