<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
    <channel>
        <title><![CDATA[WordPress Security Advisory]]></title>
        <description>RSS of WordPress Security Advisory</description>
        <pubDate>Sun, 17 May 2026 14:33:03 -0400</pubDate>
        <link>https://www.quicksilk.com</link>
                        <item>
            <title><![CDATA[8 Common Security Mistakes Made Using Open Source Software]]></title>
            <description><![CDATA[Businesses often incorporate open-source software without taking the &amp;quot;finishing&amp;quot; steps needed to adequately harden the server or software. We examine 8 of the most common security mistakes made.
]]></description>
            <pubDate>2020-02-08</pubDate>
            <link>https://www.quicksilk.com/blog/1/8-common-security-mistakes-using-open-source-software</link>
            <guid>https://www.quicksilk.com/blog/1/8-common-security-mistakes-using-open-source-software</guid>
                    </item>
                <item>
            <title><![CDATA[Security Threats in 5 of the Most Popular WordPress Plugins]]></title>
            <description><![CDATA[Do not presume that WordPress&amp;rsquo; most popular plugins are stable and secure. Even when flaws are identified and addressed by developers, it remains the website owner&amp;rsquo;s responsibility to install updates as soon as they become available.
]]></description>
            <pubDate>2019-09-27</pubDate>
            <link>https://www.quicksilk.com/blog/1/security-threats-in-5-of-the-most-popular-wordpress-plugins</link>
            <guid>https://www.quicksilk.com/blog/1/security-threats-in-5-of-the-most-popular-wordpress-plugins</guid>
                    </item>
                <item>
            <title><![CDATA[5 Key Signs Your WordPress Site is at Risk of Being Hacked [Infographic]]]></title>
            <description><![CDATA[Here are some of the factors that make your WordPress website more attractive to hackers, as well as indicators that a threat actor may already be trying to hack into your site.
]]></description>
            <pubDate>2019-07-20</pubDate>
            <link>https://www.quicksilk.com/blog/1/5-key-signs-your-wordpress-site-is-at-risk-of-being-hacked</link>
            <guid>https://www.quicksilk.com/blog/1/5-key-signs-your-wordpress-site-is-at-risk-of-being-hacked</guid>
                    </item>
                <item>
            <title><![CDATA[WordPress White Screen of Death (WSOD)]]></title>
            <description><![CDATA[WordPress&amp;#39;s new &amp;quot;white screen of death&amp;quot; security feature is scheduled for release in patch 5.1. Problem is, it may make WordPress sites more vulnerable.
]]></description>
            <pubDate>2019-02-19</pubDate>
            <link>https://www.quicksilk.com/blog/1/wordpress-white-screen-of-death</link>
            <guid>https://www.quicksilk.com/blog/1/wordpress-white-screen-of-death</guid>
                    </item>
                <item>
            <title><![CDATA[Giant Botnet Attacking WordPress Websites]]></title>
            <description><![CDATA[Recent news from the security world of WordPress is that a botnet of over 20,000 compromised WordPress websites is being used to attack other WordPress websites.
]]></description>
            <pubDate>2019-02-05</pubDate>
            <link>https://www.quicksilk.com/blog/1/massive-wordpress-botnet-attacking-wordpress-websites</link>
            <guid>https://www.quicksilk.com/blog/1/massive-wordpress-botnet-attacking-wordpress-websites</guid>
                    </item>
                <item>
            <title><![CDATA[Former Employee Hacks WPML Plugin]]></title>
            <description><![CDATA[A massively popular WordPress multilingual plugin was hacked by a former employee who sent a mass email warning of security vulnerabilities. The plugin &amp;mdash; WPML (or WP MultiLingual) &amp;mdash; is an extremely popular (+600,000 active installations) paid plugin.
]]></description>
            <pubDate>2019-01-29</pubDate>
            <link>https://www.quicksilk.com/blog/1/former-employee-hacks-wpml-wordpress-plugin</link>
            <guid>https://www.quicksilk.com/blog/1/former-employee-hacks-wpml-wordpress-plugin</guid>
                    </item>
                <item>
            <title><![CDATA[AMP Vulnerability Provides WP Admin Access]]></title>
            <description><![CDATA[Recently, AMP for WP was subjected to a massive security vulnerability that put all +100,000 of its users at risk&amp;nbsp; &amp;mdash;&amp;nbsp; you NEED to update your plugin ASAP!
