<?xml version="1.0" encoding="utf-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
                <channel>
                    <atom:link href="https://my.wpnet.nz/announcements/rss" rel="self" type="application/rss+xml"/>
                    <title>WP NET Announcements</title>
                    <description>The latest updates and security notices for WP NET WordPress hosting customers</description>
                    <link>https://my.wpnet.nz/announcements</link>
                    
<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
    <title><![CDATA[Billing Issue]]></title>
    <link>https://my.wpnet.nz/announcements/737</link>
    <guid>https://my.wpnet.nz/announcements/737</guid>
    <pubDate>Thu, 26 Feb 2026 10:50:00 +1300</pubDate>
    <description><![CDATA[<p>Due to an issue with our billing system - the <a href="https://my.wpnet.nz/announcements/734/">Stripe Card Fee</a> is not currently being applied to invoices.</p>
<p>Stripe Card Fees will not be retroactively charged - they will be waived until the invoicing issue is remedied.</p>
<p>Please accept our apologies for this error and we appreciate your patience while we work to resolve the problem.</p>
<hr />
<p>If you have any questions or concerns, please contact us directly at <a href="mailto:contact@wpnet.nz">contact@wpnet.nz</a> or <a href="https://my.wpnet.nz/ticket">open a support ticket</a>.</p>
<p>Thank you.</p>
<p>WP NET Support</p>
<p> </p>]]></description>
</item>

<item>
    <title><![CDATA[ Happy Holidays from WP NET! ]]></title>
    <link>https://my.wpnet.nz/announcements/736</link>
    <guid>https://my.wpnet.nz/announcements/736</guid>
    <pubDate>Tue, 23 Dec 2025 18:12:00 +1300</pubDate>
    <description><![CDATA[<p>We hope you all have a great Christmas and summer holiday!</p>
<p>Thank you for your continued support through 2025!</p>
<p>WP NET Support is available throughout the holiday period, though we are running at reduced staffing levels, and responses may be delayed.</p>
<p>We return to normal from 12 January, 2026.</p>]]></description>
</item>

<item>
    <title><![CDATA[Reduced Stripe Card Fee]]></title>
    <link>https://my.wpnet.nz/announcements/735</link>
    <guid>https://my.wpnet.nz/announcements/735</guid>
    <pubDate>Mon, 03 Nov 2025 15:45:00 +1300</pubDate>
    <description><![CDATA[<p>Stripe has recently announced a reduction in domestic card processing fees for New Zealand.</p>
<p>Accordingly, we will be reducing the Stripe Card Fee that we charge.</p>
<ul>
<li>Card processing fees will <strong>reduce</strong> from 2.70% + NZ$0.30 <strong>to 2.65% + NZ$0.30</strong></li>
</ul>
<hr />
<p><strong>Note: </strong>WP NET only on-charges the Stripe Card Fee for payments of NZD$100 or more. The new rate is effective from 1 December 2025.</p>
<p> </p>]]></description>
</item>

<item>
    <title><![CDATA[Stripe Payments – Card Fee]]></title>
    <link>https://my.wpnet.nz/announcements/734</link>
    <guid>https://my.wpnet.nz/announcements/734</guid>
    <pubDate>Tue, 09 Sept 2025 08:42:00 +1200</pubDate>
    <description><![CDATA[<p>Effective 10 September 2025, a Stripe Card Fee will apply to all credit &amp; debit card payments of NZD$100 or more.</p>
<p>The Stripe Card Fee is 2.65% + $0.30. (as at 27/2/2026)</p>
<p>Payments made via NZ Bank Direct Debit (GoCardless) incur no processing fee. To avoid the Stripe Card Fee, please pay via GoCardless.</p>
<p>For help, please see Change Payment Method on the <a href="https://my.wpnet.nz/knowledgebase/9/">Payment &amp; Billing Options</a> Knowledgebase article.</p>
<p>If you need any help with changing payment method or setting up payments, please <a href="https://my.wpnet.nz/ticket">open a support ticket</a> and we’ll sort it for you ASAP.</p>]]></description>
</item>

