WordPress.org began testing two-factor authentication (2FA) as an opt-in feature in May 2023. The interface and functionality are still in beta but it’s operational. This week contributors have expanded support for 2FA with a new interface for adding security keys, which are more secure than the one-time passwords. A logged in user can set up […]
All-In-One Security (AIOS), a plugin active on more than a million WordPress sites, was found to be logging plaintext passwords from login attempts in the database and has patched the security issue in version 5.2.0. In a post titled “Cleartext passwords written to aiowps_audit_log” published to the plugin’s support forum two weeks and five days […]