• For Enquiry
  • Sales : 888-308-8879
  • Technical : 847-868-9208
WordPress Loginizer Plugin Was Automatically Updated Due To VulnerabilityWordPress Loginizer Plugin Was Automatically Updated Due To VulnerabilityWordPress Loginizer Plugin Was Automatically Updated Due To VulnerabilityWordPress Loginizer Plugin Was Automatically Updated Due To Vulnerability
  • Home
  • Why Choose CIO Landing?
    • Our Team
    • Success Stories
    • ‘8 Things’ We Do Better
    • Partners & Certifications
    • Our Services
  • Industry Expertise
    • Manufacturing
    • Medical
    • Education
    • Financial Services
    • Non-Profit
    • Legal
  • IT Solutions
    • Co-Managed Service
    • Managed IT Services
    • IT Support
      • On Demand Services
      • Office Moves & Wiring
      • Security
    • Server Management
    • Backup & Disaster Recovery
    • Cloud Services
    • CIO & IT Consulting
    • VoIP
    • Managed Firewall
    • Microsoft 365
      • Microsoft 365 Plans
        • Small Business
        • Enterprise
        • Education
    • Hardware & Software Sales
    • Email & Spam Protection
  • Resources
    • Free Copy Of New Book
    • Blog
    • Newsletter
    • Video Tips
      • Video Tips Archive
    • Free Cloud Report
    • IT Buyers Guide
    • Cybersecurity Crisis Report
    • Network Audit
    • COVID 19 Resources
    • In The NEWS
    • Online Training
  • About Us
    • Our Mission
    • Leadership
    • Teams
    • Referral Program
    • Press Releases
      • CIO Landing: More Than Just an IT
      • Small businesses can have an IT department too
      • CIO Landing, Inc. has joined forces with Banc Certified Merchant Services (BCMS).
    • Affiliations
    • Careers
      • Job Descriptions
    • FAQs
    • Causes We Support
  • Locations
    • Northfield, IL
    • Chicago Illinois
    • Miami Florida
    • Schaumburg, Illinois
  • Support
✕
Coordinated Effort Underway To Take Down Trickbot Malware
October 29, 2020
Photoshop Testing Security For Images To Prevent Theft And Fakes
October 31, 2020

WordPress Loginizer Plugin Was Automatically Updated Due To Vulnerability

October 30, 2020

WordPress tends to take a light-handed approach when it comes to managing the legions of plugins that are compatible with the most popular blogging platform on the planet. This time, however, they’re taking a different approach. They’re forcing a security update to counter a dangerous bug in a wildly popular plugin that’s being used by more than a million websites around the world.

The plugin in question is Loginizer, which was designed to help websites fight back against brute force attacks by blocking the login function for a given IP address once a certain threshold of login retries has been reached.

It’s an indispensable plugin, honestly, but researchers discovered a fatal flaw in it in the form of an SQL injection issue. The issue could have allowed a hacker to take complete control over the site running the older version of the plugin, thus, WordPress’ decisive action, which forces an update on everyone who uses it.

While we normally don’t approve of such heavy-handed measures, in this particular instance, we feel it was justified. Had the company not taken the action it did, users would have been slow to update the plugin, and many may not have updated at all, or even been aware there was an issue. This way, everyone is protected, and it happened quickly, in an organized manner.

In an ideal world, some other solution could have been implemented, but then, in an ideal world, hackers wouldn’t abuse security flaws and loopholes in the first place. Here, WordPress made the best of a number of bad decisions and took swift decisive action designed to keep their massive user base safe and protect their brand image. While it’s less than ideal, we applaud the company for their efforts.

If you use the plugin in question, just be aware that you’re getting an update whether you want one or not. In this case, that’s probably not a bad thing.

Share
40
taylor
taylor

Related posts

November 17, 2023

Navigating Data Privacy Laws and Cybersecurity Compliance: Safeguarding Your Business in the Digital Era


Read more
November 17, 2023

Mastering Passwords: Essential Practices for Digital Security


Read more
November 10, 2023

Layered Defense: The Power of MFA


Read more

Leave a Reply Cancel reply

You must be logged in to post a comment.

© 2023 All Rights Reserved | Powered by CIO Landing