Wordfence Profile Banner
Wordfence Profile
Wordfence

@wordfence

8,278
Followers
33
Following
429
Media
3,532
Statuses

Protecting over 4 million WordPress sites. Get Wordfence at #WordPress #Security

Seattle, WA
Joined June 2012
Don't wanna be here? Send us removal request.
@wordfence
Wordfence
10 months
Earn up to $10,000 for finding Vulnerabilities in WordPress Software. For the next 20 days, we have added a 6.25X multiplier to all bug bounties, starting NOW. These are some of the highest payouts for finding vulnerabilities in the history of WordPress. If you're a vulnerability
5
32
270
@wordfence
Wordfence
3 years
(New Blog Post) PSA: Widespread Remote Working Scam Underway
4
25
154
@wordfence
Wordfence
8 years
Updated a highly cited post (WSJ this week). Chrome & Google have done a fine job of mitigating data URL phishing.
3
42
118
@wordfence
Wordfence
3 years
We're incredibly excited to announce the launch of two new products, Wordfence Care and Wordfence Response. Check out our fun animation below which explains our newly expanded product lineup. You can find the full announcement on our blog:
12
16
77
@wordfence
Wordfence
3 years
Effective immediately, Wordfence has deployed real-time threat intelligence (normally a paid only feature) to over 8,000 sites running the Free version of Wordfence on the .UA top-level domain. This will auto-update - no site change or work needed. Also:
3
26
56
@wordfence
Wordfence
3 years
Wordfence in Partnership with Far Away Friends just completed a project to provide sustainable solar powered light and electricity to a school campus in Uganda. To read the full story about this amazing project and see a short video, please visit
3
11
50
@wordfence
Wordfence
4 years
An update: @elemntor has released Pro version 2.9.4, and our threat intelligence team has verified it fixes the authenticated file upload vulnerability. Please ensure you update your Elementor Pro plugins to 2.9.4. Kudos to Elementor for the fast fix.
@wordfence
Wordfence
4 years
Combined Attack on Elementor Pro and Ultimate Addons for Elementor Puts 1 Million Sites at Risk
3
24
28
2
24
40
@wordfence
Wordfence
4 years
This afternoon, the official Trump campaign website was hacked and defaced. We have examined the site configuration and possible intrusion vectors, and our team has published what we know about this compromise, and lessons learned.
0
21
36
@wordfence
Wordfence
2 years
We've officially launched Wordfence Intelligence Community Edition: an entirely free vulnerability database API and web interface for commercial use by hosting companies, security organizations, threat analysts, security researchers, and the WordPress user community.
4
14
34
@wordfence
Wordfence
4 years
Moments ago, the Wordfence Threat Intelligence team published details about a Cross-Site Scripting vulnerability discovered in the WPBakery plugin which is installed on over 4 million sites.
1
30
38
@wordfence
Wordfence
7 years
Breaking: Aggressive WordPress Brute Force Attack Campaign Started Today, 3am UTC
Tweet media one
2
44
28
@wordfence
Wordfence
3 years
Today, we are excited to announce that Wordfence is authorized by the Common Vulnerabilities and Exposures (CVE®) Program as a CNA, or CVE Numbering Authority. Find out what this means for our customers on the official Wordfence blog.
4
12
35
@wordfence
Wordfence
2 years
Our new product, Wordfence Intelligence, is officially here. Check out our animation to explore our biggest, most exciting product yet. For more information, visit:
2
6
32
@wordfence
Wordfence
3 years
GoDaddy breached. Affects 1.2M customers. More on this shortly.
0
28
30
@wordfence
Wordfence
3 years
The Wordfence website will be undergoing maintenance this morning starting at 7am Pacific, 10am Eastern and 3pm UTC/GMT. This window starts in 30 mins and will last 1 to 2 hours. Plugins are unaffected. Updates will be provided here. Get ready for a major announcement.
3
4
30
@wordfence
Wordfence
4 years
Over the weekend, two malicious commits were pushed to a development version of PHP. Moments ago, our Threat Intelligence team published an analysis of what happened & what this means to WordPress.
0
17
29
@wordfence
Wordfence
4 years
Moments ago, the Wordfence Threat Intelligence team posted details of a critical zero-day file upload vulnerability patched in the WooCommerce Upload Files plugin. This vulnerability allowed Remote Code Execution and site takeover.
0
18
30
@wordfence
Wordfence
1 year
So we just launched Wordfence CLI, an absolutely killer high performance command line malware scanner from #WCUS a few seconds ago. Come say hi if you’re in the room. This is a game changer for devs, hosting providers and anyone scripting #wordpress malware scanning at scale.
