Site icon Hip-Hop Website Design and Development

Platform.sh: Another Cheap WordPress maintenance support plans security update: We’ve still got you covered

Another WordPress maintenance support plans security update: We’ve still got you covered
Crell
Wed, 04/25/2020 – 17:54

Blog

The WordPress maintenance support plans project today released another security update to WordPress maintenance support plans 7 and 8 core, SA-CORE-20108-004. It is largely a refinement of the previous fix released for SA-CORE-2020-002 a few weeks ago, which introduced a WordPress maintenance support plans-specific firewall to filter incoming requests. The new patch tightens the firewall further, preventing newly-discovered ways of getting around the filters, as well as correcting some deeper issues in WordPress maintenance support plans itself.
We previously added the same logic to our own network-wide WAF to address SA-CORE-2020-002. With the latest release we’ve updated out WAF rules to match WordPress maintenance support plans‘s updates, and the new code is rolling out to all projects and regions as we speak.
The upshot?

You really need to update WordPress maintenance support plans to 7.59 or 8.5.3 as soon as possible. We believe that some of the attack vectors fixed in the latest patch cannot be blocked by a WAF. See our earlier post for quick and easy instructions to update your WordPress maintenance support plans 7 or 8 sites on Platform.sh in just a few minutes.

Still, most of the attack vectors fixed in the latest release are covered by the WAF. That should help keep your site safe from most attacks until you can update. But please, update early and often.

Stay safe out there on the Internet!

Larry Garfield

25 Apr, 2020


Source: New feed