Site icon Astra Security Blog

Monthly WordPress Security Roundup [August 2020]

Monthly WordPress Security Roundup August 2020

Hello everyone, it’s Kanishk from Astra Security. This is another edition of the Monthly WordPress Security Roundup for August 2020. Today we’ll discuss the core changes in the new WordPress 5.5 updates, recent vulnerabilities found in WP plugins and themes, and some other security issues. So, let’s get straight into the news.

WordPress rolls out version 5.5

On 11th August, WordPress rolled out its latest version 5.5 with the changes to its block editor interface (1500+), enhancements and feature requests (150+), bug fixes (300+), and more. The update also added a new feature called ‘Automatic updates’ for themes and plugins and suspended a couple of themes due to violations of WP theme guidelines.

We’ve also seen many publishers complaining about some unexpected behaviors after updating to WordPress 5.5. You can check this article on how to find and fix them.

Whereas, this month, no WordPress core security vulnerabilities were disclosed.

A new feature of auto-updates for updating themes and plugins:

The newly introduced ‘Automatic updates’ feature allows site owners to enable auto-updates for individual plugins and themes. This will help in improving the site security and functionality by shortening the time of doing manual updates for each plugin or theme. Many of the 455 million websites powered by WordPress still run vulnerable plugin versions for weeks or even months after the release of security patches. This feature is expected to reduce that number and prevent the sites from being hacked. 

The Automatic updates feature will be disabled by default, but you can enable it by going to Plugins section in your WP menu and click on Enable auto-updates as shown in below image:

UI changes for block editor:

WordPress 5.5 included 1500+ changes to the block editor user interface “in the hope of simplifying iconography, color palette, focus, and general interface.” For more info, check here

WordPress themes suspended:

WordPress has penalized the WPAstra theme which is a first non-default WordPress theme that crossed over 1 Million installs mark. This temporary suspension was enforced due to a violation of the WP theme review guidelines. Similar to this case, the Zerif Lite theme was also suspended. Both the themes were found injecting affiliate links into their theme code that lead to a said temporary suspension. 

Get the ultimate WordPress security checklist with 300+ test parameters

Vulnerabilities discovered in WordPress themes and plugins

This month, a lot of critical vulnerabilities were discovered and patched in the WordPress plugins, and themes. Many of these plugins and themes are quite popular with WordPress website owners and there is a strong possibility you might be using one.

Here are those:

1. Newsletter plugin 

2. Divi Theme, Extra Theme, and Divi Builder plugin (by Elegant Themes)

3. Facebook Chat Plugin

4. Quiz and Survey Master plugin

5. Advanced Access Manager

6. TinyMCE Editor

7. Discount Rules for WooCommerce

8. WooCommerce extension NAB Transact

Websites that are running on Astra Security’ Firewall are already protected from XSS, RCE, PHP object injection, arbitrary file upload & deletion, authorization bypass, and SQL injection attacks against such vulnerabilites.

A Tip: “Earlier this month cPanel and WebHost Manager (WHM) users began reporting a targeted phishing email campaign with an email subject of “cPanel Urgent Update Request” that was pretending to be a security advisory from the company. This fake advisory stated that updates had been released to fix “security concerns” in cPanel and WHM software versions 88.0.3+, 86.0.21+, and 78.0.49+, and recommends all users install the updates.” (Source)

That does it for this month’s WordPress Security Roundup. Stay safe from any unanticipated attack and be aware of the security vulnerabilities and latest patches. From all of us here at Astra Security, have a great month ahead and we’ll catch you up next time.

Astra Security Suite – WordPress Security Plugin Can Help Secure Your Site

Astra Security Suite, WordPress security plugin, is the go-to security suite for your WordPress website. With Astra Security Suite, you don’t have to worry about any malware, credit card hack, SQLi, XSS, SEO Spam, comments spam, brute force & 100+ types of threats. This means you can get rid of other security plugins & let Astra Security take care of it all.

Exit mobile version