]]></description>
            <pubDate>2019-01-22</pubDate>
            <link>https://www.quicksilk.com/blog/1/amp-wp-vulnerability-gave-admin-access-to-wordpress</link>
            <guid>https://www.quicksilk.com/blog/1/amp-wp-vulnerability-gave-admin-access-to-wordpress</guid>
                    </item>
                <item>
            <title><![CDATA[WordPress Attacks Triple in 2018]]></title>
            <description><![CDATA[To say that WordPress is popular would be an understatement. Over 30% of websites trust WordPress as their CMS. But, what happens when the world&amp;#39;s most popular CMS isn&amp;#39;t safe?
]]></description>
            <pubDate>2019-01-15</pubDate>
            <link>https://www.quicksilk.com/blog/1/wordpress-attacks-triple-in-2018</link>
            <guid>https://www.quicksilk.com/blog/1/wordpress-attacks-triple-in-2018</guid>
                    </item>
                <item>
            <title><![CDATA[WordPress Plugins: AMP &amp; GDPR Vulnerabilities]]></title>
            <description><![CDATA[The AMP and GDPR plugin vulnerabilities discuss in this blog post have Ajax hook issues. Anyone with these plugins installed needs to update their website
]]></description>
            <pubDate>2019-01-03</pubDate>
            <link>https://www.quicksilk.com/blog/1/AMP-GDPR-wordpress-plugin-vulnerabilities</link>
            <guid>https://www.quicksilk.com/blog/1/AMP-GDPR-wordpress-plugin-vulnerabilities</guid>
                    </item>
                <item>
            <title><![CDATA[jQuery File Upload Plugin Vulnerability]]></title>
            <description><![CDATA[The big news this week is the discovery of an exploit in the jQuery File Upload plugin - the second most downloaded jQuery-related project on Github
]]></description>
            <pubDate>2018-12-20</pubDate>
            <link>https://www.quicksilk.com/blog/1/jQuery-file-upload-plugin</link>
            <guid>https://www.quicksilk.com/blog/1/jQuery-file-upload-plugin</guid>
                    </item>
                <item>
            <title><![CDATA[PHP 5.X EOL &amp;amp; Your WordPress Website]]></title>
            <description><![CDATA[On December 31st, 2018 the PHP 5.x branch will stop receiving security updates. You need to update now, if your website is running on this version
]]></description>
            <pubDate>2018-12-11</pubDate>
            <link>https://www.quicksilk.com/blog/1/php5-end-of-life</link>
            <guid>https://www.quicksilk.com/blog/1/php5-end-of-life</guid>
                    </item>
                <item>
            <title><![CDATA[WordPress Plugin Security History]]></title>
            <description><![CDATA[We shift gears in this blog post and talk a little about the history of WordPress&amp;#39;s ongoing plugin problems, to better appreciate WordPress&amp;#39;s overall vulnerability issues
]]></description>
            <pubDate>2018-12-04</pubDate>
            <link>https://www.quicksilk.com/blog/1/wordpress-plugin-security-history</link>
            <guid>https://www.quicksilk.com/blog/1/wordpress-plugin-security-history</guid>
                    </item>
                <item>
            <title><![CDATA[How Hackers Target WordPress Websites]]></title>
            <description><![CDATA[WordPress has a ton of weaknesses. So, it&amp;#39;s no surprise that WordPress websites have become a haven for hackers to inject malicious material into.
]]></description>
            <pubDate>2018-10-23</pubDate>
            <link>https://www.quicksilk.com/blog/1/how-to-make-wordpress-secure-from-hackers</link>
            <guid>https://www.quicksilk.com/blog/1/how-to-make-wordpress-secure-from-hackers</guid>
                    </item>
                <item>
            <title><![CDATA[United Nations WordPress Website Disclosure Vulnerability]]></title>
            <description><![CDATA[WordPress disclosure vulnerabilities on a United Nations website provide public access to CVs from job applicants. Despite receiving a private report on the issue the organization had yet to plug the leak.
]]></description>
            <pubDate>2018-10-10</pubDate>
            <link>https://www.quicksilk.com/blog/1/united-nations-website-wordpress-disclosure-vulnerability</link>
            <guid>https://www.quicksilk.com/blog/1/united-nations-website-wordpress-disclosure-vulnerability</guid>
                    </item>
                <item>
            <title><![CDATA[Colossal WordPress Redirect Campaign Targets Vulnerable Websites]]></title>
            <description><![CDATA[A new vulnerability impacting a massive number of WordPress has been found; It redirects site visitors to phishing sites.
