<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wordpress - Latest News &amp; Reviews</title>
	<atom:link href="https://www.thetechoutlook.com/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.thetechoutlook.com/tag/wordpress/</link>
	<description>Daily Tech News, Interviews, Reviews and Updates</description>
	<lastBuildDate>Tue, 03 Feb 2026 20:42:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://www.thetechoutlook.com/wp-content/uploads/2019/09/cropped-favicon-1-150x150.png</url>
	<title>Wordpress - Latest News &amp; Reviews</title>
	<link>https://www.thetechoutlook.com/tag/wordpress/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>WordPress 6.9.1 Maintenance Update Now Rolling Out with 49 Bug Fixes; Version 7.0 Coming April 9th</title>
		<link>https://www.thetechoutlook.com/new-release/software-apps/wordpress-6-9-1-maintenance-update-now-rolling-out-with-49-bug-fixes-version-7-0-coming-april-9th/</link>
		
		<dc:creator><![CDATA[Divya Dhingra]]></dc:creator>
		<pubDate>Tue, 03 Feb 2026 20:42:51 +0000</pubDate>
				<category><![CDATA[Software & Apps]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=247309</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-150x84.jpg 150w" sizes="(max-width: 1200px) 100vw, 1200px" /></div>
<p>In a blog post, WordPress announced the rollout of a new update, version 6.9.1, a maintenance release. WordPress has stated that this update brings a total of 49 bug fixes throughout the core and block editor. Further mentioning that, it will address issues affecting multiple areas of WordPress, including the block editor, mail, and classic [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/new-release/software-apps/wordpress-6-9-1-maintenance-update-now-rolling-out-with-49-bug-fixes-version-7-0-coming-april-9th/">WordPress 6.9.1 Maintenance Update Now Rolling Out with 49 Bug Fixes; Version 7.0 Coming April 9th</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-6.9.1-150x84.jpg 150w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p>In a blog post, WordPress announced the rollout of a new update, version 6.9.1, a maintenance release. WordPress has stated that this update brings a total of 49 bug fixes throughout the core and block editor. Further mentioning that, it will address issues affecting multiple areas of WordPress, including the block editor, mail, and classic themes.</p>
<p>Since the rollout has just begun, for those who have automatic background updates enabled, the update process will run in the background. However, if you haven&#8217;t turned on the automatic updates, you will get a notification soon in your dashboard area. From there, you can click &#8220;Updates&#8221; and then click &#8220;Update Now&#8221;, by following the onscreen instructions for the same.</p>
<figure id="attachment_247310" aria-describedby="caption-attachment-247310" style="width: 831px" class="wp-caption alignnone"><img decoding="async" class="size-full wp-image-247310" src="https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-Version-6.9.1.jpg" alt="Wordpress Version 6.9.1" width="831" height="141" srcset="https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-Version-6.9.1.jpg 831w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-Version-6.9.1-300x51.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-Version-6.9.1-768x130.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2026/02/Wordpress-Version-6.9.1-150x25.jpg 150w" sizes="(max-width: 831px) 100vw, 831px" /><figcaption id="caption-attachment-247310" class="wp-caption-text">WordPress Version 6.9.1 Notification in Dashboard</figcaption></figure>
<p>It also confirms that the next update&#8217;s version will be 7.0 and will be rolled out on April 9th, 2026, at WordCamp Asia. To check out the complete list of bug fixes, you can <a href="https://make.wordpress.org/core/2026/01/30/wordpress-6-9-1-rc1-is-now-available/">check it out from the official release notes.</a></p>
<p>The post <a href="https://www.thetechoutlook.com/new-release/software-apps/wordpress-6-9-1-maintenance-update-now-rolling-out-with-49-bug-fixes-version-7-0-coming-april-9th/">WordPress 6.9.1 Maintenance Update Now Rolling Out with 49 Bug Fixes; Version 7.0 Coming April 9th</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New AI Agent Skill introduced for WordPress that streamlines testing and iteration, and works with Playground</title>
		<link>https://www.thetechoutlook.com/new-release/software-apps/new-ai-agent-skill-introduced-for-wordpress-that-streamlines-testing-and-iteration-and-works-with-playground/</link>
		
		<dc:creator><![CDATA[Estuti Bajpai]]></dc:creator>
		<pubDate>Sat, 31 Jan 2026 07:16:11 +0000</pubDate>
				<category><![CDATA[Software & Apps]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=247097</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-150x84.jpg 150w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>To enhance testing and iteration in WordPress, Brandon Payton (WordPress contributor) has published wp-playground, a new AI agent skill designed to run WordPress via the Playground CLI. A new AI agent skill has been introduced that streamlines testing and iteration in WordPress and works with Playground. This innovative tool reduces setup time from minutes to [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/new-release/software-apps/new-ai-agent-skill-introduced-for-wordpress-that-streamlines-testing-and-iteration-and-works-with-playground/">New AI Agent Skill introduced for WordPress that streamlines testing and iteration, and works with Playground</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2026/01/WordPress1-150x84.jpg 150w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>To enhance testing and iteration in WordPress, Brandon Payton (WordPress contributor) has published wp-playground, a new AI agent skill designed to run WordPress via the Playground CLI.</p>
<blockquote class="twitter-tweet" data-width="550" data-dnt="true">
<p lang="en" dir="ltr">A new AI agent skill has been introduced that streamlines testing and iteration in WordPress and works with Playground. This innovative tool reduces setup time from minutes to seconds, enhancing collaboration and creativity. </p>
<p>Test it out today: <a href="https://t.co/LP7NWA8Jz5">https://t.co/LP7NWA8Jz5</a> <a href="https://t.co/Xq6ujsp9vy">pic.twitter.com/Xq6ujsp9vy</a></p>
<p>&mdash; WordPress (@WordPress) <a href="https://twitter.com/WordPress/status/2017312079795872048?ref_src=twsrc%5Etfw">January 30, 2026</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p>This new AI agent skill is said to give agents an easy way to test WordPress code and make building and experimenting with WordPress a lot more accessible.</p>
<p>During testing, agents were able to start WordPress, build playful plugins, and validate behavior in a tight feedback loop. Once Playground was running, the agent alternated between tools such as curl and Playwright to interact with WordPress, verify results, apply fixes when needed, and then re-verify with Playground.</p>
<p>When launched, this skill starts WordPress and detects where the current code should live inside a WordPress install. This helps agents move from “generated code” to “running site” with fewer manual steps. It is revealed that helper scripts handle startup and shutdown, so an agent doesn’t waste time guessing when WordPress is ready. This reduces the “ready to test” moment from roughly a minute to a few seconds on the author’s machine. The Playground CLI can also log in automatically to easier WP-Admin access during testing.</p>
<h2>Availability</h2>
<p>To try this new AI agent skill in Claude Code, Codex, or another AI agent, installation requires Node.js and npm.</p>
<p>In addition to the new AI agent skill, WordPress has also made an announcement of a <a href="https://github.com/WordPress/agent-skills">new experimental GitHub repo</a> where WordPress is testing how AI agents can work with WordPress tools. It&#8217;s an early step in exploring how AI agents can collaborate with WordPress tooling and is open to community contributions. It is revealed that future additions being explored include persistent Playground sites based on the current directory, running commands against an existing Playground instance (including wp-cli), and Blueprint generation.</p>
<p>The post <a href="https://www.thetechoutlook.com/new-release/software-apps/new-ai-agent-skill-introduced-for-wordpress-that-streamlines-testing-and-iteration-and-works-with-playground/">New AI Agent Skill introduced for WordPress that streamlines testing and iteration, and works with Playground</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Here&#8217;s How to Install WordPress Manually on Linux Server</title>
		<link>https://www.thetechoutlook.com/tech-blogs/heres-how-to-install-wordpress-manually-on-linux-server/</link>
		
