InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: WordPress to Require Two-Factor Authentication for Plugin and Theme Developers
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > WordPress to Require Two-Factor Authentication for Plugin and Theme Developers
Technology

WordPress to Require Two-Factor Authentication for Plugin and Theme Developers

September 12, 2024 3 Min Read
Share
WordPress to Require Two-Factor Authentication for Plugin and Theme Developers
SHARE

WordPress.org has announced new account security measures that will require mandatory activation of two-factor authentication (2FA) for accounts with the ability to update plugins and themes.

The law is scheduled to come into effect on October 1, 2024.

“Accounts with commit access can push updates and changes to plugins and themes that are used by millions of WordPress sites around the world,” said an administrator of the open-source, self-hosted content management system (CMS) version.

“Securing these accounts is essential to preventing unauthorized access and maintaining the security and trust of the WordPress.org community.”

In addition to requiring 2FA, WordPress.org said it will introduce something called SVN passwords, which refers to dedicated passwords for committing changes.

The company says this is an effort to introduce an additional layer of security by separating users’ code commit access from their WordPress.org account credentials.

“This password acts like an application or additional user account password,” the team states, “preventing your main password from being leaked and allowing you to easily revoke SVN access without changing your WordPress.org credentials.”

WordPress.org also said that technical limitations prevented it from applying 2FA to existing code repositories, and as a result opted for “a combination of account-level two-factor authentication, high-entropy SVN passwords, and other deployment-time security features (e.g. release verification).”

The measure is seen as a way to counter a scenario in which bad actors could hijack a publisher’s account and introduce malicious code into legitimate plugins or themes, potentially causing a large-scale supply chain attack.

The disclosure comes after Sucuri warned about an ongoing ClearFake campaign targeting WordPress sites with the aim of tricking site visitors into manually running PowerShell code to fix webpage rendering issues and to distribute an information stealing tool called RedLine.

See also  Taylor Swift at the 2024 VMAs: Photos of the pop star's red carpet outfit

Threat actors have also been seen using infected PrestaShop e-commerce sites to deploy credit card skimmers to steal financial information entered on the checkout page.

“Outdated software is a prime target for attackers exploiting vulnerabilities in old plugins and themes,” said security researcher Ben Martin. “Weak admin passwords are a gateway for attackers.”

Users are advised to keep plugins and themes up to date, deploy a Web Application Firewall (WAF), regularly review admin accounts, and monitor website files for any unauthorized changes.

Share This Article
Twitter Copy Link
Previous Article Anime Royale Code September 2024 Anime Royale Code September 2024
Next Article 2024 Election (Taylor's version): Swift votes for Kamala Harris to beat Trump 2024 Election (Taylor’s version): Swift votes for Kamala Harris to beat Trump
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

insighthubnews
Technology

From Atari to Doom: How Google is redefining video games with AI

9 Min Read
Is there a way to slow down fast fashion? Lawmakers are trying
Environment

Is there a way to slow down fast fashion? Lawmakers are trying

9 Min Read
mm
Technology

Data-Centric AI: The Importance of Systematically Designing Training Data

10 Min Read
Android Malware
Technology

New Android malware ‘Ajina.Banker’ steals financial data via Telegram, bypasses 2FA

4 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?