Reading view

Not a great month for our favorite Elementor-related plugins...

A supply chain hit has just taken down the BdThemes lineup, disabling popular plugins like Element Pack and Prime Slider on the official WordPress directory. This is not your typical code hack. They did not touch any files on the WordPress servers. Instead, they went upstream and poisoned the remote static JSON feed that pushes promotional banners into the admin dashboard.
___
Element Pack Addons for Elementor, Prime Slider Addons for Elementor, Pixel Gallery Addons for Elementor, Ultimate Post Kit Addons for Elementor, Ultimate Store Kit, Live Copy Paste for Elementor, Smart Admin Assistant.
----

In short, an escaping flaw allowed malicious data from that feed to execute JavaScript whenever an administrator loaded a WordPress admin page. The injected JavaScript could silently create rogue administrators, install a web shell, and establish persistent backdoors. Yeah, that's not good.

Why is this important?
The plugin files themselves did not need to be altered.
Let's let that sink in for a moment...

https://preview.redd.it/wa22w0vsneih1.png?width=791&format=png&auto=webp&s=9cc4ad1c533796ddc8394ebba6bf7070c7a3126d

submitted by /u/hackrepair
[link] [comments]
  •  

WordPress took a beating this past month...

WordPress took a beating this past month. The newest AI models are finding and writing code to exploit vulnerabilities that sat hidden for years.

Nobody caught them until these latest model releases. So now we are dealing with the fallout...

WordPress 7.0.3 officially dropped today, August 6, as a new security release.

The recent security reality.
The WordPress.org core team forced a background auto-update for 7.0.2 in July to handle active exploits.

What was patched in July?
- Patched one critical-severity flaw.
- Patched one high-severity flaw.

Version 7.0.3 follows right on its heels. Given the current wave of AI-driven attacks, you want to apply this patch immediately.

Those 7.0 branch fixes?
The 7.0 branch was a significant upgrade, to say the least. It dropped native AI engine frameworks and fixed server-side memory leaks that previously choked websites.

And version 7.0.1 knocked out 31 bugs in the block editor, fixed media library folder-view errors, and cleaned up display issues in the new admin dashboard.

I think, all told, the core team resolved over 700 bugs across core and Gutenberg. So for those folks who say the WordPress dev team has fallen asleep on the job, well, I'd say more like three Red Bulls a day...

Do not wait on this. Log into your dashboard, run a backup, and apply the 7.0.3 update.

https://preview.redd.it/y3wg4dslfthh1.png?width=575&format=png&auto=webp&s=b11a3495980f61d30753e969ebc9efed0c79f406

submitted by /u/hackrepair
[link] [comments]
  •  
❌