		<dc:creator><![CDATA[Sidharth Joseph]]></dc:creator>
		<pubDate>Sat, 05 Apr 2025 08:03:13 +0000</pubDate>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=218666</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="WordPress - Feature Image" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-150x84.jpg 150w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>WordPress is considered to be the most popular software that is relied on to create websites and it stands out to be the most user-friendly content management system that is currently available. This article is intended to take readers through the steps which will let them manually install and run WordPress on a Linux server. [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/tech-blogs/heres-how-to-install-wordpress-manually-on-linux-server/">Here&#8217;s How to Install WordPress Manually on Linux Server</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="WordPress - Feature Image" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/WordPress-Feature-Image-150x84.jpg 150w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>WordPress is considered to be the most popular software that is relied on to create websites and it stands out to be the most user-friendly content management system that is currently available. This article is intended to take readers through the steps which will let them manually install and run WordPress on a Linux server.</p>
<p>Read more about it below.</p>
<h3><strong>Install WordPress Manually on a Linux Server &#8211; Step by Step Guide</strong></h3>
<ul>
<li>Firstly, there are a few prerequisites that have to be ensured from the users&#8217; end before proceeding to install WordPress on a Linux server &#8211; A basic understanding about Linux commands is needed, a Linux system that has admin privilege, and a stable internet connection.</li>
<li>After meeting these, the next step is to see whether the Linux server is up to date &#8211; <strong>sudo apt update &amp;&amp; sudo apt upgrade -y</strong> command ensures that it is up to date.</li>
<li>Next, a web server which will host the WordPress site has to be set up and Apache is said to be the widely-used choice. Use <strong>sudo apt install apache2</strong> command to install Apache, and it will thus be serving as the engine behind the WordPress site. With the <strong>sudo systemctl enable apache2</strong> command, its service can be enabled.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218679 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-1.avif" alt="Output (1)" width="800" height="113" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-1.avif 800w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-1-300x42.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-1-768x108.avif 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-1-150x21.avif 150w" sizes="auto, (max-width: 800px) 100vw, 800px" /></p>
<p style="padding-left: 40px">With the <strong>sudo systemctl start apache2</strong> command, the Apache server can be started. The status of the running Apache server can be checked with the <strong>Systemctl status apache2</strong> command.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218680 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-2.avif" alt="Output (2)" width="800" height="362" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-2.avif 800w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-2-300x136.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-2-768x348.avif 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-2-150x68.avif 150w" sizes="auto, (max-width: 800px) 100vw, 800px" /></p>
<p style="padding-left: 40px">Furthermore, to check local IP address on the browser, use <strong>http://server-ip-address</strong>.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218681 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/To-check-IP-address.avif" alt="To check IP address" width="800" height="541" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/To-check-IP-address.avif 800w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/To-check-IP-address-300x203.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/To-check-IP-address-768x519.avif 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/To-check-IP-address-150x101.avif 150w" sizes="auto, (max-width: 800px) 100vw, 800px" /></p>
<ul>
<li>To store data generated from the WordPress CMS (content management system), MariaDB is being used here (any database can be used &#8211; MySQL/PostGRES). Use the <strong>sudo apt install mariadb-server mariadb client</strong> command to install MariaDB, and then use <strong>sudo systemctl enable &#8211;now mariadb</strong> and <strong>sudo systemctl start mariadb</strong> commands to respectively enable and start it. Status can be checked with the <strong>systemctl status mariaDB</strong> command.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218683 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-3.avif" alt="Output (3)" width="800" height="463" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-3.avif 800w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-3-300x174.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-3-768x444.avif 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-3-150x87.avif 150w" sizes="auto, (max-width: 800px) 100vw, 800px" /></p>
<p style="padding-left: 40px">Also, to enable security within the installed database, use <strong>sudo mysql_secure_installation</strong> command to initiate the MySQL Secure Installation Wizard. The prompt will ask users to configure multiple security options.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218687 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-4.avif" alt="Output (4)" width="592" height="370" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-4.avif 592w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-4-300x188.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-4-150x94.avif 150w" sizes="auto, (max-width: 592px) 100vw, 592px" /></p>
<ul>
<li>PHP and other essential extensions can be installed with the <strong>sudo apt install -y php php-common php-mysql php-xml php-xmlrpc php-curl php</strong> command, and the installed PHP version can be check with <strong>php &#8211;version</strong> command.</li>
<li>Now to setup WordPress on Linux, use <strong>sudo apt install wget unzip</strong> command to install the necessary tools and then use <strong>wget https://wordpress.org/latest.zip</strong> command to download the latest WordPress version. With <strong>sudo unzip latest .zip</strong> command, extract the WordPress archive. Using <strong>cd wordpress </strong>command, navigate to the WordPress directory, copy WordPress files to the Web Server Directory with <strong>sudo cp -r * /var/www/html</strong> command, navigate to the directory using <strong>cd /var/www/html</strong> command, remove default index file with <strong>sudo rm -rf index.html</strong> command, and install additional PHP modules with <strong>sudo apt install php-mysql php-cgi php-cli php-gd -y</strong> command. By running the <strong>sudo systemctl restart apache2</strong> command, restart Apache so that the changes can be successfully applied. Using <strong>sudo chown -R www-data:www- /var/www/</strong> command, the ownership for the Apache server can be set.</li>
<li>To create a database for WordPress, login to the database server using <strong>sudo mysql -u root -p</strong> command, establish a dedicated database using <strong>create database new_DB;</strong> command, create a user account linked to the database using <strong>CREATE USER &#8216;new_user&#8217;@&#8217;%&#8217; IDENTIFIED BY &#8216;your_password&#8217; ;</strong>, and finally authorize the user with the <strong>GRANT ALL PRIVILEGES ON new_DB.* TO &#8216;new_user&#8217;@&#8217;%&#8217;;</strong> command. Also to add, <strong>new_user</strong>, <strong>new_DB</strong>, and <strong>your_password </strong>can be changed accordingly.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218690 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-5.avif" alt="Output (5)" width="648" height="576" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-5.avif 648w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-5-300x267.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Output-5-150x133.avif 150w" sizes="auto, (max-width: 648px) 100vw, 648px" /></p>
<ul>
<li>For setting up the WordPress CMS Web Interface Setup, access the WordPress site on the browser and visit the endpoint (<strong>http://your-server-ip-address/wp-admin/setup-config.php</strong>). Next, add the IP address of the Linux server in place of <strong>your-server-ip-address</strong>. Then select the preferred language and click on <strong>Continue</strong>.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218695 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Select-language.avif" alt="Select language" width="790" height="768" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Select-language.avif 790w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Select-language-300x292.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Select-language-768x747.avif 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Select-language-150x146.avif 150w" sizes="auto, (max-width: 790px) 100vw, 790px" /></p>
<ul>
<li>To add database information to WordPress, click on <strong>Let&#8217;s go!</strong></li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218696 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Adding-database-information.avif" alt="Adding database information" width="792" height="570" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Adding-database-information.avif 792w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Adding-database-information-300x216.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Adding-database-information-768x553.avif 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Adding-database-information-150x108.avif 150w" sizes="auto, (max-width: 792px) 100vw, 792px" /></p>
<p style="padding-left: 40px">On the WordPress setup wizard, enter all the necessary credentials and click on <strong>Submit.</strong></p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218697 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Click-on-Submit.avif" alt="Click on Submit" width="764" height="590" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Click-on-Submit.avif 764w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Click-on-Submit-300x232.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Click-on-Submit-150x116.avif 150w" sizes="auto, (max-width: 764px) 100vw, 764px" /></p>
<p style="padding-left: 40px">Click on <strong>Run the Installation </strong>to complete this process.</p>
<ul>
<li>Finally to create admin user and password, add site title, username, and password. Then press the <strong>Install WordPress</strong> button.</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218698 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Create-Admin-User-and-Password.avif" alt="Create Admin User and Password" width="740" height="714" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Create-Admin-User-and-Password.avif 740w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Create-Admin-User-and-Password-300x289.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Create-Admin-User-and-Password-150x145.avif 150w" sizes="auto, (max-width: 740px) 100vw, 740px" /></p>
<p style="padding-left: 40px">To get to the backend, make use of the created admin credentials.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-218699 size-full" src="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Login-to-backend.avif" alt="Login to backend" width="800" height="601" srcset="https://www.thetechoutlook.com/wp-content/uploads/2025/04/Login-to-backend.avif 800w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Login-to-backend-300x225.avif 300w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Login-to-backend-768x577.avif 768w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Login-to-backend-86x64.avif 86w, https://www.thetechoutlook.com/wp-content/uploads/2025/04/Login-to-backend-150x113.avif 150w" sizes="auto, (max-width: 800px) 100vw, 800px" /></p>
<p>Following these above mentioned steps, anyone will be able to easily install and run WordPress on the Linux server.</p>
<p>The post <a href="https://www.thetechoutlook.com/tech-blogs/heres-how-to-install-wordpress-manually-on-linux-server/">Here&#8217;s How to Install WordPress Manually on Linux Server</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Up to 47,000 malicious plugins have been identified on 25,000 WordPress websites</title>
		<link>https://www.thetechoutlook.com/news/security/up-to-47000-malicious-plugins-have-been-identified-on-25000-wordpress-websites/</link>
					<comments>https://www.thetechoutlook.com/news/security/up-to-47000-malicious-plugins-have-been-identified-on-25000-wordpress-websites/#respond</comments>
		
