{"id":37777,"date":"2020-10-21T16:31:25","date_gmt":"2020-10-21T16:31:25","guid":{"rendered":"http:\/\/882f8d45-ad14-4b55-9fe5-3e29e87d810f"},"modified":"2020-10-21T16:31:25","modified_gmt":"2020-10-21T16:31:25","slug":"wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/","title":{"rendered":"WordPress deploys forced security update for dangerous bug in popular plugin"},"content":{"rendered":"<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2019\/05\/07\/db25a4bf-5180-45dc-a520-6fa2224b17fb\/wordpress-security.jpg\" class alt=\"WordPress security\"><\/span><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<p>The WordPress security team has taken a rare step last week and used a lesser-known internal capability to forcibly push a security update for a popular plugin.<\/p>\n<p>WordPress sites running the Loginizer plugin were forcibly updated this week to Loginizer version 1.6.4.<\/p>\n<p>This version contained a security fix for a dangerous SQL injection bug that could have allowed hackers to take over WordPress sites running older versions of the Loginizer plugin.<\/p>\n<p><a href=\"https:\/\/wordpress.org\/plugins\/loginizer\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Loginizer<\/a>&nbsp;is one of today&#8217;s most popular WordPress plugins, with an installbase of over one million sites.<\/p>\n<p>The plugin provides security enhancements for the WordPress login page. According to its official description, Loginizer can blacklist or whitelist IP address from accessing the WordPress login page, can add support for two-factor authentication, or can add simple CAPTCHAs to block automated login attempts, among many other features.<\/p>\n<h3>SQL injection discovered in Loginizer<\/h3>\n<p>This week, security researcher Slavco Mihajloski&nbsp;<a href=\"https:\/\/twitter.com\/mslavco\/status\/1318877097184604161\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">disclosed<\/a>&nbsp;a severe vulnerability in the Loginizer plugin.<\/p>\n<p>According to a&nbsp;<a href=\"https:\/\/wpscan.com\/vulnerability\/10441\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">description<\/a>&nbsp;provided by the WPScan WordPress vulnerability database, the security bug resides in Loginizer&#8217;s brute-force protection mechanism, enabled by default for all sites where Loginizer is installed.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>To exploit this bug, an attacker can try to log into a WordPress site using a malformed WordPress username in which they can include SQL statements.<\/p>\n<p>When the authentication fails, the Loginizer plugin will record this failed attempt in the WordPress site&#8217;s database, along with the failed username.<\/p>\n<p>But as Slavco and WPScan explain, the plugin doesn&#8217;t sanitize the username and leaves the SQL statements intact, allowing remote attackers to run code against the WordPress database \u2014 in what security researchers refer to as an unauthenticated SQL injection attack.<\/p>\n<p>&#8220;It allows any unauthenticated attacker to completely compromise a WordPress website,&#8221; Ryan Dewhurst, Founder &amp; CEO of WPScan, told&nbsp;<em>ZDNet<\/em>&nbsp;in an email today.<\/p>\n<p>Dewhurst also pointed out that Mihajloski provided a simple proof-of-concept script in a&nbsp;<a href=\"https:\/\/wpdeeply.com\/loginizer-before-1-6-4-sqli-injection\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">detailed write-up<\/a>&nbsp;published earlier today.<\/p>\n<p>&#8220;This allows anyone with some basic command-line skills to completely compromise a WordPress website,&#8221; Dewhurst said.<\/p>\n<h3>Forced plugin update receives public backlash<\/h3>\n<p>The bug is one of the worst security issues discovered in WordPress plugins in recent years, and it&#8217;s why the WordPress security team appears to have decided to forcibly push the Loginizer 1.6.4 patch to all affected sites.<\/p>\n<p>Dewhurst told&nbsp;<em>ZDNet&nbsp;<\/em>that this &#8220;forced plugin update&#8221; feature has been present in the WordPress codebase since v3.7, released in 2013; however, it has used very rarely.<\/p>\n<p>&#8220;A vulnerability I myself discovered in the popular Yoast SEO WordPress plugin back in 2015 was forcibly updated. Although, the one I discovered was not nearly as dangerous as the one discovered within the Loginizer WordPress plugin,&#8221; Dewhurst said.<\/p>\n<p>&#8220;I&#8217;m not aware of any other [cases of forced plugin updates], but it is very likely that there have been others,&#8221; the WPScan founder added.<\/p>\n<p>But there&#8217;s a reason why the WordPress security team doesn&#8217;t use this feature for all plugin vulnerabilities and uses this only for the bad bugs.<\/p>\n<p>As soon as the Loginizer 1.6.4 patch started reaching WordPress sites last week, users started complaining on the plugin&#8217;s forum on the WordPress.org repository.<\/p>\n<p>&#8220;Loginizer has been updated from 1.6.3 to 1.6.4 automatically although I had NOT activated this new WordPress option. How is it possible?,&#8221;&nbsp;<a href=\"https:\/\/wordpress.org\/support\/topic\/automatic-update-33\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">asked one disgruntled user<\/a>.