5 Jul 2021

Web Host A2’s 50,000+ Install WordPress Plugin To Help Secure Websites Lacks Basic Security

A week ago we looked at a WordPress plugin promoting that it could improve the security of websites, while the plugin itself lacked basic security. It certainly isn’t alone in that. Take the web host A2’s A2 Optimized WP plugin, which is marketed as:

A2 Optimized is designed to make it quick and easy to speed up and secure your website by installing and configuring several well known, stable optimizations with a few quick clicks. [Read more]

22 Apr 2019

Vulnerability Details: Information Disclosure in A2 Optimized WP

Several days after version 2.0.10.9 of the plugin A2 Optimized WP was released the developer added the changelog for it “Fixes security issue that may expose wp-config.php contents” and an upgrade notice, “Important security update”. Please upgrade immediately.” Looking at the changes made we found that the changelog entry accurately reflected what is at issue.


[Read more]