{"id":2698,"date":"2016-05-10T15:26:17","date_gmt":"2016-05-10T21:26:17","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2698"},"modified":"2016-05-10T15:26:29","modified_gmt":"2016-05-10T21:26:29","slug":"trend-micro-running-outdated-and-insecure-version-of-wordpress-on-their-blog","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/05\/10\/trend-micro-running-outdated-and-insecure-version-of-wordpress-on-their-blog\/","title":{"rendered":"Trend Micro Running Outdated and Insecure Version of WordPress on Their Blog"},"content":{"rendered":"<p>When it comes to the problems with cyber security one of the issues we see is that the wrong people are often getting the blame for its poor state.<\/p>\n<p>WordPress frequently gets unfairly criticized in a security context, while in a lot of ways they are really at the forefront of improving security of web software. Take for example the <a href=\"https:\/\/codex.wordpress.org\/Configuring_Automatic_Background_Updates\">automatic background updates feature<\/a>\u00a0that was released back in WordPress 3.7, which allows for security fixes to be applied million of websites quickly without requiring any user interaction.<\/p>\n<p>On the other side are security companies that seem to in a lot of cases care little for security and in some cases seem to peddling false hoods to increase their profits. One such recent example where a security company didn&#8217;t seem care about security was with Trend Micro, which had a password manager included with their antivirus software that had <a href=\"http:\/\/www.zdnet.com\/article\/trend-micro-password-manager-had-remote-command-execution-holes-and-dumped-data-to-anyone-project\/\">incredibly severe security issues<\/a>.<\/p>\n<p>When bring these to two examples up because they come to together with something we noticed recently. Trend Micro&#8217;s blog recently is\u00a0running an outdated and insecure version of WordPress:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2701\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/05\/trend-micro-wordpress-version.png\" alt=\"The Trend Micro blog is running WordPress 4.5\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/05\/trend-micro-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2016\/05\/trend-micro-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p><a href=\"https:\/\/wordpress.org\/news\/2016\/04\/wordpress-4-5-1-maintenance-release\/\">WordPress 4.5.1<\/a> was released on April 26 and <a href=\"https:\/\/wordpress.org\/news\/2016\/05\/wordpress-4-5-2\/\">4.5.2<\/a>, which fixed two security issue, was released on May 6.<\/p>\n<p>Seeing as those versions would\u00a0normally have been applied automatically within hours of their release due to the automatic background updates feature, either Trend Micro\u00a0unwisely disabled that feature or some bug is stopping that from happening in their case. If it is the later then Trend Micro\u00a0could actually help to improve the security of WordPress websites by working the WordPress developers to resolve that, so that others impacted by the issue could also start getting updates.<\/p>\n<p>Looking at the source code of the blog homepage&#8217;s you can see\u00a0that at least one of their plugins is also not up to date:<\/p>\n<blockquote><p>&lt;!&#8211; This site is optimized with the Yoast SEO plugin v3.2.3 &#8211; https:\/\/yoast.com\/wordpress\/plugins\/seo\/ &#8211;&gt;<\/p><\/blockquote>\n<p>The latest version of the <a href=\"https:\/\/wordpress.org\/plugins\/wordpress-seo\/\">Yoast SEO plugin<\/a> is 3.2.5 and that version fixed a <a href=\"https:\/\/www.wordfence.com\/blog\/2016\/05\/yoast-seo-vulnerability\/\">very low severity security issue<\/a> (the current version of that plugin has at least one other security issue that is fairly obvious if look into the vulnerability that was fixed).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to the problems with cyber security one of the issues we see is that the wrong people are often getting the blame for its poor state. WordPress frequently gets unfairly criticized in a security context, while in a lot of ways they are really at the forefront of improving security of web &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/05\/10\/trend-micro-running-outdated-and-insecure-version-of-wordpress-on-their-blog\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Trend Micro Running Outdated and Insecure Version of WordPress on Their Blog&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,35],"tags":[60],"class_list":["post-2698","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-outdated-web-software","tag-trend-micro"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2698"}],"version-history":[{"count":4,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2698\/revisions"}],"predecessor-version":[{"id":2703,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2698\/revisions\/2703"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}