Tweet media one
3
6
29
@wordfence
Wordfence
4 years
Our Threat Intelligence Team just published details of numerous Cross-Site Scripting vulnerabilities discovered in the Elementor plugin, installed on over 7 million WordPress sites. Details on the official Wordfence blog.
2
20
28
@wordfence
Wordfence
4 years
One day after releasing WordPress 5.5.2, a security and maintenance release, the WordPress core team has released WordPress 5.5.3, an emergency release. What happened and what this means for your sites on the official Wordfence blog.
0
26
28
@wordfence
Wordfence
7 years
Massive Cryptomining Campaign Targeting WordPress Sites
1
34
24
@wordfence
Wordfence
4 years
Combined Attack on Elementor Pro and Ultimate Addons for Elementor Puts 1 Million Sites at Risk
3
24
28
@wordfence
Wordfence
3 years
Most commonly used work phrase in 2021: You’re on mute.
0
5
24
@wordfence
Wordfence
1 year
Arrived in DC. In case you’re at #WCUS and don’t know what the Wordfence founders look like, this is Kerry and me. Selfie in a mirror this evening. Please say hi if you see us, or stop by the Wordfence booth!! 😁
Tweet media one
1
0
26
@wordfence
Wordfence
4 years
Moments ago, we published details about a critical vulnerability discovered in two themes by Elegant Themes, Divi and Extra, as well as the Divi Builder plugin. Combined, these products are installed on an estimated 700,000 sites. #divi
0
18
26
@wordfence
Wordfence
3 years
Our customers LOVE Wordfence Care & Wordfence Response! Congrats everyone who has upgraded from Premium, or bought a new Care or Response license and is benefiting from unlimited hands-on support, incident response, and the Wordfence Team monitoring your site security. 🔒🥳🎈🎊
2
6
22
@wordfence
Wordfence
3 years
TSOHost also breached. More on the Wordfence blog shortly. Very similar announcement to GoDaddy and owned by them. Investigating other related hosts now. DM @ramuelgall to send us a lead. Thanks.
Tweet media one
2
13
22
@wordfence
Wordfence
4 years
WordPress 5.5 is scheduled to be released next week, including a new feature that allows site owners to enable automatic updates of plugins & themes whenever a new version is released. Should you use this feature? We've detailed our recommendations.
2
15
23
@wordfence
Wordfence
5 years
Good morning, WordCamp Minneapolis! We're ready to teach you lock picking and talk WordPress security. Stop by and say hi to Tim, Scott and Kathy at our table! @WordCampMpls #WCMSP
Tweet media one
1
4
22
@wordfence
Wordfence
1 year
We've been made aware that a WAF Rule we deployed today has unfortunately caused some sites to get a 500 error. We've implemented a fix on our side to prevent the issue from occurring on sites that have not yet been updated and we are continuing to work on a fix for sites that
7
10
22
@wordfence
Wordfence
5 years
We're ready for you, WordCamp NYC! Come meet some of the brightest minds in WordPress security at our sponsor booth. Meet @scottbisker , @poutine_hero , @infosecchloe , and @tcan1337 . We've got lock picking, great swag, & answers to your security questions. #WCNYC @wordcampNYC
Tweet media one
1
3
23
@wordfence
Wordfence
3 years
Moments ago, the Wordfence Threat Intelligence Team published details of patched vulnerabilities affecting more than 15 of the most popular addon plugins for Elementor, which are collectively installed on over 3.5 million sites.
0
10
22
@wordfence
Wordfence
2 years
We've compiled the most common exploit attempt types broken down by the firewall rule used to block the attempt. 1. SQL Injection 2. wp-config.php Traversal 3. Directory Traversal 4. XSS 5. Local File Inclusion Do any of them surprise you? #WordPress #cybersecuritytips #SQLI
Tweet media one
3
8
22
@wordfence
Wordfence
4 years
Earlier today, a security patch was released for arguably the most widely used WordPress plugin, Contact Form 7. Our analysis of this file upload vulnerability is on the official Wordfence blog.
1
25
23
@wordfence
Wordfence
7 years
New Feature Protects Against Password Leak Attacks
2
14
21
@wordfence
Wordfence
2 years
WordPress 6.0.3 is now available! Our Threat Intelligence team is assessing the impact but we highly recommend ensuring your site has been updated if you haven’t already done so.
2
3
19
@wordfence
Wordfence
8 years
Read from the bottom. #wordpress #REST API exploit #fail . #WP #security
Tweet media one
2
6
21
@wordfence
Wordfence
2 years
Update your Chrome browsers immediately. A new release just went out to fix a zero day vulnerability. An exploit for this vulnerability exists in the wild. Update Chrome now.
