Monday, 3 July 2017

SQL Injection Vulnerability in WP Statistics


Security Risk: Dangerous Exploitation Level: Easy/Remote
DREAD Score: 7/10
Vulnerability: SQL Injection
Patched Version: 12.0.8
As part of a vulnerability research project for our Sucuri Firewall, we have been auditing popular open source projects looking for security issues.
While working on the WordPress plugin WP Statistics, we discovered a SQL Injection vulnerability. This plugin is currently installed on 300,000+ websites.
Are You at Risk?
This vulnerability is caused by the lack of sanitization in user provided data. An attacker with at least a subscriber account could leak sensitive data and under the right circumstances/configurations compromise your WordPress installation.
If you have a vulnerable version installed and your site allows user registration, you are definitely at risk.
Technical Details
WordPress provides an API that enables developers to create content that users can inject to certain pages just using a simple shortcode:
[shortcode atts_1=”test” atts_2=”test”]
Among other functionalities, WP Statistics allows admin users to get detailed information related with the number of visits by just calling the shortcode below:
As you can see on
Source: https://managewp.org/articles/15459/sql-injection-vulnerability-in-wp-statistics




source https://williechiu40.wordpress.com/2017/07/03/sql-injection-vulnerability-in-wp-statistics/

Easy Ways to Check Disk Usage in WordPress


There is no such thing as “unlimited” disk space or bandwidth when it comes to web hosting. Shared WordPress hosts typically advertise this but still have limits in place behind the scenes if you read their terms of service (TOS). Over time your WordPress site can grow pretty fast, and eventually, you might hit your limits, whether it be 5 GB or 20 GB. And if you hit the magical “unlimited” quota, this is usually an email from your host saying you’re abusing their TOS. So today we will share with you a few ways to check disk usage in WordPress so you can clean up your sites. There are a lot of server commands that allow you to do this, but we are going to focus on some easy ways for those that may not be comfortable using SSH or aren’t as tech savvy. Calculating Disk Usage in WordPress
Before we dive into how to check your disk usage, it is important to understand that what we are referring to. In WordPress, disk usage is typically composed of two things; your files and database. Combined these make up your total disk usage that is being used on your server, that take up your allocated resources.
Files on the Server
WordPress files that take up disk
Source: https://managewp.org/articles/15458/easy-ways-to-check-disk-usage-in-wordpress




source https://williechiu40.wordpress.com/2017/07/03/easy-ways-to-check-disk-usage-in-wordpress/

How to Create User Generated Content for Your WordPress Website and Business


First off, what exactly is user generated content (UGC)? This is content that is created by your customers. It can be anything from a blog post, product reviews, photos, videos or comments. Content marketing is currently a top marketing strategy for most businesses. A report by Demand Gen shows that 47% of customers surveyed will read about three to five pieces of content prior before they consider reaching out to a company to get its products or services.
Creating content is time consuming and not every business owner has the time to create so much content to keep their customers happy. But you know what? Many of your customers are actually more than willing to create content for you. All you have to do is ask 🙂
Why You Should Encourage User Generated Content
There are a few other good reasons to encourage user generated posts including:
1. Relevancy
UGC will keep your website content relevant. People will only find your content useful if it’s relevant to them. Who knows what they want more than your customers? So listen to them.
2. Increased User Engagement
By allowing people to contribute to your website you make them feel important and a part of your website. In return, they
Source: https://managewp.org/articles/15455/how-to-create-user-generated-content-for-your-wordpress-website-and-business




source https://williechiu40.wordpress.com/2017/07/03/how-to-create-user-generated-content-for-your-wordpress-website-and-business/

Setup a WooCommerce Members-Only store with Paid Member Subscriptions


Why should you run a WooCommerce members-only store and when it is valuable to build one: you have a membership site and want to sell products to your private audience. The membership site can be a private community, a private or niche club, also if you are a multi-skilled entrepreneur or a best-selling author, that is sharing his knowledge beyond the traditional books (audible files, mentoring, educational programs).
How to turn your site into a members-only store
In order to turn your WordPress site into a members-only store, you should use two plugins that now are beautifully integrated, namely WooCommerce and Paid Member Subscriptions.
WooCommerce is an open source e-commerce plugin for WordPress, that is designed for small to large-sized online merchants using WordPress.
Paid Member Subscriptions, on the other hand, is a membership plugin that can be installed in only 3 minutes and 4 easy steps, by using Shortcodes for Member Registration, Content Restriction, and Membership Plans.
In order to have the features developed in this integration up and running on your site, you have to install and activate both Paid Member Subscription and WooCommerce:
Paid Member Subscription–
Source: https://managewp.org/articles/15457/setup-a-woocommerce-members-only-store-with-paid-member-subscriptions




source https://williechiu40.wordpress.com/2017/07/03/setup-a-woocommerce-members-only-store-with-paid-member-subscriptions/

How to Change the Category Base Prefix in WordPress

Do you want to change the category base prefix in WordPress? By default, WordPress automatically adds /category/ as a prefix to URLs for all category pages. In this article, we will show you how to change the category base prefix in WordPress. We will also talk about whether or not you should remove the base prefix altogether.

How to change the category base prefix in WordPress

What is Category Base Prefix? Should You Change It?

Each category on your WordPress site get its own page and RSS feed. You can view all posts filed under a category by visiting that category archive page.

By default, WordPress adds ‘category’ as base prefix to URLs for category pages. This helps differentiate pages and posts from category and tag archives.