		<dc:creator><![CDATA[Somya Agrawal]]></dc:creator>
		<pubDate>Mon, 29 Aug 2022 13:11:33 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[plugins]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[yoda]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=71371</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>Up to 47,337 malicious plugins have been identified on 24,931 unique websites, and 3,685 of those plugins were offered for sale on trustworthy marketplaces, earning the hackers $41,500. Results from a new program named YODA that seeks to detect rogue WordPress plugins and trace their origin, according to an 8-year study conducted by a group [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/up-to-47000-malicious-plugins-have-been-identified-on-25000-wordpress-websites/">Up to 47,000 malicious plugins have been identified on 25,000 WordPress websites</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-29T175604.540-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>Up to 47,337 malicious plugins have been identified on 24,931 unique websites, and 3,685 of those plugins were offered for sale on trustworthy marketplaces, earning the hackers $41,500. Results from a new program named YODA that seeks to detect rogue WordPress plugins and trace their origin, according to an 8-year study conducted by a group of scholars from the Georgia Institute of Technology<br />
In use today are almost 44,000 of these plugins or more than 94%.</p>
<p>While posing as developers of useful plugins, attackers distributed pirated plugins to spread malware. Harmful activity peaked in March 2020, and there have been a growing amount of malicious plugins on websites throughout time. It&#8217;s surprising to see that 94% of the malicious plugins that were installed throughout those 8 years are still active. It was found in the long analysis that threat actors had infected plugins after they had been released, costing a total of $834,000, by looking at WordPress plugins installed on 410,122 different web servers going back to 2012.</p>
<p>YODA can be installed either by directly integrating it into a website and web server hosting provider or by using a marketplace for plugins. The framework can be used to find out a plugin&#8217;s owner and provenance in addition to finding out where add-ons are hidden and malware-rigged. In order to locate the plugins, it analyses the server-side code files and the associated metadata. Then, it conducts a syntactic and semantic analysis to find malicious activities.</p>
<p>The semantic model considers a variety of red flags, including web shells, the capacity to add new posts, password-protected code injection, spam, code obfuscation, blackout SEO, malware downloaders, malvertising, and cryptocurrency miners.<br />
Spam injection was made possible via 3,452 plugins that were accessible in trusted plugin markets.<br />
40,533 plugins were infected with malware on 18,034 websites after being distributed.<br />
unauthorized plugins WordPress plugins or themes that have been altered to download malicious malware from the servers made up 8,525 of the malicious add-ons. Approximately 75% of the stolen plugins stole $228,000 from their creators.<br />
By using YODA, plugin creators and marketplaces can inspect their plugins before distribution, and website owners and hosting providers can search the web server for potentially harmful plugins.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/up-to-47000-malicious-plugins-have-been-identified-on-25000-wordpress-websites/">Up to 47,000 malicious plugins have been identified on 25,000 WordPress websites</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/security/up-to-47000-malicious-plugins-have-been-identified-on-25000-wordpress-websites/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WordPress sites being hacked with fake Cloudflare DDoS to distribute malware</title>
		<link>https://www.thetechoutlook.com/news/security/wordpress-sites-being-hacked-with-fake-cloudflare-ddos-to-distribute-malware/</link>
					<comments>https://www.thetechoutlook.com/news/security/wordpress-sites-being-hacked-with-fake-cloudflare-ddos-to-distribute-malware/#respond</comments>
		