<item>
    <title><![CDATA[Product Updates - September 2025]]></title>
    <link>https://my.wpnet.nz/announcements/733</link>
    <guid>https://my.wpnet.nz/announcements/733</guid>
    <pubDate>Mon, 18 Aug 2025 22:56:00 +1200</pubDate>
    <description><![CDATA[<p>We have several price changes to announce for September 2025. If you have any questions regarding these changes and how they affect you, please <a href="mailto:gb@wpnet.nz">contact me directly</a>.</p>
<p>For all the details, please see <a href="https://wpnet.nz/updates/09-2025/">Product Updates - September 2025</a>.</p>
<ul>
<li><a href="https://wpnet.nz/updates/09-2025/#wp-shield">WP Shield (Multisite)</a> – Price increase to NZD$60 / month.</li>
<li><a href="https://wpnet.nz/updates/09-2025/#wp-server">WP Server </a>– New pricing for all WP Server products.</li>
<li><a href="https://wpnet.nz/updates/09-2025/#card-fee">Stripe Card Fee</a> – A fee will apply to credit &amp; debit card payments of NZ$100 or more. No fee applies to Direct Debit (GoCardless) payments.</li>
<li><a href="https://wpnet.nz/updates/09-2025/#domain-fees">Domain Fees</a> – New pricing for several TLDs, including all .nz extensions.</li>
</ul>]]></description>
</item>

<item>
    <title><![CDATA[Debunking WordPress Security Myths]]></title>
    <link>https://my.wpnet.nz/announcements/732</link>
    <guid>https://my.wpnet.nz/announcements/732</guid>
    <pubDate>Thu, 10 Jul 2025 11:41:00 +1200</pubDate>
    <description><![CDATA[<p>Delicious Brains have recently published <a href="https://deliciousbrains.com/debunking-wordpress-security-myths-what-developers-often-miss/">an excellent article</a> on WordPress security, some myths, misconceptions and recommended best practices.</p>]]></description>
</item>

<item>
    <title><![CDATA[Domain Registration Price Changes]]></title>
    <link>https://my.wpnet.nz/announcements/731</link>
    <guid>https://my.wpnet.nz/announcements/731</guid>
    <pubDate>Thu, 03 Jul 2025 12:31:00 +1200</pubDate>
    <description><![CDATA[<p>This is a preliminary notice that we have updated prices for several domain extensions. These price changes are in effect from today for domain registration, renewals and transfers.</p>
<p><strong>A full <a href="https://wpnet.nz/updates">Product Update</a> and email notification will be sent in the coming days.</strong></p>
<hr />
<p>Due to price increases from our wholesale domain registrar, effective from 1 July 2025, we are adjusting our retail prices accordingly.</p>
<p>Cost increases range from 10-22%.</p>
<p>For full price details of all available domain extensions (TLDs), please see the <a href="https://wpnet.nz/domain-checker/">Domain Checker page</a>. </p>]]></description>
</item>

<item>
    <title><![CDATA[Changes to account suspension and termination policy]]></title>
    <link>https://my.wpnet.nz/announcements/730</link>
    <guid>https://my.wpnet.nz/announcements/730</guid>
    <pubDate>Mon, 16 Jun 2025 08:53:00 +1200</pubDate>
    <description><![CDATA[<p>Please note that we have changed our policy regarding overdue account suspensions and terminations.</p>
<p>The period of time that an account can remain in arrears before the service(s) are suspended is now <strong>14 days</strong>.</p>
<p>Accounts in arrears for <strong>30 days</strong> will have the service(s) terminated.</p>
<p>Please see our <a href="https://wpnet.nz/terms-and-conditions/#termination-billing">Terms &amp; Conditions</a> for details.</p>]]></description>
</item>

