WordPress iOS App Bug Leaked Secret Access Tokens to Third-Party Sites

If you have a “private” blog with WordPress.com and are using its official iOS app to create or edit posts and pages, the secret authentication token for your admin account might have accidentally been leaked to third-party websites.

WordPress has rec… Continue reading WordPress iOS App Bug Leaked Secret Access Tokens to Third-Party Sites

Hackers using hacked WordPress & Joomla sites to drop malware

By Waqas
Apparently, the malware attack is carried out by Russian speaking hackers. The IT security researchers at Zscaler have discovered a sophisticated malware campaign targeting websites based on WordPress and Joomla content management system (CMS)… Continue reading Hackers using hacked WordPress & Joomla sites to drop malware

Bugs, Breaches, and More! – Application Security Weekly #55

XSS Vulnerability in Abandoned Cart Plugin Leads to WordPress Site Takeover, The RedMonk Programming Language Rankings: January 2019, I Deleted Facebook Last Year; Here’s What Changed (and What Didn’t), CommitStrip: Over-excited, and more! … Continue reading Bugs, Breaches, and More! – Application Security Weekly #55