0
17
18
@wordfence
Wordfence
3 years
Severe vulnerabilities have been patched in Simple 301 Redirects by BetterLinks, a plugin used by over 300,000 WordPress sites. Some of these vulnerabilities made it possible for unauthenticated attackers to redirect all of a site’s visitors.
0
12
19
@wordfence
Wordfence
5 years
WordCamp Harare in Zimbabwe took place this weekend, too. Mark Maunder did a livestream video with WC Harare and visited a few sponsor booths at WordCamp US including Yoast. Watch for our video coming soon! #WCUS #WCHRE @mmaunder @wordcampharare @yoast
Tweet media one
2
6
21
@wordfence
Wordfence
4 years
We are seeing a dramatic rise in attacks against the vulnerability in the File Manager plugin found earlier this week. Today alone, as of 9AM Pacific Time, Wordfence has already recorded attacks against over 1 million sites.
1
24
22
@wordfence
Wordfence
8 months
We worked with Greg at @gregxsunday to create an awesome technical guide to hacking WordPress to discover vulnerabilities! You can earn money by submitting new vulnerabilities to the Wordfence Bug Bounty Program: 6.25x Bounties Right Now 🔥
@gregxsunday
Bug Bounty Reports Explained
8 months
WordPress powers about 40% of the websites today so finding a bug in it or in a popular plugin can have significant impact. In my latest video, I tell you how to start analyzing a WordPress plugin and the methods to monetize bugs that you will find Enjoy!
0
22
129
0
3
24
@wordfence
Wordfence
2 years
Our team responsibly disclosed two vulnerabilities in All In One SEO, a WordPress plugin installed on over 3M sites. We issued a firewall rule to protect against the more severe vulnerability, which is available to all Wordfence users as of 2/24.
Tweet media one
0
5
20
@wordfence
Wordfence
5 years
We've updated this post to confirm that Duplicator Pro installations are also affected by this vulnerability. We estimate about 170,000 WordPress sites are running Duplicator Pro; approximately150,000 of these sites have not been patched.
0
16
21
@wordfence
Wordfence
4 years
Our Threat Intelligence team found a vulnerability in the Contact Form 7 Style plugin installed on 50K+ sites. This vulnerability remains unpatched & the plugin is now closed. We've withheld full details, but we've shared steps to keep your site safe.
1
10
21
@wordfence
Wordfence
5 years
Here's a short clip from our Zoom chat with friends at @wordcampharare in Zimbabwe when we visited the @jetpack booth at @WordCampUS . We had much fun connecting WordPress users across continents; thanks to everyone who participated! The full video is coming soon. #WCUS #WCHRE
1
8
21
@wordfence
Wordfence
8 years
Massive increase in brute force #attacks on #wordpress sites during past 18 hours. Will exceed 60 day peak today by 25%. #security #wp
Tweet media one
0
21
16
@wordfence
Wordfence
7 years
Chrome and Firefox Phishing Attack Uses Domains Identical to Known Safe Sites #chrome #firefox #phishing
4
39
16
@wordfence
Wordfence
5 years
PSA: If you're one of the 4 million Elementor users, update ASAP as a cross-site scripting vulnerability was found in versions 2.8.4 and earlier; the proof of concept has been published by the researcher. (CVE-2020-8426) #pluginvulnerabilities #update #infosec
Tweet media one
0
13
20
@wordfence
Wordfence
5 years
We had a great time sponsoring WordCamp Orange County! Thanks to the organizers, the attendees, the speakers, and all of the volunteers who made this spectacular event possible! #wcoc @OCWordCamp
@SC_WordPress
Stephen Harvey - WP Evangelist🗣⛪
5 years
This is definitely a highlight of my #WCOC experience! Awesome finally meeting @mmaunder and @danmoen of @wordfence ... AND, getting to see @kathyzant is always a bonus too.🤩🤩🤩🤩🤩🤩🔐🔐🔐 #security
Tweet media one
1
2
16
2
1
20
@wordfence
Wordfence
3 years
On July 14, WooCommerce released a patch for a SQL Injection vulnerability that allowed unauthenticated attackers to access arbitrary data in a store’s database. Moments ago, the Wordfence Threat Intelligence team posted a deeper look at the vulnerability.
2
15
19
@wordfence
Wordfence
3 years
Just sent an urgent email to our WordPress security list about the log4j vulnerability with a bunch of resources. We're not blogging about it because it's not our wheelhouse, but I'm pasting the email here for our Java friends to help them get secure fast. This is Javageddon.
1
6
18
@wordfence
Wordfence
3 years
Sunset in the Salish Sea.