<item>
    <title><![CDATA[WordPress 6.8 “Cecil” released!]]></title>
    <link>https://my.wpnet.nz/announcements/729</link>
    <guid>https://my.wpnet.nz/announcements/729</guid>
    <pubDate>Wed, 16 Apr 2025 10:04:00 +1200</pubDate>
    <description><![CDATA[<p>The latest version of WordPress, version 6.8 is now available.</p>
<p>You can read about this release on the <a href="https://wordpress.org/news/2025/04/cecil/">WordPress.org blog post</a>.</p>
<p>Detailed <a href="https://wordpress.org/documentation/wordpress-version/version-6-8/">release notes</a> are also available on the WordPress.org Docs page.</p>]]></description>
</item>

<item>
    <title><![CDATA[WordPress 6.8 will use bcrypt for password hashing]]></title>
    <link>https://my.wpnet.nz/announcements/728</link>
    <guid>https://my.wpnet.nz/announcements/728</guid>
    <pubDate>Wed, 19 Mar 2025 15:59:00 +1300</pubDate>
    <description><![CDATA[<p>A long overdue, but nonetheless significant security update is coming in WordPress 6.8.</p>
<hr />
<p>The underlying algorithm that’s used to hash and store user passwords in the database will be changed in WordPress 6.8 from phpass portable hashing to bcrypt. The adoption of bcrypt hardens password security in WordPress by significantly increasing the computational cost of cracking a password hash.</p>
<p>In addition, application passwords, user password reset keys, personal data request keys, and the recovery mode key will switch from using phpass to the cryptographically secure but fast BLAKE2b hashing algorithm via Sodium.</p>
<hr />
<p><a href="https://make.wordpress.org/core/2025/02/17/wordpress-6-8-will-use-bcrypt-for-password-hashing/">Read more on the Make WordPress blog post</a>.</p>]]></description>
</item>

<item>
    <title><![CDATA[WordPress 6.7 "Rollins" has been released!]]></title>
    <link>https://my.wpnet.nz/announcements/727</link>
    <guid>https://my.wpnet.nz/announcements/727</guid>
    <pubDate>Wed, 13 Nov 2024 16:33:00 +1300</pubDate>
    <description><![CDATA[<p>The latest version of WordPress, version 6.7 is now available.</p>
<p>You can read about this release on the <a href="https://wordpress.org/news/2024/11/rollins/">WordPress.org blog post</a>.</p>
<p>Detailed <a href="https://wordpress.org/download/releases/6-7/">release notes</a> are also available on the WordPress.org Docs page.</p>]]></description>
</item>

<item>
    <title><![CDATA[Elementor Pro update causing fatal errors]]></title>
    <link>https://my.wpnet.nz/announcements/726</link>
    <guid>https://my.wpnet.nz/announcements/726</guid>
    <pubDate>Tue, 29 Oct 2024 14:47:00 +1300</pubDate>
    <description><![CDATA[<div class="alert alert-warning">
<p><strong>Some customers are reporting fatal PHP errors on their sites in the last couple of hours.</strong></p>
</div>
<p>Investigation reveals that an Elementor Pro update (3.25) appears to be breaking 3rd party integrations, and so numerous themes and plugins that include support for Elementor Pro are throwing critical errors after updating to v3.25.0.</p>
<p>Rolling back to Elementor Pro v3.24.4, fixes the problem.</p>
<p>At time of writing, the Elementor Pro changelog makes no mention of the problem, and no version past 3.25 is available.</p>
<p><a href="https://elementor.com/pro/changelog/">https://elementor.com/pro/changelog/</a></p>
<p>If you use Elementor Pro, but have not yet updated to v3.25, we recommend that you <strong>hold off on installing the update</strong> for a day or so, or until you see that the latest version is at least 3.25.1.</p>
<p>If you're experiencing any issues with your Elementor based sites, or have need any assistance, please <a href="https://wpnet.nz/ticket">open a support ticket</a> and we'll be happy to help.</p>
<p> </p>]]></description>
</item>