		<dc:creator><![CDATA[Pavan Naidu]]></dc:creator>
		<pubDate>Sat, 20 Aug 2022 16:32:25 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Raccoon Stealer]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=69412</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="WordPress sites being hacked with fake Cloudflare DDoS to distribute malware" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>On Saturday, WordPress sites are being hacked for displaying fake Cloudflare DDoS protection pages to circulate malware that installs the NetSupport RAT and the RaccoonStealer password-stealing Trojan. DDoS protection screens are commonplace on the internet, that protects sites from bots, pinging them with bogus requests which aim to overwhelm them with garbage traffic. Internet users [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/wordpress-sites-being-hacked-with-fake-cloudflare-ddos-to-distribute-malware/">WordPress sites being hacked with fake Cloudflare DDoS to distribute malware</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="WordPress sites being hacked with fake Cloudflare DDoS to distribute malware" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-5-7-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>On Saturday, WordPress sites are being hacked for displaying fake Cloudflare DDoS protection pages to circulate malware that installs the NetSupport RAT and the RaccoonStealer password-stealing Trojan.</p>
<p>DDoS protection screens are commonplace on the internet, that protects sites from bots, pinging them with bogus requests which aim to overwhelm them with garbage traffic.</p>
<p>Internet users treat these welcome screens as an unavoidable short-term annoyance that keeps their favorite online resources protected from malicious operatives. Unfortunately, this familiarity serves as an excellent opportunity for malware campaigns, Bleeping Computer reports.</p>
<p>According to the reports by Sucuri, hackers are attacking poorly protected WordPress sites to add a heavily obscure JavaScript payload, displaying a fake Cloudflare protection DDoS screen.</p>
<p>In June 2022, Raccoon Stealer returned to operations when its authors released its second major version and made it available to cybercriminals under a subscription model.</p>
<p>Raccoon 2.0 targets passwords, cookies, auto-fill data, and credit cards saved on web browsers, a wide range of cryptocurrency wallets, and it also has the potential of performing file exfiltration and taking screenshots of the victim&#8217;s desktop.</p>
<p>&nbsp;</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/wordpress-sites-being-hacked-with-fake-cloudflare-ddos-to-distribute-malware/">WordPress sites being hacked with fake Cloudflare DDoS to distribute malware</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/security/wordpress-sites-being-hacked-with-fake-cloudflare-ddos-to-distribute-malware/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to Disable XML-RPC Pingback in WordPress?</title>
		<link>https://www.thetechoutlook.com/featured/how-to-disable-xml-rpc-pingback-in-wordpress/</link>
					<comments>https://www.thetechoutlook.com/featured/how-to-disable-xml-rpc-pingback-in-wordpress/#respond</comments>
		