]]></description>
            <pubDate>2018-08-23</pubDate>
            <link>https://www.quicksilk.com/blog/1/massive-wordpress-redirect-malware-campaign</link>
            <guid>https://www.quicksilk.com/blog/1/massive-wordpress-redirect-malware-campaign</guid>
                    </item>
                <item>
            <title><![CDATA[Drupal Hit With RCE Vulnerability]]></title>
            <description><![CDATA[A security team discovered a critical vulnerability in the Drupal system. The Remote Code Execution allow hackers to trigger code across networks and platforms
]]></description>
            <pubDate>2018-08-02</pubDate>
            <link>https://www.quicksilk.com/blog/1/drupalgeddon-rce-vulnerability</link>
            <guid>https://www.quicksilk.com/blog/1/drupalgeddon-rce-vulnerability</guid>
                    </item>
                <item>
            <title><![CDATA[WooCommerce Plugin Problems]]></title>
            <description><![CDATA[WordPress just uncovered more plugins with vulnerabilities. This time, the plugins are related directly to WooCommerce, and all of them come from the same publisher - MULTIDOT Inc.
]]></description>
            <pubDate>2018-07-31</pubDate>
            <link>https://www.quicksilk.com/blog/1/woocommerce-wordpress-plugin-vulnerabilities</link>
            <guid>https://www.quicksilk.com/blog/1/woocommerce-wordpress-plugin-vulnerabilities</guid>
                    </item>
                <item>
            <title><![CDATA[10,000+ Hacked WordPress Sites]]></title>
            <description><![CDATA[&amp;nbsp;Check Point Research recently reported more than 10,000 WordPress sites were compromised in a well-planned &amp;quot;malvertisement&amp;quot; attack.
]]></description>
            <pubDate>2018-07-26</pubDate>
            <link>https://www.quicksilk.com/blog/1/checkpoint-10000-hacked-wordpress-sites</link>
            <guid>https://www.quicksilk.com/blog/1/checkpoint-10000-hacked-wordpress-sites</guid>
                    </item>
                <item>
            <title><![CDATA[WordPress Hackers: Mining Crypto Gold]]></title>
            <description><![CDATA[Typically, cryptojackers will infect a host website with packets containing malware that use a visitor&amp;rsquo;s browser to download themselves onto host computers and infect them with malware.
]]></description>
            <pubDate>2018-07-24</pubDate>
            <link>https://www.quicksilk.com/blog/1/wordpress-hackers-cryptojacking</link>
            <guid>https://www.quicksilk.com/blog/1/wordpress-hackers-cryptojacking</guid>
                    </item>
                <item>
            <title><![CDATA[BabaYaga: Self-Healing Malware]]></title>
            <description><![CDATA[Recently, a powerful new Malware was discovered infiltrating WordPress, Joomla, and Drupal websites; it&amp;#39;s called Baba Yaga.
]]></description>
            <pubDate>2018-07-17</pubDate>
            <link>https://www.quicksilk.com/blog/1/wordpress-security-babayaga</link>
            <guid>https://www.quicksilk.com/blog/1/wordpress-security-babayaga</guid>
                    </item>
                <item>
            <title><![CDATA[Vulnerabilities in WordPress Core]]></title>
            <description><![CDATA[WordPress is getting a lot of heat for being unresponsive to potential flaws - especially when it comes to flaws built into the core of WordPress.
]]></description>
            <pubDate>2018-07-12</pubDate>
            <link>https://www.quicksilk.com/blog/1/vulnerabilities-in-wordpress-core</link>
            <guid>https://www.quicksilk.com/blog/1/vulnerabilities-in-wordpress-core</guid>
                    </item>
                <item>
            <title><![CDATA[A History of WordPress Security]]></title>
            <description><![CDATA[Let&amp;#39;s have a glance at the history of security and WordPress (spoiler alert -- it&amp;#39;s not pretty.)
]]></description>
            <pubDate>2018-07-05</pubDate>
            <link>https://www.quicksilk.com/blog/1/history-wordpress-security-issues</link>
            <guid>https://www.quicksilk.com/blog/1/history-wordpress-security-issues</guid>
                    </item>
                <item>
            <title><![CDATA[WordPress Security: A Blog Series]]></title>
            <description><![CDATA[WordPress has a storied history of security problems dating back to 2008 and security stats that you&amp;rsquo;d think would make this software a non-starter, in today&amp;rsquo;s increasingly security conscious world.
]]></description>
            <pubDate>2018-07-03</pubDate>
            <link>https://www.quicksilk.com/blog/1/wordpress-security-blog</link>
            <guid>https://www.quicksilk.com/blog/1/wordpress-security-blog</guid>
                    </item>
                    </channel>
</rss>
