WordPress Core and Plugin Update Needed (Updated)

wp-vulnerabilityfixed
Sucuri has recently announced the discovery of a XSS vulnerability that affects multiple plugins. At least 15 popular plugins are affected including Jetpack, WordPress SEO, Gravity Forms and more. At the time of the vulnerability disclosure the majority of the plugin authors have launched new versions of their plugins fixing the issues. The next day a security release (4.1.2) of the WordPress core itself was released.  It is reported to fix several security issues too.
Continue reading “WordPress Core and Plugin Update Needed (Updated)”

Protected Against a Vulnerability in WordPress SEO by Yoast Plugin

idealno

A security vulnerability in the famous WordPress SEO plugin by Yoast was just reported by the WP Scan Vulnerability Database website. Our security specialists have immediately reacted to protect all SiteGround customers and have crafted and added new security rules to our WAF (web application firewall). This means that we will actively filter any possible incoming hacking attempts that try to exploit the vulnerability.

Although Yoast SEO users are protected on our servers we still highly recommend to anyone using the plugin to update it to the latest version 1.7.4. This latest release is not vulnerable to the reported Blind SQL Injection.

[subscribe_cta]

Client Survey 2014

lead

We could not have wrapped up last year without collecting feedback from our customers via the traditional client satisfaction survey. We want to thank all of you who took the time to fill it out and answer our questions. The results once again managed to exceed our expectations. We already knew that 2014 was a record year for us in terms of number of new customers added, however with growth at such fast rate it can be challenging to maintain service quality. That is why we were very excited to see that not only the number of the customers has increased, but we managed to keep, and even improve, the amazing satisfaction levels from the previous years. Below I will share a summary of the findings from the 2014 survey responses.
Continue reading “Client Survey 2014”

Hosting WordSesh 2014 – Challenge Accepted!

wordsesh

Few months ago WordSesh organizers contacted us asking if we would host their online conference. Needless to say, we got quite excited to help this great WordPress event happen. The project was very interesting from a technical point of view too, as we needed to ensure that thousands of visitors will be able to follow the free live stream for 24 hours without any downtime or other technical issue.
Continue reading “Hosting WordSesh 2014 – Challenge Accepted!”

Our WordPress sites now on PHP 5.5 and above!

wp-to-php55

PHP 8.4: Stay Updated! 🚀 Check out our latest blog post to explore the newest features and enhancements in PHP 8.4.


During the past few weeks, we have undertaken a serious campaign to increase the number of the WordPress sites that use more recent PHP versions on our servers. As a result, now more than 90% of all our WordPress sites are on PHP 5.5 or higher. As scary as such a massive update may sound when you have more than 100,000 WordPress instances, it turned out to be a real success.

Continue reading “Our WordPress sites now on PHP 5.5 and above!”

WordCamping with Angels

blog11

SiteGround was one of the sponsors of the Los Angeles WordCamp 2014 and I was thrilled to be part of the team attending the event. We spent three extremely exciting and rewarding days together with more than 300 other WordPress enthusiasts in the City of Angels. We also had the chance to be involved in many of the great #WCLAX activities including the beginner’s workshop, the selfie scavenger hunt and the contribution Sunday.
Continue reading “WordCamping with Angels”

SiteGround Customers Protected Against Serious VirtueMart Vulnerability!

vulnerability

A serious vulnerability in the popular Joomla extension VirtueMart was discovered by the awesome people at Sucuri during one of their regular security audits. It allows regular users to gain Super Administrator privileges to a Joomla website with VirtueMart 2.6.8c and below installed on it. If a site with an older version of VirtueMart allows user registration (which is a default mode in VirtueMart) it can be hacked through this vulnerability.
Continue reading “SiteGround Customers Protected Against Serious VirtueMart Vulnerability!”

WordPress & Drupal Vulnerability? –  Keep calm and update!

drupal-wp-vuln

Yesterday, a serious vulnerability in the PHP XML parser used by WordPress and Drupal was announced. After some great collaboration between the core developers of those applications, new versions that address the issue were released for both WordPress and Drupal. We, at SiteGround, are proactively addressing the issue too:
Continue reading “WordPress & Drupal Vulnerability? –  Keep calm and update!”

TimThumb Critical Vulnerability Fixed on SiteGround Servers

header

Another serious security issue was reported earlier today within one of the popular WordPress plugins for managing thumbnails – TimThumb. This plugin already has a history of causing security issues in the past with which we dealt with. The current vulnerability allows the attacker to gain unauthorised access to your hosting account and even execute shell commands on it. Needless to say, this is not something we can allow to happen.

Our security team has reacted immediatelly after the vulnerability was disclosed. We have applied a patch in our in-house system to protect all our customers from getting hacked through TimThumb. Currently, if you’re hosted on SiteGround, you will be protected against hacking attempts that try to utilise this problem.

However, we strongly recommend that you switch plugins or update TimThumb as soon as new version is released.

[subscribe_cta]