<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>wordpress security — LowEndSpirit DEV</title>
        <link>https://dev.lowendspirit.com/index.php?p=/</link>
        <pubDate>Sun, 12 Apr 2026 04:24:31 +0000</pubDate>
        <language>en</language>
            <description>wordpress security — LowEndSpirit DEV</description>
    <atom:link href="https://dev.lowendspirit.com/index.php?p=/discussions/tagged/wordpress-security/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>More WordPress Plugin Issues- Feb 2022Edition Part II</title>
        <link>https://dev.lowendspirit.com/index.php?p=/discussion/3797/more-wordpress-plugin-issues-feb-2022edition-part-ii</link>
        <pubDate>Thu, 24 Feb 2022 08:18:44 +0000</pubDate>
        <category>WordPress</category>
        <dc:creator>vyas</dc:creator>
        <guid isPermaLink="false">3797@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Let us close the month with not One, Not Two, but NINE plugins</p>

<p>It just keeps getting better and better. <br /><a href="https://www.searchenginejournal.com/nine-wordpress-plugins-expose-over-1-3-million-sites-to-exploits/439276/#close" rel="nofollow">https://www.searchenginejournal.com/nine-wordpress-plugins-expose-over-1-3-million-sites-to-exploits/439276/#close</a></p>

<p>"Vulnerabilities in Nine WordPress Plugins<br />
While there were many more plugins found vulnerable, the nine most  popular plugins affected well over 1.3 million websites. The  vulnerabilities were rated<br />
The following are on the list of nine vulnerable plugins:</p>

<pre spellcheck="false" tabindex="0">Header Footer Code Manager 300,000+ installations
Ad Inserter – Ad Manager &amp; AdSense Ads 200,000+ installations
Popup Builder WordPress plugin 200,000+ installations
Anti-Malware Security and Brute-Force Firewall 200,000+ installations
WP Content Copy Protection &amp; No Right Click 100,000+ installations
Database Backup for WordPress 100,000+ installations
GiveWP – Donation Plugin and Fundraising Platform 100,000+ installations
Download Manager 100,000+ installations
Advanced Database Cleaner WordPress plugin 80,000+ installations"
</pre>

<p>Edit: Fixed title.</p>
]]>
        </description>
    </item>
    <item>
        <title>Attack on ~ 1.5 Mn WordPress Sites</title>
        <link>https://dev.lowendspirit.com/index.php?p=/discussion/3621/attack-on-1-5-mn-wordpress-sites</link>
        <pubDate>Fri, 10 Dec 2021 17:46:47 +0000</pubDate>
        <category>WordPress</category>
        <dc:creator>vyas</dc:creator>
        <guid isPermaLink="false">3621@/index.php?p=/discussions</guid>
        <description><![CDATA[<p><a href="https://www.bleepingcomputer.com/news/security/massive-attack-against-16-million-wordpress-sites-underway/" rel="nofollow">https://www.bleepingcomputer.com/news/security/massive-attack-against-16-million-wordpress-sites-underway/</a></p>

<p>Check the themes and plugins in the list. If present. maybe disable!</p>

<p>The affected plugins and their versions are:</p>

<pre spellcheck="false" tabindex="0">PublishPress Capabilities
Kiwi Social Plugin
Pinterest Automatic
WordPress Automatic 
</pre>

<p>The targeted Epsilon Framework themes are:</p>

<pre spellcheck="false" tabindex="0">Shapely
NewsMag
Activello
Illdy
Allegiant
Newspaper X
Pixova Lite
Brilliance
MedZone Lite
Regina Lite
Transcend
Affluent
Bonkers
Antreas
NatureMag Lite – No patch available
</pre>

<p>Among the top 10 attack machines have <br />
Contabo and OVH ips</p>

<p>( I had read 1.9 Mn sites elsewhere, the bleeping computer link mentions 1.6 Mn. Updated the title)</p>
]]>
        </description>
    </item>
   </channel>
</rss>
