Join the Online WordPress Portsmouth Meetup on 20th November 2024 for a discussion on Security Best Practices for your WordPress websites.
After a brief introduction by the organisers we’ll open the meeting to a general discussion on the main topics of interest, allowing members to share their experiences – both good and bad – on the subject of WordPress security.
Topics we may cover include:
- Threats
- Hosting
- Backup & restore
- Two Factor Authentication
- Security plugins
- Monitoring
- A to Z of security
- Top 10 tips from around the world
🏕️ WHO CAN ATTEND?
All levels of experience of WordPress and website publishing welcome. We are a learning and development group. We welcome WordPress beginners.
Please sign-up if you intend to join the Meetup. If you are new to the group, please can you complete your Meetup profile to help us plan topics.
⏱ AGENDA
The event starts at 7pm BST.
| Time | Item |
|---|---|
| 7.00pm | Connect to Zoom. Bring your own drink and chair |
| 7.10pm | Organisers’ introduction to the online meeting |
| 7.15pm | Security Best Practices |
| 8:15pm | Topic for the next meetup |
| 8.20pm | Wrap-up |
| 8.30pm | Close |
Slides
As usual slides will be available here.
Threats
Here’s the full extract from ChatGPT’s response to “What are the biggest threats to website security?”
The biggest threats to website security stem from a mix of vulnerabilities in code, infrastructure, and user interaction. Here are some of the most common threats:
- SQL Injection: Attackers exploit vulnerabilities in a website’s database queries by inserting malicious code into an input field. This allows them to view, edit, or delete sensitive data.
- Cross-Site Scripting (XSS): This occurs when malicious scripts are injected into webpages viewed by other users. It can lead to data theft, session hijacking, and other malicious activities.
- Cross-Site Request Forgery (CSRF): This attack tricks users into performing actions they did not intend by exploiting their authenticated sessions. For instance, an attacker might manipulate a user to unknowingly change their account settings.
- Broken Authentication and Session Management: If authentication mechanisms (like password storage) or session controls are not securely implemented, attackers can take over accounts, often by stealing session tokens.
- Insecure Direct Object References (IDOR): If users can access data by simply changing parameters in URLs (e.g., viewing another user’s information by modifying their user ID), this can lead to unauthorized data access.
- Remote Code Execution (RCE): A severe vulnerability that allows attackers to execute arbitrary code on the server, potentially leading to full control over the website and server.
- File Upload Vulnerabilities: Allowing users to upload files without strict validation can let attackers upload malicious scripts or executables, leading to data breaches or malware injections.
- Distributed Denial of Service (DDoS) Attacks: Attackers overload a website with traffic, rendering it unavailable to legitimate users. This is often used to disrupt services rather than gain unauthorized access.
- Misconfigured Security Headers: Missing or incorrect security headers (like Content Security Policy or X-Frame-Options) can expose websites to XSS, clickjacking, and other attacks.
- Weak Password Policies: Allowing weak passwords or lacking brute-force protection can make it easier for attackers to gain unauthorized access through credential-stuffing attacks.
- Outdated Software and Libraries: Using outdated CMSs, plugins, or libraries can expose websites to known vulnerabilities. Regular updates are crucial for maintaining security.
- Social Engineering and Phishing: Attackers target users or admins to gain access to credentials or sensitive information through deceptive tactics.
Proactive measures like secure coding practices, regular vulnerability assessments, strong access controls, and constant monitoring can greatly reduce these risks.
This month’s question
In your opinion which of the following is the most important consideration when it comes to WordPress website security.
- Hosting
- Backup & Restore
- Two Factor Authentication
- Security plugins
- Other.
Discuss!
References
The last meetup we had on security was 6 years ago. Is it really that long?
- https://www.hostinger.com/tutorials/how-to-secure-wordpress
- https://wpastra.com/guides-and-tutorials/wordpress-security-guide/
- https://www.wpbeginner.com/wordpress-security/
- https://www.siteground.co.uk/wordpress-security-ebook
- https://my.siteground.com/support/tutorials/wordpress/security/
- https://www.bluehost.com/help/article/basic-site-security-checklist
- https://www.bluehost.com/blog/website-security-how-to-keep-your-site-safe-from-digital-threats/
- https://jetpack.com/blog/wordpress-security-tips-and-best-practices/
- PS. 20th November is Name your PC Day
- From Learn.WordPress.org
- https://learn.wordpress.org/lesson/7-tips-to-improve-website-security/
- https://learn.wordpress.org/tutorial/7-tips-to-improve-website-security/
- https://learn.wordpress.org/lesson/essential-security-plugin-features-and-settings/
- https://learn.wordpress.org/tutorial/extending-wordpress-common-security-vulnerabilities/
- https://learn.wordpress.org/lesson/tools-site-health/
- More from WP-Pompey
Information
Topics for future meetups
Planned
- 18th December 2024 – Explore WordPress Playground https://wordpress.org/playground/
Future meetups – 2025
We’ve had some recommendations for future meetups.
- Developing an artists or portfolio site using WP.
- Explore WordPress 6.5, 6.6 and 6.7 highlights?
- Workthrough of the new block capabilities in WordPress 6.5, 6.6 & 6.8
- Guided walkthrough of Justin Tadlock’s tutorial on “Mixing and matching styles, colors, and typography in WordPress 6.6″
- In person social meetup and informal discussion event around a particular area of WP, with perhaps people getting to Portsmouth earlier and doing a trip up the Spinnaker Tower first.
What do you think of these topics?
What do you want to hear about next?
To find out what’s going on elsewhere see https://events.wordpress.org/upcoming-events/filtered/country/GB/

