2023 Annual Survey Results and Next Steps

Each year, WordPress seeks to collect high-level data about trends and themes across the vast ecosystem of users, site builders, extenders, and contributors to help inform decision-making and provide valuable feedback on the project’s status.  For 2023, the survey process was updated to enhance accessibility, usability, analysis, and multilingual support. Additionally, a few questions were … Read more

Wordfence Intelligence Weekly WordPress Vulnerability Report (September 11, 2023 to September 17, 2023)

Last week, there were 55 vulnerabilities disclosed in 46 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 15 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our mission with … Read more

Two PHP Object Injection Vulnerabilities Fixed in Essential Blocks

On August 18, 2023, the Wordfence Threat Intelligence team initiated the responsible disclosure process for two PHP Object Injection vulnerabilities in the Essential Blocks plugin for WordPress, a plugin with over 100,000 installations. We received a response three days later and sent over our full disclosure on August 23, 2023. A patched version of the … Read more