home.social

#wordfence — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wordfence, aggregated by home.social.

  1. Wordfence reports more than 440,000 blocked attack attempts targeting two WordPress plugins: about 250,000 against Super Forms – Drag & Drop Form Builder and 190,000 against Elementor Pro.

    The issues could allow attackers to upload files and potentially take control of affected sites.

    Super Forms is fixed in version 6.3.314; Elementor Pro in 4.2.2.

    Site owners should update and check for unfamiliar files or unexplained…

    en.hacks.gr/super-forms-kai-el

    #WordPress #ElementorPro #SuperForms #Wordfence

  2. Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
    ----------
    On July 28th, 2026, our autonomous AI vulnerability intelligence agent, Wordfence PRISM, identified a critical[…]

    WordPress #Security #Tools #Wordfence #WordfencePRISM

    wpnews.io/wordfence-prism-dete

  3. Wordfence: 1,764 CVEs, 528 critical/high. Avg CVSS 6.38, max 10. 0% unpatched, Trust Score A. But 2025→2026 CVEs +1,513. XSS (CWE-79) dominates. Vigilance still key. #Wordfence #infosec #cybersecurity

    valtersit.com/vendors/wordfenc

  4. 📣🚨 Critical backdoor found in #ARVE, a WordPress plugin used by 20,000+ sites to embed responsive videos from YouTube, Vimeo, Rumble, Odysee, TikTok, Twitch, Facebook, Dailymotion, Kick, and other platforms.

    Listen/Read: hackread.com/wordfence-critica

    #WordPress #Cybersecurity #Wordfence #Malware

  5. anyone at #WordFence kicking around here? Either way, I'd REALLY like to know why there are super special IPs I'm not allowed to block?

  6. Never had any issues with #Wordfence for years till I stuck it on our shop. There must be something in our #Woocommerce set-up that it doesnʼt like. Had to deactivate it via my phone to look for other solutions (as it somehow disliked my using broadband to get in and made the site unreachable)!

  7. My current guess is it's a #wordpress/#wordfence plugin issue error?

    Clearing device browser cache and flushing DNS does not resolve it. Other devices on other networks load the actual pages fine, and even other devices on this network can do so.

  8. Ich habe mir vorgenommen, wieder häufiger zu bloggen und bin dabei direkt in ein Problem gelaufen:
    Stolperstein 2FA bei WordPress-Zugriff per XML-RPC (Wordfence)
    schacknetz.de/stolperstein-2fa

    #Wordpress #Wordfence #2FA #XMLRPC #MarsEdit

  9. @macmanx @threadi @ramsey @simon
    In last months I got mails both from patchstack.com and from wordfence.com. If they detect a vulnerability #Wordfence closes the plugin, #Patchstack sets a deadline.

    wordfence.com/threat-intel/vul

  10. > The Plugin "…" appears to be abandoned (updated December 18, 2023, tested to WP 6.9.0).

    Well, thanks Wordfence but I think tested up to WP 6.9.0 indicates that it isn't abandoned.

    Sometimes, plugins don't need fixes or new features. 🙄

  11. Holy crap, #Wordpress users out there, is #Wordfence the single dumbest piece of software ever made? I view a site "protected" by Wordfence, it loads fine. Then I go to a different site and read a page, then I hit back in my browser, and the original site is now "Advanced blocking in effect" on my (presumably) IP address.

  12. OK, so #Wordfence and #Wordpress.org need to get their shit together. No way do I suddenly have 2484 suspicious files in my core installation 6 hours after an update.

  13. BuddyPress 14.2.1 Maintenance & Security release

    The “Take Photo” feature (which uses the logged in user’s Webcam to capture their profile photo) was vulnerable to an authenticated (Subscriber+) directory traversal. Discovered by Domons from the Wordfence organization.

    #buddypress #wordpress #plugin #foss #opensource #software #security #wordfence