<item>
    <title><![CDATA[Change to WP Site Plugin Update Notifications]]></title>
    <link>https://my.wpnet.nz/announcements/725</link>
    <guid>https://my.wpnet.nz/announcements/725</guid>
    <pubDate>Wed, 09 Oct 2024 19:25:00 +1300</pubDate>
    <description><![CDATA[<div class="alert alert-info">
<p><strong>TLDR:</strong> The regular "WordPress Updates Notification" emails for WP Site customers are being discontinued. Vulnerability Reports will now be sent instead. Read on for details.</p>
</div>
<p>Customers on our WP Site (Plesk) hosting plans will be familiar with the email notifications that are sent, informing you of <strong>all</strong> new updates for your WordPress plugins and themes.</p>
<p>We are aware that some of our customers find these email notifications to be a nuisance, while others find them useful as a reminder to jump into their WordPress Dashboard now and again and install pending updates.</p>
<p>We appreciate the concerns that some customers have raised - that these emails can be too frequent - and we have been working on a solution, trying to find the balance between security and keeping our customers informed, while not pestering them with too many emails.</p>
<h4>Current Policy</h4>
<p><strong>As a reminder - on WP Site plans - only updates that fix known vulnerabilities are installed automatically</strong>. General, day-to-day updates are left to the customer to install on their own schedule.</p>
<p>For quite a while now, our policy has been to <strong>not</strong> send email notifications about these discovered vulnerabilities. Primarily, because the updates are set to install automatically (so in many cases, no action is required). We also don't want to alarm customers unecessarily and send yet more emails. However, a trend that we have noticed over the last several months has lead us to reconsider this approach.</p>
<div class="alert alert-info">
<p><strong>Please note:</strong> Our actual update policy is not changing in any way. Security updates for vulnerabilities will be installed automatically (where possible) just as before. We're only changing the type of email notifications that we send to you.</p>
</div>
<h4>WordPress EcoSystem - Change is the only constant</h4>
<p>More frequently, we are finding that a vulnerability is discovered in a plugin (and sometimes a theme) - but no update is immediately available - so Plesk is not able to install an update and patch the vulnerability. Sometimes a fix is released in the following days, and Plesk will install the update automatically, when it becomes available.</p>
<p>Other times, the plugin has been discontinued and the only option is to deactivate or remove the plugin completely. As this is likely to have some impact on the operation of your website, we can't automate this process, so the we need to reach out the customer and discuss their options. </p>
<p>Another increasingly regular occurance is that a vulnerability fix for a "premium" or "paid" WordPress plugin cannot be installed because the license has expired and so automatic update of the plugin is blocked.</p>
<p>In these cases, we have been sending a support ticket to the customer, prompting a discussion of the best course of action.</p>
<div class="alert alert-warning">
<p><strong>For these reasons we will be discontinuing the current WP Site email notifications of all pending updates, and will instead only send notifications of discovered vulnerabilities.</strong></p>
</div>
<h4>WordPress Vulnerabilities Email Notifications</h4>
<p>The new notifications will use the subject line: <em><strong>"WP Toolkit - Vulnerability Report"</strong></em>.</p>
<p>This means that you will receive fewer emails, but the emails you do receive will be more important. Often, the notification will just be informing you that vulnerabilities have been found and that updates were automatically installed. In these cases, the message you will see is:</p>
<p><strong><em>"The following vulnerabilities are handled by WP Toolkit right now based on site autoupdate policy:"</em></strong></p>
<p>In other cases, the notification will inform you that an update is not available or can't be installed (if possible, an explanation will be included), and therefore some user action is required. In these cases, the message you will see is: </p>
<p><strong><em>"The following vulnerabilities need your attention because they have to be addressed manually:"</em></strong></p>
<p>We hope that this change will reduce the email clutter sent to our customers, while also keeping you more informed of the most important updates that affect your websites.</p>
<p><strong>Want to change the email address that these notifications are sent to?</strong></p>
<p>You can change the recipient email address for all WP Site (Plesk) email notifications by logging into your Plesk Panel and going to Edit Profile, in the top menu bar.</p>
<p>Note that this is separate from any email addresses and notification settings in My WP NET. The WP Toolkit notifications are sent from the Plesk Panel, and so the recipient email address must be set there. The benefit of this is that you can use a different address to receive WP Toolkit notifications (such as your WP developer), while leaving all your My WP NET notifications as they are now.</p>
<hr />
<p>These changes will be rolled out to all WP Site servers over the next few days. If you receive a vulnerability notification and don't know what to do - or just have questions - please don't hesitate to <a href="https://my.wpnet.nz/ticket">open a support ticket</a> and we'll be happy to help!</p>]]></description>
</item>