1
0
17
@wordfence
Wordfence
8 months
WordPress v6.4.3 released addressing two minor security concerns in Core. 1st patch secures file upload, mainly concerning to locked-down configurations. 2nd improves option storage sanitization. Both issues low-risk unless site installation is incomplete.
0
10
18
@wordfence
Wordfence
4 years
Our Threat Intelligence Team found a vulnerability in The Official Facebook Chat Plugin, used by 80,000 WP sites. This vulnerability allowed attackers to connect their own Facebook Messenger account to sites running the vulnerable plugin.
0
12
19
@wordfence
Wordfence
10 months
🚨Alert to all WordPress users! Beware of the latest phishing scam using fake CVE-2023-45124. This scheme lures users into installing a backdoor plugin. #WordPress #WP #CyberSecurity
Tweet media one
0
10
20
@wordfence
Wordfence
5 years
We're having a great time at WordCamp Kansas City this weekend, and we're excited about Jim Grant's @SimplyMediaKC WordPress security talk in 30 minutes. Will we see you there? @wordcampkc #wckc #wordcampkc
0
2
19
@wordfence
Wordfence
2 years
That’s a wrap on Black Hat 2022! A huge thanks to everyone who stopped by our booth to learn about our new product, Wordfence Intelligence. We look forward to helping make the online community safer. #blackhat2022 #BlackHat #WordPress
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
6
19
@wordfence
Wordfence
7 years
PSA: Replace Your SSL/TLS Certs by Symantec, Thawte, VeriSign, Equifax, GeoTrust and RapidSSL
0
19
18
@wordfence
Wordfence
8 years
Expect a WP core security update in the near future. A vuln in phpmailer that affects core was announced. #WP #wordpress #security #infosec
1
15
16
@wordfence
Wordfence
7 years
Three Plugins Backdoored in Supply Chain Attack
1
32
18
@wordfence
Wordfence
4 years
Our Threat Intelligence team discovered a vulnerability affecting over 2 million sites using the All in One SEO Pack plugin. We've included a proof of concept video explaining how this vulnerability could be exploited to take over a WordPress site.
0
18
18
@wordfence
Wordfence
3 years
WordPress 5.7.2 is a security patch for a Critical Object Injection vulnerability in PHPMailer, the component that WordPress uses to send emails by default. Moments ago, we posted an analysis of the risk presented by this vulnerability.
0
11
18
@wordfence
Wordfence
6 years
Using PHP 5 Becomes Dangerous in 2 Months
1
9
17
@wordfence
Wordfence
2 years
Wordfence film crew headed out to Ironman World Championships in St George to support Wordfence sponsored Marco Stichini. #ironman
Tweet media one
0
2
17
@wordfence
Wordfence
4 years
PHP 8.0 is set to be released on November 26, 2020, and WordPress site owners and developers may be in for a rough ride. Today, we take a look at what this means for your WordPress site on the official Wordfence blog.
0
13
18
@wordfence
Wordfence
5 years
Kathy Zant will be bringing The Hacking Mindset to WordCamp Seattle this weekend. This is not your average #WordPress #security talk; Kathy will show you how being proactive about security helps you overcome obstacles & become successful in all areas of business and life. #WCSEA
Tweet media one
2
6
18
@wordfence
Wordfence
3 years
XSS Vulnerability Patched in SEOPress Affects 100,000 sites. Flaw made it possible for an attacker to inject arbitrary web scripts on a vulnerable site which would execute anytime a user accessed the “All Posts” page. Details on the Wordfence blog:
1
11
18
@wordfence
Wordfence
4 years
Happening now on Wordfence Live: how does your website's speed & responsiveness affect your customer's experience? We're looking at the website speed measurement secrets you won't see anywhere else. Also, giving away swag you won't find anywhere else, too!
0
13
17
@wordfence
Wordfence
11 months
Wordfence launches Wordfence CLI 2.0.1 "Voodoo Child" -- Server vulnerability scanning at scale for free and commercial use, without limitations. Scan your entire fleet of WordPress servers in minutes for vulnerabilities and malware from the Linux command line.
0
4
18
@wordfence
Wordfence
4 years
The Wordfence Threat Intelligence team has requested further information to verify the allegedly critical severity vulnerability found in Contact Form 7. Read more about our tests & why detailed Proof of Concepts are important for security research.
2
8
18
@wordfence
Wordfence
4 years
Moments ago, our Threat Intelligence team published details about 2 vulnerabilities discovered in Facebook for WordPress, a plugin installed on over 500K sites. These are considered high & critical severity flaws that could lead to site takeover.
0
11
17
@wordfence
Wordfence
6 years
Did a hack pollute your search engine results and damage your reputation? Not all is lost. Here's how to recover your search engine results after you've been hacked. #seo #wordpress #security
0
5
15