Get Expert Website Hosting

Choose website reliability and expertise with SiteGround!

Security WordPress

PublishPress Capabilities Forced Update due to Serious Security Vulnerability

Dec 10, 2021 1 min read Hristo Pandjarov

A couple of days ago a serious security issue with the PublishPress Capabilities plugin was discovered. Usually, we always try to protect our customers using our powerful WAF (Web Application Firewall) system and build rules to stop hacking attempts while leaving the update itself to the client’s preferences.

However, due to the nature of the exploit, we couldn’t protect our clients’ sites with WAF rules so, we decided to perform an emergency update on all our active installations of the plugin. Although, we do not expect any problems associated with this update (even the default WordPress system issued an update), if you notice something not working properly, feel free to contact the PublishPress Support for additional assistance!

Who’s Affected?

Only plugin versions between 2.0.0 and 2.3.0 are affected by this vulnerability. That’s why our team has performed the update only on them in order to avoid any problems with the plugin’s normal operation.

UPDATE

PublishPress Capabilities plugin has been successfully updated on our servers. As the vulnerability was reported to affect a few other plugins and themes we have gone deeper with the investigation of the issues and have managed to create a WAF rule that is protecting against possible exploits of this particular vulnerability.

Share this article

Hristo Pandjarov

Product Innovation Director

Enthusiastic about all Open Source applications you can think of, but mostly about WordPress. Add a pinch of love for web design, new technologies, search engine optimisation and you are pretty much there!

More by Hristo

Related Posts

The Complete WordPress Security Guide + the Best Fixes

WordPress powers over a whopping 40% of the web. That’s an awful lot of websites—and also…

  • Feb 12, 2025
  • 9 min read

How to Secure a Website in 2025: 10 Critical Tactics

The question “how to secure a website” might seem daunting at first. With terms like HTTPS,…

  • Jan 07, 2025
  • 8 min read

7 Website Security Vulnerabilities + Simple Fixes

The internet can often feel like the Wild West—a vast frontier filled with opportunities but also…

  • Dec 30, 2024
  • 8 min read

Comments ( 0 )

Leave a comment

Add comment