		<dc:creator><![CDATA[Somya Agrawal]]></dc:creator>
		<pubDate>Mon, 15 Aug 2022 17:16:16 +0000</pubDate>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[disable]]></category>
		<category><![CDATA[methods]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[XML-RPC Pingback]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=68476</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>You can remotely publish articles using a tablet, a smartphone, or Windows Live Writer thanks to WordPress&#8217; fantastic XML-RPC tool. When you leave XML-RPC enabled on your WordPress blog, there is, however, a risk. Recently, using xml-rpc on one of my WordPress blogs, an attacker transmitted some spam traffic to several domains. Because it was [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/featured/how-to-disable-xml-rpc-pingback-in-wordpress/">How to Disable XML-RPC Pingback in WordPress?</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-15T222601.109-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>You can remotely publish articles using a tablet, a smartphone, or Windows Live Writer thanks to WordPress&#8217; fantastic XML-RPC tool. When you leave XML-RPC enabled on your WordPress blog, there is, however, a risk. Recently, using xml-rpc on one of my WordPress blogs, an attacker transmitted some spam traffic to several domains. Because it was an outdated WordPress version (on an abandoned domain), even the xml-rpc may have been vulnerable to an attack. The xml-rpc in the most recent WordPress version, however, concerns me as to its security. If you ever want to disable xml-rpc on WordPress, there are three ways to do it.</p>
<p>99% of pingbacks are spam. By sending a pingback notification and collecting link juice from the targeted website because pingbacks are usually shown as regular comments, spammers will try to construct a linkback to their content. Furthermore, by abusing the XML-RPC pingback features, distributed denial of service assaults may be made easier (DDoS). By taking advantage of reliable blogs and websites, this vulnerability may persuade them to voluntarily participate in DDoS attacks against particular websites.</p>
<p><strong>How does Pingback DDoS operate?</strong></p>
<p>In order to launch a DDoS attack against a target system, a malicious hacker sends a large number of innocent WordPress blogs that have enabled pingbacks specially crafted pingback instructions, deceiving them into believing the originator is the target system. By sending a deluge of answers, the bloggers will unwittingly deliver erroneous traffic to the target system.</p>
<p>If you stop pingbacks, DDoS assaults against your blog are no longer possible.Actually, you should just disable some of the supported XML-RPC functionality. If you don&#8217;t, you can experience issues with certain of your plugins, like JetPack, which rely on XML-RPC to communicate with distant servers.</p>
<p><strong>Method 1: using onboard means</strong></p>
<p>The simplest fix is to uncheck the item in WordPress&#8217; settings. Under Settings-&gt;Discussion, uncheck the box next to &#8220;Allow link notifications from other blogs (pingbacks and trackbacks)&#8221;. Select &#8220;Save Changes&#8221; after that.</p>
<p>This will only block pingbacks (and trackbacks) for upcoming posts and pages; it won&#8217;t have an impact on the present posts and pages. In order to disable additionally for the already-existing posts and pages, you must run a few SQL queries. You can utilise the phpMyAdmin tool for this. Simply look for the phpMyAdmin tool in your web hosting account&#8217;s CPanel control panel. Once there, locate the database for the blog and select the SQL tab. then type the subsequent commands:</p>
<p>[UPDATE wp_posts SET ping_status=&#8217;closed&#8217;</p>
<p>WHERE post_status = &#8216;publish&#8217; AND post_type = &#8216;post&#8217;;</p>
<p>&nbsp;</p>
<p>UPDATE wp_posts SET ping_status=&#8217;closed&#8217;</p>
<p>WHERE post_status = &#8216;publish&#8217; AND post_type = &#8216;page&#8217;;]</p>
<p>To find out which database is used by your blog follow these steps:</p>
<ol>
<li>Connect to your hosting account with an FTP client, for example, WinSCP;</li>
<li>Navigate to your site’s root directory, usually <strong>public_html</strong>;</li>
<li>Locate and open to view <strong>wp-config.php</strong>file;</li>
<li>Within this file locate the string <strong>DB_NAME</strong>; it should bring you to a declaration like this: define(‘DB_NAME’, ‘pref_wp239’);  The second parameter is the name of the database.</li>
</ol>
<p><strong>Method 2: Using Plugins</strong></p>
<p>One of the simplest of them that does exactly what it says is disable-xml-rpc-pingback. This free plugin disables only the pingback part of XML-RPC API.</p>
<p>Just go to <strong>Plugins-&gt;Add New</strong> and enter “<strong>disable xml rpc pingback</strong>” in the search box. Then install “<strong>Disable XML-RPC Pingback</strong>” by Samuel Aguilera. When done, you have to activate it.</p>
<p><strong>Method 3: A little coding</strong></p>
<p>ust go to <strong>Appearance-&gt;Editor</strong>, then choose <strong>functions.php</strong> and add this code at the end:</p>
<p>&nbsp;</p>
<p>[// disable pingbacks</p>
<p>add_filter( &#8216;xmlrpc_methods&#8217;, function( $methods ) {</p>
<p>unset( $methods[&#8216;pingback.ping&#8217;] );</p>
<p>return $methods;</p>
<p>} );]</p>
<p>Don’t forget to click on “<strong>Update File</strong>” when finished.</p>
<p>The post <a href="https://www.thetechoutlook.com/featured/how-to-disable-xml-rpc-pingback-in-wordpress/">How to Disable XML-RPC Pingback in WordPress?</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/featured/how-to-disable-xml-rpc-pingback-in-wordpress/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A new phishing kit has been discovered attacking PayPal users! Read more</title>
		<link>https://www.thetechoutlook.com/news/security/a-new-phishing-kit-has-been-discovered-attacking-paypal-users-read-more/</link>
					<comments>https://www.thetechoutlook.com/news/security/a-new-phishing-kit-has-been-discovered-attacking-paypal-users-read-more/#respond</comments>
		
		<dc:creator><![CDATA[Neha Kunder]]></dc:creator>
		<pubDate>Fri, 15 Jul 2022 07:31:18 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Paypal]]></category>
		<category><![CDATA[Phishing kit]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=62227</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="PayPal" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>Recently, a new phishing kit has been discovered attacking PayPal users to steal their confidential data which includes user&#8217;s government identification documents and photos. Phishing kits are simple tools that quickly creates fake websites to steal the victim&#8217;s personal data. Accordingly, hackers uses these phishing kits to hack the confidential data from their victims. Some [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/a-new-phishing-kit-has-been-discovered-attacking-paypal-users-read-more/">A new phishing kit has been discovered attacking PayPal users! Read more</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="PayPal" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/Untitled-design-2022-07-15T123714.147-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>Recently, a new phishing kit has been discovered attacking PayPal users to steal their confidential data which includes user&#8217;s government identification documents and photos.</p>
<p>Phishing kits are simple tools that quickly creates fake websites to steal the victim&#8217;s personal data. Accordingly, hackers uses these phishing kits to hack the confidential data from their victims. Some kits also includes tools like sending out fraud e-mails, a control panel and dictionaries to locate the cyberattacks.</p>
<p>Consequently, the kit is been hosted on the hacked WordPress websites which allows the kit to avoid the system recognition. However, the security experts at internet technology company Akamai found the phishing kit after the hackers hosted it on their WordPress website.</p>
<p>The kit presents a CAPTCHA challenge to the users and asks them to log into their PayPal account using their email ID and password. The threat actor also asks for more verification information from the users. Afterwards, the victim is asked to give the host their personal and financial details, including debit card details, with the card verification code, address, social security number and others. This doesnot stops here. The fraudulents also asks victims to link their email account to PayPal which gives the hacker to access the contents of the provided email address.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/a-new-phishing-kit-has-been-discovered-attacking-paypal-users-read-more/">A new phishing kit has been discovered attacking PayPal users! Read more</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/security/a-new-phishing-kit-has-been-discovered-attacking-paypal-users-read-more/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to create a website on WordPress?</title>
		<link>https://www.thetechoutlook.com/new-release/software-apps/how-to-create-a-website-on-wordpress/</link>
					<comments>https://www.thetechoutlook.com/new-release/software-apps/how-to-create-a-website-on-wordpress/#respond</comments>
		