<\/p>\n<p>&#8220;I have the same question too. It has happened on 3 websites I look after of which none of them have been set to auto update,&#8221; said another.<\/p>\n<p>Similar negative feedback was also seen back in 2015 when Dewhurst first saw the plugin forced update feature being deployed by the WordPress team.<\/p>\n<figure class=\"media-source\">\n<div class=\"twitterContainer\" readability=\"5.9276729559748\">\n<blockquote class=\"twitter-tweet\" readability=\"5.4716981132075\">\n<p lang=\"en\" dir=\"ltr\">The more I think about it, the more infuriating the auto-update of WP SEO gets.<\/p>\n<p>\u2014 My name is Doug, I have just met you, &amp; I LOVE YOU (@zamoose) <a href=\"https:\/\/twitter.com\/zamoose\/status\/576014984641130496?ref_src=twsrc%5Etfw\" rel=\"noopener noreferrer\" target=\"_blank\" data-component=\"externalLink\">March 12, 2015<\/a><\/p><\/blockquote><\/div>\n<\/figure>\n<p>Dewhurst believes the feature isn&#8217;t more broadly used because the WordPress team fears the &#8220;risks of pushing a broken patch to so many users.&#8221;<\/p>\n<p>WordPress core developer Samuel Wood said this week the feature was used &#8220;<a href=\"https:\/\/wordpress.org\/support\/topic\/automatic-update-33\/#post-13552372\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">many times<\/a>&#8221; but did not provide details about other instances where it was used. In 2015, another WordPress developer said the plugin forced update feature was used&nbsp;<a href=\"https:\/\/twitter.com\/nacin\/status\/576032016321417216\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">only five times<\/a>&nbsp;since it launched in 2013, confirming that this feature is only used for the critical bugs only, those impacting millions of sites, and not just any plugin vulnerability.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>More than one million WordPress sites were running a vulnerable version of the Loginizer plugin.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":37778,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-37777","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WordPress deploys forced security update for dangerous bug in popular plugin 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WordPress deploys forced security update for dangerous bug in popular plugin 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-10-21T16:31:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"WordPress deploys forced security update for dangerous bug in popular plugin\",\"datePublished\":\"2020-10-21T16:31:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/\"},\"wordCount\":745,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/\",\"name\":\"WordPress deploys forced security update for dangerous bug in popular plugin 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg\",\"datePublished\":\"2020-10-21T16:31:25+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/10\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg\",\"width\":1000,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WordPress deploys forced security update for dangerous bug in popular plugin\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WordPress deploys forced security update for dangerous bug in popular plugin 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/","og_locale":"en_US","og_type":"article","og_title":"WordPress deploys forced security update for dangerous bug in popular plugin 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-10-21T16:31:25+00:00","og_image":[{"width":1000,"height":450,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"WordPress deploys forced security update for dangerous bug in popular plugin","datePublished":"2020-10-21T16:31:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/"},"wordCount":745,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/","url":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/","name":"WordPress deploys forced security update for dangerous bug in popular plugin 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg","datePublished":"2020-10-21T16:31:25+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/10\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin.jpg","width":1000,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/wordpress-deploys-forced-security-update-for-dangerous-bug-in-popular-plugin\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"WordPress deploys forced security update for dangerous bug in popular plugin"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=37777"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/37777\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/37778"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=37777"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=37777"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=37777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}