WordPress Security Plugin Protects Website From Dangerous Hacker Known as WordPress Security Plugin
Experts praised the update for closing a vulnerability that allowed attackers to exploit the very software installed to prevent attackers from exploiting the software.
CYBERSPACE — Website administrators worldwide breathed a cautious sigh of relief Thursday after updating two WordPress plugins that had reportedly introduced the exciting new security feature of being security problems themselves.
Genesis Blocks Pro released version 3.1.11 to fix a stored cross-site scripting vulnerability in its Sharing block—a tool specifically designed to help website visitors share content, including, until recently, malicious JavaScript.
“We wanted users to share articles on Facebook, LinkedIn, and X,” said a Genesis spokesperson. “Unfortunately, they could also share complete administrative control of your website.”
Defender Pro also announced “security improvements” to its Hub Connector, assuring customers that the plugin protecting their WordPress dashboard from unauthorized access would now spend slightly less time creating opportunities for unauthorized access.
The updates are part of WordPress’s celebrated security model:
- Install a plugin to protect WordPress.
- Install another plugin to enhance the first plugin.
- Discover a vulnerability in both plugins.
- Update everything.
- Watch the update break the contact form.
- Restore yesterday’s backup.
- Reinstall the vulnerable versions.
- Receive an email titled “Your Site Is Safe!”
Website owner Mark Ellis confirmed he updated Genesis Blocks Pro immediately after learning its Sharing block contained stored XSS.
“I don’t even use the Sharing block,” Ellis said. “But apparently the plugin wanted to make sure hackers could.”
Security professionals emphasized that administrators should install the patches as soon as possible, but only after creating a full backup, testing the updates on a staging environment, checking PHP compatibility, clearing four separate caches, regenerating CSS files, resaving permalinks, and sacrificing a junior developer beneath the waning moon.
At press time, WordPress administrators were celebrating the successful security updates by discovering that every icon on the website had disappeared.
