Web Flaws and Vulnerabilities

iThemes Security < 7.9.1 – Hide Backend ByPass

April 21, 2021 0 comments

iThemes Security is a know security plugin in the WordPress community since years. One week ago we discovered a security issue in their “Hide Backend” module, leaking the hidden login page. This ByPass Vulnerability has been patched in 7.9.1, update it if you’re using it.

Read more
SecuPress

SecuPress v2.0 aka Python

March 22, 2021 0 comments

SecuPress 2.0 is here! As always, after a while without updating, this 2.0 is finally here. The goal of this version is to open the door to future versions 2.x because this change of major version number means that all the functionalities will be reviewed one by one in order to be improved in every […]

Read more
Secure WordPress

Reveal It, Share Your Messages Safely

September 24, 2020 0 comments

When I want to share sensitive data or when I ask a client to share sensitive data, I use a service to do the job, a service called RevealIt.me. This free service was made by a an ex-coworker, it works fine, I trust him so everything was OK. Then one day on Slack someone (also […]

Read more
Web Flaws and Vulnerabilities

WordPress Security, a response to Yoast

June 10, 2020 0 comments

This post is a response to Yoast at https://yoast.com/wordpress-security/. Yoast is a SEO company in the WordPress ecosystem since 10 years now. They are professionals without any doubts, but for SEO purposes, not for Security. After my read on that particular and recent post from them, I had to answer and fix the issues. Some […]

Read more