WP Builds Newsletter #55 – Multiple plugins hacked, plugin updates and MySpace loses data

This weeks WordPress news – Covering The Week Commencing 18th March 2019:

WordPress Core

WordPress Ends Support for PHP 5.2 – 5.5, Bumps Minimum Required PHP Version to 5.6
“WordPress has officially ended support for PHP 5.2 – 5.5 and bumped its minimum required PHP version to 5.6. The plan announced last December was to bump the minimum required version in early 2019 and, depending on the results, bump it again to PHP 7 in December 2019. Sites on PHP 5.5 or earlier can still get security updates but will not be able to upgrade to the latest major WordPress version…”

Gutenberg 5.3 Introduces Block Management, Adds Nesting to the Cover Block
“Gutenberg 5.3 was released today with basic block management, a feature that will be included in WordPress 5.2. It is a new modal that can be launched from the vertical ellipses menu, inspired by Rich Tabor’s CoBlocks implementation. Users can turn individual blocks on/off or even entire sections, such as Common Blocks, Formatting, and Embeds. Block management should help users avoid the bloat that happens when installing block collections with more blocks than they need…”

The Improved Fatal Error Protection
“Following the post on Site Health mechanisms released in WordPress 5.1, the feature labelled “Fatal Error Protection” (see #44458) was reverted, resulting in it not ending up as part of that release. This was necessary due to several security concerns, partly discovered by the team, partly by third-party security experts…”

Deploy WordPress Plugins from GitHub to the WordPress.org Plugin Repository
“10up has released a GitHub Action that enables developers to deploy to the WordPress.org Plugin repository by tagging a new version on GitHub. Helen Hou-Sandí, 10up’s Director of Open Source Initiatives, explained how it works…”


Social Warfare Plugin Zero-Day: Details and Attack Data
“Vulnerability Details – The plugin features functionality that allows users to clone its settings from another site. However, this functionality was not restricted to administrators or even logged-in users. An attacker is able to input a URL pointing to a crafted configuration document, which overwrites the plugin’s settings on the victim’s site…”

Hackers Abusing Recently Patched Vulnerability In Easy WP SMTP Plugin
“Over the weekend, a vulnerability was disclosed and patched in the popular WordPress plugin Easy WP SMTP. The plugin allows users to configure SMTP connections for outgoing email, and has a userbase of over 300,000 active installs. The vulnerability is only present in version 1.3.9 of the plugin, and all of the plugin’s users should update to as quickly as possible to address the flaw…”


WordCamp Miami Draws 100+ for Kid’s Camp, Plans to Host Standalone Kid’s WordPress Conference in Summer 2019
“The 11th edition of WordCamp Miami was held this past weekend, a three-day event that featured multiple learning workshops and six different tracks. The speaker ratio was 50% male and 50% female, and nearly half of the speakers were new to WordCamp Miami.,,”

How to Copyright Your Website’s Content
“Your website’s content is valuable, especially if it’s tied to your income. Therefore, protecting it from people who might want to copy and redistribute it without your permission is vital. This will help you maintain your site’s and business’ integrity, and avoid missing out on revenue…”


Brizy Pro 0.0.19: 17 new premium layout packs
“In our continuous effort to make Brizy the tool of choice when it comes to building stunning websites, I’d glad to tell you that we’ve just added 17 new premium layout packs that will let you kick start client websites in minutes. That is another 99 layouts on top of the 56 we already have…”

Smush Now Has Lazy Loading… and it’s Free!
“If you thought Smush couldn’t get any better after 3.0, think again. Our CDN upgrade unlocked the future of site speed and WordPress performance – instantaneously delivering next-gen images at the right size for every container from our global image delivery network – 45 points of presence at 40 Tbps…”

Why I Hated NodeJS, Gulp, And Sass, And What I’m Doing About It
“It’s becoming increasingly difficult to tout yourself as a true “Pro” in the WordPress web development scene without some form of contact with these NodeJS powered package managers, task managers, and build tools. We’ve gone from debating our favorite code editors to arguing over which CSS pre-processor is king. Life was so much easier when all we had to deal with was a simple folder filled with CSS, PHP, and JS files…”

Client Portal – Private File Uploads
“This is a new feature introduced in CP version 4.6. This allows you to select Private file upload when selecting the module type. This support doc will explain how to use it and some notes to be aware of…”

Have you got WordPress plugin fatigue?
“If you’re a WordPress user then you’ve used heaps of plugins in the past. They enable WordPress to do anything don’t they? That’s WordPress’ greatest strength and it’s largest curse! There are so many to choose from, and all that choice leads to plugin fatigue. You never quite know if the plugin that you’re using is ‘the best’ and so you’re constantly on the look out for a newer, shinier plugin. The problem is that this cycle does not have an end…”

Not WordPress, but useful anyway…

Myspace lost all the music its users uploaded between 2003 and 2015
“It’s been a year since the music links on Myspace stopped working; at first the company insisted that they were working on it, but now they’ve admitted that all those files are lost: ‘As a result of a server migration project, any photos, videos, and audio files you uploaded more than three years ago may no longer be available on or from Myspace. We apologize for the inconvenience’…”

the WP Builds news is brought to you today by Kinsta.