<item>
    <title><![CDATA[Product Updates - October 2024]]></title>
    <link>https://my.wpnet.nz/announcements/724</link>
    <guid>https://my.wpnet.nz/announcements/724</guid>
    <pubDate>Tue, 01 Oct 2024 09:30:00 +1300</pubDate>
    <description><![CDATA[<p>We like to take this time before the Christmas rush to review the year so far and announce any product updates and other news. We have lots to get through this time, so buckle up.</p>
<p>First, the not-so-great news. We continue to face increasing costs in a very competitive space. Therefore, we are making a few small price adjustments, all the details are included below.</p>
<p>We work very hard to avoid price changes where ever possible and also to keep any price increases to a minimum. I'm pleased to say that the changes this year are minimal and will have little impact on most of our customers.</p>
<p><strong>Except for domain registration price changes (which take affect immediately) all other changes take affect from October 7, 2024.</strong></p>
<hr />
<h4>Domain Registration - New TLDs and Price Changes</h4>
<p>We're pleased to announce that we are adding some new TLDs that customers have requested. You can now register or transfer <strong>.maori.nz</strong>, <strong>.kiwi</strong> and <strong>.website</strong> domains!</p>
<p>We can now register or renew all supported TLDs for 1-5 years. Previously, some domains were limited to 2 years.</p>
<p>Many TLDs have had wholesale price changes in the last year, and we are now updating our retail prices accordingly. </p>
<p>Lastly, just a note that we have intentionally absorbed any price increase for .nz domains, as we like to keep these at the lowest possible price for our customers.</p>
<p>Please see below for all new pricing effective immediately. </p>
<p><strong>Domain Pricing</strong></p>
<ul>
<li>.nz | .co.nz | .net.nz | .org.nz | .geek.nz | .kiwi.nz | .maori.nz — $50 / year (no change)</li>
<li>.kiwi — $85 / year</li>
<li>.com | .net — $45 / year</li>
<li>.org — $40 / year (no change)</li>
<li>.biz | .website — $55 / year</li>
<li>.info — $65 / year</li>
</ul>
<p>Domain pricing is per year, in NZD, excluding GST.</p>
<h4>WP Site  - Price Changes</h4>
<p>We're just making one small change: the <strong>WP Site 1</strong> plan price is increasing to $35 per month.</p>
<p><strong>WP Site 1 &amp; 2 receive a 5% discount for annual payment, reducing the monthly price (per site) to $33.25 and $28.50 respectively!</strong></p>
<p>We regularly review our competitors, and even with these pricing changes, we still believe our WP Site plans represent excellent value when considering the service features and level of support that we offer.</p>
<p>Many similar, NZ-based providers charge up to $60 per month for similar WordPress hosting &amp; support services! (We still reckon we're better tho...)</p>
<p>All other WP Site pricing remains the same.</p>
<h4>WP Site - Storage Addon Changes</h4>
<p>Upon reviewing our customer's usage of storage upgrades, we found that almost all were using at least 2GB of addon storage. We have therefore decided to drop the 1GB addon and these will now be sold in units of 2GB, at $5 per 2GB upgrade.</p>
<p><strong>Also, just a reminder that back in February of this year, we increased the included storage space for all WP Site plans by up to 100%!</strong></p>
<p>New pricing is as follows:</p>
<ul>
<li>+2GB - $5 / month</li>
<li>+4GB - $10 / month</li>
<li>+6GB - $15 / month</li>
<li>+8GB - $20 / month</li>
<li>+10GB - $25 / month</li>
</ul>
<p>All customers who currently use a disk space upgrade will have their site automatically upgraded or downgraded as appropriate, to fit within the new plans.</p>
<h4>WP Server</h4>
<p>There are no pricing changes for WP Server to announce at this time. However, we do have some exciting updates in the works. We'll have more information on this shortly.</p>
<p>What I can say is that we are planning huge improvements to our vulnerabilty patching &amp; auto-updates, along with new client-facing resource monitoring for WP Servers. </p>
<h4>New Website Coming Soon!</h4>
<p>We usually like to release an annual refresh of our main website at this time, but we've been so busy working on our client's sites, that we haven't managed to complete our new site build in time.</p>
<p>We hope to launch this within the next few weeks!</p>
<hr />
<p>If you have any questions or concerns regarding these changes, please don't hesitate to contact me directly on <a href="mailto:gb@wpnet.nz">gb@wpnet.nz</a> or <a href="https://wpnet.nz/ticket">open a support ticket</a>.</p>
<p>We really appreciate the commitment of our customers and the positive feedback we regularly receive is incredibly motivating!</p>
<p>Thank you for taking the time to read this and for your continued business and support!</p>]]></description>
</item>

