WP Engine

Solutions
AgencyEnterpriseSmall & Medium BusinessMarketer
How WP Engine supports marketers.Benefits for marketers.Features that help you innovate.
Developer
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Explore Our Platform
Insights
Thought LeadershipTopics

Read articles, trends, and insights on these topics from leaders in marketing and technology.

Creative AgilityEnterprise PerformanceActionable IntelligenceEcosystem Integration
Resources

Access ebooks, whitepapers, webinars, and other knowledge from our ecosystem of digital experts.
Visit Resource Center.

Delivering a Slam Dunk Experience on WordPressEbook: The Ultimate Guide to WordPress Plugins15 Common WordPress Mistakes Agencies and their Clients Make
Case Studies
About
Our CompanyOur PlatformLatest News

Access the latest news from inside WP Engine.
Visit the Newsroom.

WP Engine Secures Strategic Growth Investment From Silver LakeWP Engine Unveils First WordPress Digital ExperienceWP Engine Expands Global Presence with New Office in Brisbane
Media Center

Get announcements and resources about WP Engine.

Press Releases
Careers at WP Engine
Pricing
Sales Questions?

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Compare Plans
Need Support?
Support DocumentationBilling HelpSupport

We offer support 24 hours a day, 7 days a week, 365 days a year. Log in to get expert one-on-one help.

Log in for support

Sales Questions

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Sign in
Sign in
Search

Search

Compare Plans
Call Sales +1-512-201-4819
Menu
AgencyEnterpriseSmall & Medium BusinessMarketers
How WP Engine supports marketers.Benefits for marketersFeatures that help you innovate.
Developers
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Our PlatformPricingResource CenterOur CompanySolution CenterThought LeadershipDocumentationCareers
1.5 Million Sites Defaced Through REST API Vulnerability

1.5 Million Pages Defaced Through REST API Vulnerability

Darcy Wheeler 2.10.2017

In late January 2017, WordPress 4.7.2 was released, containing security patches that addressed four different vulnerabilities. Three of the vulnerabilities were disclosed at the time of the release, while WordPress privately contacted WordPress hosts with information about ways to protect users.

It was later revealed that the most critical issue of the bunch is a vulnerability in a REST API endpoint. This flaw has allowed hackers to break in to modify the content of any site running WordPress versions 4.7.0 and 4.7.1. So far, 20 hacking groups have defaced over 1.5 million web pages and thousands of websites running on these two outdated versions.

The vulnerability was discovered by Sucuri researchers, who worked with WordPress and other WAF vendors to build a fix in the 4.7.2 update. (See here for WordPress’ full disclosure.)

1.5 Million Sites Defaced Through REST API Vulnerability

Source: Threat Post

The REST API content endpoints were first introduced to WordPress 4.7.0 in December 2016. This means sites running on versions 4.7.0 and 4.7.1 must be updated to the latest WordPress version to avoid the risk of malicious content injection.

WP Engine customers need not worry as we’ve been issuing patches across the platform to upgrade installs to the next stable version. As soon as a new version of WordPress rolls out, we automatically upgrade your site for you so it contains the latest security patches. Automated security updates are part of our promise to deliver the most secure WordPress experience possible.

See here for more information on secure WordPress hosting with WP Engine. 


A photography and art enthusiast, in her spare time she enjoys traveling, practicing yoga, designing items for her craft store, and trying new cooking recipes. Follow her on Twitter @darewhee.

More WordPress news from WP Engine

Harden the Heart of Your WordPress Site [Webinar]How Many Trees Has Ecommerce Saved?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Subscribe

    Subscribe to our blog to get great tips for your WordPress site.

  • Favorite Tweets by @wpengine
  • Sign In

    Solutions

    • Agency
    • Enterprise
    • SMB
    • Marketer
    • Developer

    Insights

    • Blog
    • Torque
    • Velocitize

    About

    • Our Company
    • Leadership Team
    • Our Platform
    • Careers
    • Affiliates
    • Contact
    • Legal
    • Newsroom
    • Privacy Policy

    Resources

    • Resource Center
    • Documentation
    • Solution Center
    • Find an Agency

    WP Engine

    504 Lavaca Street, Suite 1000
    Austin, TX 78701

    Sales

    +1-512-201-4819
    [email protected]
    7am–7pm CST

    Billing

    [email protected]

    • Facebook
    • Twitter
    • LinkedIn
    • YouTube
    • Instagram
    • RSS
    © 2013—2025 WPEngine, Inc. All rights reserved.
    WP ENGINE®, VELOCITIZE®, TORQUE®, EVERCACHE®, and the cog logo service marks are owned by WPEngine, Inc.