19 Jan 2023

Cutting Through Wordfence’s FUD on Millions of Attack Attempts Against WordPress Websites

It isn’t uncommon to see comments online from people scared after a WordPress security solution, say, the Wordfence Security plugin, has alerted them that the solution has blocked a large amount of hacking attempts. The best advice as to what they should do in that situation is to a) ignore the alerts and b) find a new solution that isn’t trying to scare them through fear, uncertainty, and doubt (FUD). To get a better idea of why that is, let’s look at a recent blog post from the aforementioned Wordfence.

Inaccurate Vulnerability Information

In a post titled Holiday Attack Spikes Target Ancient Vulnerabilities and Hidden Webshells, Wordfence claimed that hackers were targeting a vulnerability in a plugin named Downloads Manager (not to be confused with Download Manager): [Read more]