Wooassist

Assistance for Your Woocommerce Store

  • How it Works
  • Pricing
  • Services
    • Site Maintenance
    • AI SEO and Content Marketing
  • Blog
    • How-To Articles
    • Code Snippets
    • SEO For E-Commerce
    • Theme and Plugin Reviews
    • Wooassist News
    • WordPress/WooCommerce News
    • Interviews
  • About Us
  • Contact
You are here: Home / Archives for WordPress/WooCommerce News

Orbit Fox by ThemeIsle Plugin Patched for Critical Vulnerabilities

January 14, 2021 By John Leave a Comment

The plugin Orbit Fox by ThemeIsle, a multi-functionality plugin installed on over 400,000 sites, has been found to carry two critical vulnerabilities. The vulnerabilities can potentially allow attackers to take over a WordPress website or inject malicious JavaScript into posts.

These are critical severity vulnerabilities and so have been addressed and patched urgently. With that, we strongly recommend updating to the patched version, 2.10.3, immediately if you have the plugin installe on your website.

For more information, please check the official public release.


If you have questions, don’t hesitate to contact our support team.

Filed Under: WordPress/WooCommerce News

Contact Form 7 Critical Vulnerability in File Upload Functionality

December 18, 2020 By John Leave a Comment

A security update has been released for the plugin, Contact Form 7, one of the most popular WordPress plugins with more than 5 million users.

The security update is meant to address a vulnerability with the file upload functionality in Contact Form 7. While the vulnerability itself is not easily exploitable, but with the popularity, it may be inevitable for attackers to target this vulnerability.

We strongly recommend an immediate update to version 5.3.2 to ensure your website is kept secure. If you aren’t using the file upload functionality, this issue doesn’t apply but it is still recommended to keep the plugin updated.

For more information, please check the official public release.


If you have questions, don’t hesitate to contact our support team.

Filed Under: WordPress/WooCommerce News

PageLayer Plugin Vulnerability Affects Over 200,000 WordPress Sites

December 13, 2020 By John Leave a Comment

Two reflected Cross-Site Scripting (XSS) vulnerabilities were found on the plugin PageLayer which is installed on over 200,000 sites. This is a critical issue as it could allow an attacker to take over a vulnerable WordPress site.

These vulnerabilities have been fully patched in version 1.3.5 and we strongly recommend all users update to the latest version.

For more information, please check the official public release.


If you have questions, don’t hesitate to contact our support team.

Filed Under: WordPress/WooCommerce News

Outdated WPBakery Plugin Critical Security Risk to Millions of Sites

October 8, 2020 By John Leave a Comment

The popular page-builder plugin WPBakery, installed in over 4 million websites, was discovered to host a critical flaw that allowed for attackers with contributor-level or above permissions, to inject malicious JavaScript in posts.

After a long period of patch development by the plugin team, a working patch was finally released on September 24, 2020.

We highly recommend updating to the latest version immediately (version 6.4.1 or higher). Simultaneously, we also recommend double-checking your website user list to make sure that no untrusted contributor-level or higher accounts have made their way inside.

For more information, please check the official public release.


If you have questions, don’t hesitate to contact our support team.

Filed Under: WordPress/WooCommerce News

WordPress Websites Security Breach – Outbreak of Malicious File Attacks

September 7, 2020 By John Leave a Comment

We are seeing a disturbing trend emerging from the WordPress community in the past few days and that is an upsurge of reported security breaches. We strongly recommend website admins to perform a security scan of their websites right now and address issues if any.

The clean-up requests we’ve received have surged and here are just some of the scan reports we’ve received:

Security report from wordfence scan 1
Security report from wordfence scan 2
Security report from wordfence scan 3
Wordfence blocked attacks report

One of the likely culprits for these breaches is the recently discovered critical security flaw with the WP File Manager plugin. Read the reports here:

https://arstechnica.com/information-technology/2020/09/hackers-are-exploiting-a-critical-flaw-affecting-350000-wordpress-sites/

https://www.techradar.com/news/millions-of-wordpress-sites-targeted-using-major-security-flaw

In any case, this is the most widespread breach we’ve seen over the years and should not be taken lightly.

Even if you do not have the WP File Manager plugin installed, we strongly recommend an immediate scan of your websites using Wordfence or any similar security plugin. And clean up issues ASAP if any are found.


If you have any questions or need assistance, don’t hesitate to contact our support team.

Secure your WordPress website

Filed Under: WordPress/WooCommerce News

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • Next Page »
Let us support your online store so you can manage your business

Get started today

Get 2 Hours of FREE SUPPORT

We are so confident that you will love our services that we will give you your first 4 hours at a 50% discount

That’s 4 hours for only $75

BUY NOW

Free eBook

5 Things Every Online Store Can Fix On Their Website In The Next Week To Increase Sales

Quick Links

  • How it Works
  • Pricing
  • Blog
  • Contact
  • About Wooassist
  • My Account
  • Checkout
  • Privacy Policy
  • Cookie Policy
  • Terms and Conditions

Wooassist

Australia:
59 Luke St.
Hemmant QLD 4174

Philippines:
San Miguel St.
Poblacion, Iligan City 9200

Connect

     

Copyright © 2026 · Wooassist

Yours FREE!

5 Things Every Online Store Can Fix On Their Website In The Next Week To Increase Sales