		<dc:creator><![CDATA[Damini Khatri]]></dc:creator>
		<pubDate>Mon, 04 Jul 2022 15:34:26 +0000</pubDate>
				<category><![CDATA[Software & Apps]]></category>
		<category><![CDATA[Website creation]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=60158</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="How to create a website on WordPress" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>Creating a website is like starting your career in such a vast empire called the internet. Nowadays, almost every human being has access to the internet. Whatever information we need to know, we search for innumerous websites. But to create a website, we need to learn certain skills about how to work on creating a [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/new-release/software-apps/how-to-create-a-website-on-wordpress/">How to create a website on WordPress?</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="How to create a website on WordPress" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/07/jpg_20220704_192501_0000-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>Creating a website is like starting your career in such a vast empire called the internet. Nowadays, almost every human being has access to the internet. Whatever information we need to know, we search for innumerous websites.</p>
<p>But to create a website, we need to learn certain skills about how to work on creating a website. There is a lot of softwares which helps to create a website but WordPress is considered as one of the most successful software which helps to develop a website.</p>
<h3><strong>What is WordPress ?</strong></h3>
<p>WordPress is a content management system (CMS) which helps to develop unique content and build websites. The features of WordPress are extremely helpful to make a website.</p>
<p>Moreover, WordPress contains plugin architecture and a template system. So you can customise any website to fit your business, blog, portfolio, or online store.</p>
<p>Steps to create a website on WordPress</p>
<p>In WordPress, there is WordPress.org and WordPress.com. out which, WordPress.com needs to be selected for developing a website.</p>
<h3><strong>So let&#8217;s learn how to create a website in WordPress.com &#8211;</strong></h3>
<p>1)Select WordPress.com Plan &#8211;</p>
<p>First, start the WordPress com and select the plan you require. In WordPress.org, there is a free plan available but, you will require to buy your domain, hosting provider, plugins, themes, and other related features.</p>
<p>So one should select a WordPress.com plan which is relevant.</p>
<p>2)Set your domain and hosting provider &#8211;</p>
<p>In WordPress, selecting a domain and a hosting provider happens at the same time. Moreover, it allows you to decide whether you want a custom domain or not. It depends on the plan you choose, but it takes care of the hosting for you.</p>
<p>On the other side, hosting providers affect the websites speed, privacy, and security.</p>
<p>3)Install WordPress &#8211;</p>
<p>Click on the WordPress app to begin its installation. After finishing installation, you will have to answer a few questions about the domain you want to select.</p>
<p>4)Choose your theme &#8211;</p>
<p>There are many themes and templates available in WordPress. There are a variety of layouts, formatting styles, font types, font colours, images, videos and many more. Choose your themes according to your genres of website blogs.</p>
<p>5)Add your post and page for your website &#8211;</p>
<p>After choosing the themes, add your content along with the feature image. Also type your content with difficult styles of writing to get more views. Check your readability and SEO score and review your content. And at last, publish your article.</p>
<p>6)Build your website &#8211;</p>
<p>Keep updating your website with varieties of contents. Build your website while adding your site title. In the dashboard, select general settings and add your website title and tagline. You can also add other basic information like email id, zone, time, etc.</p>
<p>7)Make your website to bring your page in light &#8211;</p>
<p>After completing all the above procedures, review and re-check your content with readability score and SEO score. Lastly, publish your article on your website and keep your website updated with all trending information.</p>
<p>&nbsp;</p>
<p>The post <a href="https://www.thetechoutlook.com/new-release/software-apps/how-to-create-a-website-on-wordpress/">How to create a website on WordPress?</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/new-release/software-apps/how-to-create-a-website-on-wordpress/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Want to know how hackers find your wordpress username? Details Inside</title>
		<link>https://www.thetechoutlook.com/tech-blogs/want-to-know-how-hackers-find-your-wordpress-username-details-inside/</link>
					<comments>https://www.thetechoutlook.com/tech-blogs/want-to-know-how-hackers-find-your-wordpress-username-details-inside/#respond</comments>
		