For example, if you have a category called ‘News’ then its URL will look like this:

http://example.com/category/news/

Similarly, WordPress also adds tag prefix to URLs for tag archives.

http://example.com/tag/iphone/

This SEO friendly URL structure helps users and search engines understand what kind of page they are visiting.

Most websites don’t need to change the base prefix at all. However, if you are creating a niche site where you would like to use a different word or phrase for your categories, then you can change the category base prefix to reflect that.

Changing Category Base Prefix in WordPress

Changing category base prefix is quite simple in WordPress.

You need to visit Settings » Permalinks page and scroll down to the ‘Optional’ section.

Changing category base prefix in permalink settings

Here you can enter the prefix you would like to use next to the category base option. You can also change the tag base prefix if you want.

Don’t forget to click on the save changes button to store your settings.

Setting up Redirects After Changing Category Base Prefix

If you are changing category base prefix on a new website, then you don’t need to do anything. However, if you are doing this on an existing website, then users visiting the old category page will see a 404 error.

To fix this, you will need to setup redirect to make sure both search engines and regular visitors are properly redirected to the correct category page on your site.

First you will need to install and activate the Redirection plugin. For more details, see our step by step guide on how to install a WordPress plugin.

Upon activation, you need to visit Tools » Redirection page to setup redirect.

Setting up redirect after changing category prefix

Scroll down to ‘Add new redirection’ section.

First, you need to add /category/(.*) in the source URL field. After that you need to check the box next to the regular expression option.

In the target URL field, you need to add your new category base prefix like this /topics/$1. Don’t forget to replace topics with your new category prefix.

Click on the ‘Add Redirection’ button to save your changes.

That’s all. Now all your users and search engines will be redirected to the correct URLs using your new category prefix.

Removing The Category Base Prefix in WordPress

Many of our users have asked us about removing the category base prefix from WordPress URLs altogether. This will change your category URLs to look like this:

http://example.com/news/

This is not a good idea, and we recommend that you do not remove category base prefix.

Category base prefix helps both users and search engines distinguish between posts/pages and categories. Removing the prefix makes your URLs ambiguous which is not good for user experience or SEO.

You may also run into technical issues with various WordPress plugins. For example, if you have a category and a page with the same name or when you are using %postname% as your URL structure for single posts, then your site will experience infinite redirect loop causing the pages to never load.

However, if you still want to do this, then you need to install and activate FV Top Level Categories plugin. For more details, see our step by step guide on how to install a WordPress plugin.

The plugin works out of the box and will immediately remove the category base prefix from your category URLs.

We hope this article helped you learn how to change the category base prefix in WordPress. You may also want to see our list of most wanted WordPress tips, tricks, and hacks.

If you liked this article, then please subscribe to our YouTube Channel for WordPress video tutorials. You can also find us on Twitter and Facebook.

The post How to Change the Category Base Prefix in WordPress appeared first on WPBeginner.



source http://www.wpbeginner.com/wp-tutorials/how-to-change-the-category-base-prefix-in-wordpress/

WP Rocket Giveway to Celebrate Its 4th Anniversary


WP Rocket’s 4th birthday is getting closer. Like every year, we want to celebrate the event, but this time we thought about organising a contest. We are going to give away 4 Single WP Rocket licenses that you can download for free. Speaking of exceptional prizes, we want to make this one an incredible gift. Every license will be valid for 5 years. Meaning that not only are you going to win a free WP Rocket license, but you will profit from the 4 years of renewals included.
How can you participate in the contest?
Easy! All you have to do is subscribe to our newsletter. We will make a random draw on Monday July 10th at 10h00 (GMT +02:00).
We will contact winners directly by email and we’ll give them the instructions for downloading their free WP Rocket license.
To double your chances to win, please share this post on Facebook or Twitter, using one of these links :
3 reasons why you should use WP Rocket on your WordPress site
Minimal Configuration
WP Rocket’s configuration takes less than 5 minutes, compared to the average 30 minutes you usually need to configure other WordPress cache plugins. Furthermore, you don’t need any technical skill to use it and to make
Source: https://managewp.org/articles/15454/wp-rocket-giveway-to-celebrate-its-4th-anniversary




source https://williechiu40.wordpress.com/2017/07/03/wp-rocket-giveway-to-celebrate-its-4th-anniversary/

HTTP/2 server-push, faster or slower site?


Server-push is the new feature of the new HTTP2 protocol, which can push files to the client’s browser before the browser itself recognizes that those files would be needed. This avoids the usual HTTP request/response cycle that happened for each script or stylesheet, and the main point is to speed up your site’s loading time. The new HTTP2 protocol is used by about 14% (May 2017) of all internet sites, however, the server-push technology is not even used by near 1% because it is rather new but also because it is unable to speed up every site. So it’s about time to see if this technology can speed up the loading of your WordPress site or maybe slow down. How does the HTTP2 server-push work?
For instance, let’s say we have an HTML site with two images. When a visitor tries to load this site, and the site does not support server-push, then the visitor has to go three times to the server, once for the HTML site, and twice for the both images. If the site does support server-push, then the server can respond: "Hey, you need at least these two images, take them now so you don’t have to go back twice." It is easy to be understood, doesn’t it?
Which files do you
Source: https://managewp.org/articles/15453/http-2-server-push-faster-or-slower-site




source https://williechiu40.wordpress.com/2017/07/03/http2-server-push-faster-or-slower-site/