1 min read

Update Now If You Run This WordPress Plugin

Millions of people around the world have leveraged the awesome power of WordPress to build their sites.  Whether for personal or business use, WordPress has the flexibility and functionality to create just about any type of site you can dream of.

A large part of this flexibility comes from the power of plugins, but that’s the problem.  With thousands of plugins available, there are lots of opportunities for hackers.

Recently, the authors of the Elementor WordPress plugin released an update (version 3.6.3) which addresses a critical security flaw that allowed unauthorized users to execute code remotely.  The issue put nearly half a million websites at risk, so the company moved quickly to address it.

Elementor’s user base has been quick to embrace the security patch with about a million of the plugin’s users having already updated.  Unfortunately, that still leaves about five hundred thousand users who are vulnerable.

If you have incorporated Elementor into your website’s design and functionality, check to see what version you’re running.  If you’re running anything before 3.6.3 then your site is at risk, and you should update as soon as possible.

WordPress manages their sprawling global empire with surprising efficiency, and carefully tracks security threats introduced by plugin security flaws.  Kudos to both WordPress and the development team at Elementor for finding and acknowledging the issue, then moving quickly to make sure it was resolved.

More Companies Can Learn From Elementor

In our view this is model behavior that companies in any industry can learn from.  There was a lot of transparency here right from the start.  Everyone involved with and responsible for the software was responsive and took fast action, making the fix available quickly.

Kudos all around.  This is how it should be done!

Used with permission from Article Aggregator

An AI Agent Ran a Ransomware Attack. Alone. The Real Story Is the Aftermath

An AI Agent Ran a Ransomware Attack. Alone. The Real Story Is the Aftermath

The first AI-run ransomware attack wasn't the story. What followed, and what it means for every organization deploying AI agents, is.

Read the full blog
Your IT Provider's Response Time Promise Is Only Worth What They Deliver

Your IT Provider's Response Time Promise Is Only Worth What They Deliver

Your IT provider's response time promise is only worth what they actually deliver. Here's how to read your SLA, what good looks like, and how to...

Read the full blog
Microsoft Copilot vs. ChatGPT for Business: Same Prompt, Very Different Answer

Microsoft Copilot vs. ChatGPT for Business: Same Prompt, Very Different Answer

Most businesses treating Copilot and ChatGPT as substitutes are using at least one wrong. Here's what each is built for and how to choose.

Read the full blog

Benefits of Proactive Cybersecurity & Risk Assessments in Portland

In today’s digital world, businesses must stay current on cyber threats and implement proactive cybersecurity plans to safeguard their data and...

Read the full blog

Understanding Cyber Threats

As technology continues to advance, the world becomes increasingly dependent on digital systems and networks.

Read the full blog

Update Your All In One SEO Plugin For Security Patch

Do you also use the “All in One” SEO plugin? If you answered yes, then be aware that you’ll want to update that plugin as soon as possible.

Read the full blog