		<dc:creator><![CDATA[Team Tech Outlook]]></dc:creator>
		<pubDate>Wed, 19 May 2021 21:13:30 +0000</pubDate>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[hackers find username wordpress]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=16274</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-696x392.jpg 696w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-1068x601.jpg 1068w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>Technique 1: Using/?author=1 Query Parameter At some point, I had quite recently set up another blog and thought I&#8217;d covered up my administrator zones really well. Incredibly, my security modules began sending me lockout takes note. This implies that in addition to the fact that hackers were ready to discover my login page, they had [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/tech-blogs/want-to-know-how-hackers-find-your-wordpress-username-details-inside/">Want to know how hackers find your wordpress username? Details Inside</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-768x432.jpg 768w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-696x392.jpg 696w, https://www.thetechoutlook.com/wp-content/uploads/2020/04/Hackers-selling-500000-Zoom-accounts-on-the-dark-web-1068x601.jpg 1068w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><h2>Technique 1: Using/?author=1 Query Parameter</h2>
<p>At some point, I had quite recently set up another blog and thought I&#8217;d covered up my administrator zones really well. Incredibly, my security modules began sending me lockout takes note. This implies that in addition to the fact that hackers were ready to discover my login page, they had the option to figure my WordPress username too! I opened up my crude access signs in cPanel, and discovered this:</p>
<p><img loading="lazy" decoding="async" class="alignnone  wp-image-16275" src="https://www.thetechoutlook.com/wp-content/uploads/2021/05/author-parameter.jpg" alt="" width="923" height="310" srcset="https://www.thetechoutlook.com/wp-content/uploads/2021/05/author-parameter.jpg 551w, https://www.thetechoutlook.com/wp-content/uploads/2021/05/author-parameter-300x101.jpg 300w" sizes="auto, (max-width: 923px) 100vw, 923px" /></p>
<p>Evidently, programmers can discover your username in WordPress by affixing the inquiry/?author=1! You can find in the screen capture over, that my worker quickly returned the creator page – which obviously, uncovered the username. So disregard making your username hard to figure. It&#8217;s privilege out there in the open!</p>
<p>Here&#8217;s what it looks like. In the first place, type in your blog name and type/?author=1 after the URL like this:</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-16276 aligncenter" src="https://www.thetechoutlook.com/wp-content/uploads/2021/05/append-author-parameter.jpg" alt="" width="550" height="311" srcset="https://www.thetechoutlook.com/wp-content/uploads/2021/05/append-author-parameter.jpg 550w, https://www.thetechoutlook.com/wp-content/uploads/2021/05/append-author-parameter-300x170.jpg 300w" sizes="auto, (max-width: 550px) 100vw, 550px" /></p>
<p>This will redirect to this page</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-16277 aligncenter" src="https://www.thetechoutlook.com/wp-content/uploads/2021/05/author-revealed.jpg" alt="" width="550" height="293" srcset="https://www.thetechoutlook.com/wp-content/uploads/2021/05/author-revealed.jpg 550w, https://www.thetechoutlook.com/wp-content/uploads/2021/05/author-revealed-300x160.jpg 300w" sizes="auto, (max-width: 550px) 100vw, 550px" /></p>
<p>A few specialists guarantee that uncovering WordPress usernames isn&#8217;t a security hazard. As per them, making a solid secret key and utilizing two factor confirmation is the correct approach. However, I say there&#8217;s nothing incorrectly sequestered from everything however much data as could be expected from programmers. Possibly on the off chance that somebody is genuinely resolved to know my username, they can. However, that doesn&#8217;t mean I need to make it simple for them! I need expected assailants to attempt to break into my site. Ideally, this will prevent 90% of them.</p>
<p>In the event that programmers don&#8217;t have the foggiest idea about your username, they will not spam your site attempting to figure your secret word. This implies less burden on your worker. I&#8217;ve been cut down once before by programmers DDoS&#8217;ing my login page. I would prefer not to hazard that once more.</p>
<p>So how would we close this escape clause? There are two different ways to keep WordPress from uncovering your creator name through the boundary hack.</p>
<h1>Fix 1: Modifying .htaccess</h1>
<p>This is my favored procedure since it&#8217;s a lot quicker than the other option. By making a straightforward .htaccess rule, you can promptly impede all endeavors to get to your WordPress username through the ?creator boundary. In the event that you approach it, open the covered up &#8220;.htacces&#8221; record in the root registry of your WordPress establishment, and glue in the accompanying code toward the end:</p>
<blockquote><p>RewriteEngine On RewriteCond %{REQUEST_URI} !^/wp-admin [NC] RewriteCond %{QUERY_STRING} author=\d RewriteRule ^ /? [L,R=301]</p></blockquote>
<p>This is how the code will look like after you have made the changes to the .htaccess file</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-16278 aligncenter" src="https://www.thetechoutlook.com/wp-content/uploads/2021/05/add-rewrite-rules.jpg" alt="" width="550" height="319" srcset="https://www.thetechoutlook.com/wp-content/uploads/2021/05/add-rewrite-rules.jpg 550w, https://www.thetechoutlook.com/wp-content/uploads/2021/05/add-rewrite-rules-300x174.jpg 300w" sizes="auto, (max-width: 550px) 100vw, 550px" /></p>
<h1>Fix 2: Adding a Code Snippet to WordPress</h1>
<p>The subsequent strategy is to add a code scrap to WordPress that achieves something similar. In the event that you don&#8217;t have the foggiest idea how, read my previous bit by bit instructional exercise on the most proficient method to do this. Here is the code you need to glue into your custom module or functions.php:</p>
<blockquote>
<pre class="wp-block-preformatted">function redirect_to_home_if_author_parameter() {

	$is_author_set = get_query_var( 'author', '' );
	if ( $is_author_set != '' &amp;&amp; !is_admin()) {
		wp_redirect( home_url(), 301 );
		exit;
	}
}
add_action( 'template_redirect', 'redirect_to_home_if_author_parameter' );</pre>
</blockquote>
<p>Like the .htaccess code, this does the very same thing. It verifies whether you&#8217;re not in the administrator region, and whether somebody is attempting to get to the creator name by means of the &#8220;?creator&#8221; boundary. Assuming this is the case, it diverts back to the landing page.</p>
<p>The thing that matters is that this executes at the WordPress level, and is consequently marginally more wasteful than the main strategy. Yet, on the off chance that you don&#8217;t approach .htaccess, it&#8217;s the solitary alternate way. Checking your entrance logs will uncover precisely the same thing paying little heed to which strategy you pick.</p>
<p>So while some may reject that noteworthy usernames is a security danger, my rule is that the harder you make it for somebody to nose about your site, the better. Also, in the event that you need to forestall animal power assaults, and to keep programmers from discovering your WordPress username, one of these two bits of code will get the job done!</p>
<p>In case you&#8217;re taking a gander at truly benefiting from WordPress, you ought to consider specific facilitating. Various organizations have various arrangements, and you can see the correlations of the WordPress facilitating costs at one look.</p>
<h1>Fix 3: Use Cloudflare Page or Firewall Rules</h1>
<p>A ton of sites use Cloudflare in any case, so this is a simple arrangement. Simply add another page rule or a firewall rule to prohibit the risky URL. You can either divert the page to the landing page, or square it out and out. The free form of Cloudflare accompanies 3 free page rules and 3 free firewall decides that you&#8217;re presumably not utilizing in any case. So we should use them!</p>
<p>Technique 2: Using WordPress JSON REST Endpoints</p>
<p>Visit the accompanying URL on your WordPress site:</p>
<p>https://[yoursite]/wp-json/wp/v2/clients/1</p>
<p>Supplant [yoursite] with your site name. You ought to get something like this:</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-16280 aligncenter" src="https://www.thetechoutlook.com/wp-content/uploads/2021/05/Get-the-Username-via-wp-json.png" alt="" width="550" height="263" srcset="https://www.thetechoutlook.com/wp-content/uploads/2021/05/Get-the-Username-via-wp-json.png 550w, https://www.thetechoutlook.com/wp-content/uploads/2021/05/Get-the-Username-via-wp-json-300x143.png 300w" sizes="auto, (max-width: 550px) 100vw, 550px" /></p>
<p>That is your WordPress username on display! This is on the grounds that WordPress uncovered certain REST APIs as a matter of course and this permits anybody to specify the clients by means of JSON.</p>
<p>Fix: Disable by means of Code</p>
<p>Luckily, we can simply impair these endpoints by means of this basic code scrap:</p>
<blockquote>
<pre class="wp-block-preformatted">function disable_rest_endpoints ( $endpoints ) {
    if ( isset( $endpoints['/wp/v2/users'] ) ) {
        unset( $endpoints['/wp/v2/users'] );
    }
    if ( isset( $endpoints['/wp/v2/users/(?P&lt;id&gt;[\d]+)'] ) ) {
        unset( $endpoints['/wp/v2/users/(?P&lt;id&gt;[\d]+)'] );
    }
    return $endpoints;
}
add_filter( 'rest_endpoints', 'disable_rest_endpoints');</pre>
</blockquote>
<p>The post <a href="https://www.thetechoutlook.com/tech-blogs/want-to-know-how-hackers-find-your-wordpress-username-details-inside/">Want to know how hackers find your wordpress username? Details Inside</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/tech-blogs/want-to-know-how-hackers-find-your-wordpress-username-details-inside/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hurl a flood of attacks on compromised WordPress pages by cyber criminals</title>
		<link>https://www.thetechoutlook.com/news/hurl-a-flood-of-attacks-on-compromised-wordpress-pages-by-cyber-criminals/</link>
					<comments>https://www.thetechoutlook.com/news/hurl-a-flood-of-attacks-on-compromised-wordpress-pages-by-cyber-criminals/#respond</comments>
		
