Category: WordPress Security
Number of reported WordPress Plugin & Theme vulnerabilities doubled in the first 6 months of 2023
We recently introduced vulnerability detection in Really Simple Security and have been working on a database of vulnerabilities sourced from the open WordPress Vulnerability Database API project (https://www.wpvulnerability.com) since the beginning of 2023. We have been monitoring WordPress plugin and Theme vulnerabilities for years and have seen an increase in reported vulnerabilities yearly. Having access to detailed information in our own database enabled us to look closer into the details and numbers. We were surprised to find the number of
Vulnerability Detection for WordPress
WP Vulnerabilities – An open-source initiative WP Vulnerabilities is an open-source, free API by Javier Casares with contributions from other open-source, freely available databases and many manual hours from moderators and security officers from other plugins, including our own security officer. Really Simple Security mirrors the free database with its own instance to secure stability and deliverability, but of course provides the origin database with an API to enrich, or improve its current data. An open-source platform, with an enormous
About Vulnerabilities
A vulnerability is a known security flaw in a plugin, theme, or WordPress core. When one is discovered, it gets added to public databases that attackers use to automatically find sites to target. Really Simple Security scans your installed plugins and themes against these databases and alerts you when something you are running has a known vulnerability. The alert tells you exactly which item is affected and what to do — usually updating to the latest patched version or temporarily
About custom login URLs
We have added a new feature under Advanced Hardening. You can now change your default login URL to a custom login URL. This will mitigate bot attacks on default WordPress login URLs. This features come with another, background process, that is also important to note: Email notifications. The setting for email notifications can be found under General. If you ever forget the login URL, you can use a parameter as explained below to receive an email with your custom login
Content security policy maximum size exceeded
The maximum size available for http headers on your website depends on the webserver that runs your website. For most webservers like Apache and Lightspeed the limit is 8192 bytes but the default configuration of Nginx sets this limit to 4096 bytes. When your website is running Nginx with the default configuration, available space for HTTP headers is limited. In most cases this will be fine but if you have a large Content Security Policy it might result in the