		<dc:creator><![CDATA[Kaushiki Ghosh]]></dc:creator>
		<pubDate>Sat, 28 Nov 2020 07:58:45 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cyber Attack]]></category>
		<category><![CDATA[cyber criminals]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=9033</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb.jpeg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb.jpeg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-300x169.jpeg 300w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-1024x576.jpeg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-768x432.jpeg 768w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-150x84.jpeg 150w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-600x338.jpeg 600w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-696x392.jpeg 696w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-1068x601.jpeg 1068w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-747x420.jpeg 747w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>With over 50,000 plugins and themes, WordPress is one of the most shared content management systems (CMSes) in the world, enabling pros and novices alike to create excellent websites with ease. But WordPress is also a focus of cyber-criminals finding ways to unleash their disruptive operations, with great success and readily available production options. SEO [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/hurl-a-flood-of-attacks-on-compromised-wordpress-pages-by-cyber-criminals/">Hurl a flood of attacks on compromised WordPress pages by cyber criminals</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb.jpeg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb.jpeg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-300x169.jpeg 300w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-1024x576.jpeg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-768x432.jpeg 768w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-150x84.jpeg 150w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-600x338.jpeg 600w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-696x392.jpeg 696w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-1068x601.jpeg 1068w, https://www.thetechoutlook.com/wp-content/uploads/2020/11/keyvisual-cyber-security-16to9-srgb-747x420.jpeg 747w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p class="wp-block-paragraph">With over 50,000 plugins and themes, WordPress is one of the most shared content management systems (CMSes) in the world, enabling pros and novices alike to create excellent websites with ease. But WordPress is also a focus of cyber-criminals finding ways to unleash their disruptive operations, with great success and readily available production options.</p>



<figure class="wp-block-image is-style-default"><img decoding="async" src="https://compliance4all14.files.wordpress.com/2019/07/keyvisual-cyber-security-16to9-srgb.jpeg?w=1200" alt="cyber attacks – Compliance4all"/></figure>



<p class="wp-block-paragraph"><strong>SEO Spamming continues to be a top objective</strong></p>



<p class="wp-block-paragraph">For branded blogs, the hijacking of WordPress for SEO spamming raises significant problems.</p>



<ul class="wp-block-list"><li>In a newly uncovered event, a new cyber crime group leveraged weak WordPress pages to install scammy e-commerce stores to lower the rating and credibility of a site&#8217;s search engine.</li><li>Via brute-force attacks, the attackers gained access to the site&#8217;s admin account, after which they overwrote the main index file of the site and added malicious javascript.</li><li>To maintain a steady influx of SEO spam connections, researchers have also found that attackers insert malicious PHP files into WordPress pages.</li></ul>



<figure class="wp-block-image is-style-default"><img decoding="async" src="https://heimdalsecurity.com/blog/wp-content/uploads/botnet-1.png" alt="How to DDoS Like an Ethical Hacker"/></figure>



<p class="wp-block-paragraph"><strong>Vulnerable themes and plugins fuel more attacks</strong>&nbsp;</p>



<p class="wp-block-paragraph">In addition to SEO spamming, WordPress plugins provide cybercriminals with a handy avenue to attack.</p>



<ul class="wp-block-list"><li>An ongoing large-scale attack involving mass scanning of WordPress pages with Epsilon System themes vulnerable to Feature Injection attacks was recorded on November 17 by Word fence researchers.</li><li>These insecure themes, built on more than 150,000 pages, could lead to a complete site takeover.</li><li>Also, instances of insecure WordPress plugins such as Ultimate Member and Welcart e-Commerce were found to be impacted by extreme vulnerabilities during early November that could cause attackers to hijack pages.</li></ul>



<p class="wp-block-paragraph"><strong>In this mess, WordPress is not alone</strong></p>



<ul class="wp-block-list"><li>Equally lucrative options for cyber-attacks are not only WordPress but other CMSes like Drupal and Joomla.</li><li>Recently, administrators of sites operating on Drupal were advised to patch a safety hole that depended on the trick of the double extension.</li><li>Drupal developers believed that the weakness was because sure&#8221; file names were not sanitized by the Drupal CMS, enabling any malicious files to slip through.</li></ul>



<p class="wp-block-paragraph"><strong>Main Takeaways</strong></p>



<p class="wp-block-paragraph">It is no wonder that unpatched bugs in the core applications of WordPress are driving cyber attackers&#8217; disruptive ambitions. Plugging security vulnerabilities at the right time and following best cyber security practices is also a solution to cyber attacks to secure WordPress pages.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/hurl-a-flood-of-attacks-on-compromised-wordpress-pages-by-cyber-criminals/">Hurl a flood of attacks on compromised WordPress pages by cyber criminals</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/hurl-a-flood-of-attacks-on-compromised-wordpress-pages-by-cyber-criminals/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