<item>
    <title><![CDATA[WordPress 6.6 "Dorsey" has been released! ]]></title>
    <link>https://my.wpnet.nz/announcements/723</link>
    <guid>https://my.wpnet.nz/announcements/723</guid>
    <pubDate>Tue, 23 Jul 2024 13:09:00 +1200</pubDate>
    <description><![CDATA[<p>The latest version of WordPress, version 6.5 is now available.</p>
<p>You can read about this release on the <a href="https://wordpress.org/news/2024/07/dorsey/">WordPress.org blog post</a>.</p>
<p>Detailed <a href="https://wordpress.org/documentation/wordpress-version/version-6-6/">release notes</a> are also available on the WordPress.org Docs page.</p>]]></description>
</item>

<item>
    <title><![CDATA[Polyfill.io Attack - Compromised CDN]]></title>
    <link>https://my.wpnet.nz/announcements/722</link>
    <guid>https://my.wpnet.nz/announcements/722</guid>
    <pubDate>Mon, 01 Jul 2024 17:58:00 +1200</pubDate>
    <description><![CDATA[<p>A serious security issue has been discovered, due to a compromised CDN which is delivering malicious code to websites and applications that reference it's libraries.</p>
<p>More information on this issue is available here:</p>
<ul>
<li><a href="https://www.sonatype.com/blog/polyfill.io-supply-chain-attack-hits-100000-websites-all-you-need-to-know">https://www.sonatype.com/blog/polyfill.io-supply-chain-attack-hits-100000-websites-all-you-need-to-know</a> </li>
<li><a href="https://sansec.io/research/polyfill-supply-chain-attack">https://sansec.io/research/polyfill-supply-chain-attack</a></li>
</ul>
<p>WP NET support has conducted a through search of all servers and only a very small number of references were found. Some were false-positives, while a few were out-dated plugins which included libraries from polyfill.io.</p>
<p><strong>All cases have been mitigated and we don't expect any issues for our customers.</strong></p>
<p>Please do contact us directly by <a href="https://my.wpnet.nz/ticket">opening a support ticket</a> if you have been experiencing any issues with your sites, or if you have any questions.</p>
<p> </p>]]></description>
</item>

<item>
    <title><![CDATA[Scheduled Maintenance for all MWP Servers!]]></title>
    <link>https://my.wpnet.nz/announcements/721</link>
    <guid>https://my.wpnet.nz/announcements/721</guid>
    <pubDate>Mon, 24 Jun 2024 08:00:00 +1200</pubDate>
    <description><![CDATA[<p>From Tuesday 25 June to Tuesday 2 July, we will be upgrading database software on <strong>all MWP (Plesk Panel) servers</strong>.</p>
<p>Please read the <a href="https://my.wpnet.nz/serverstatus.php">System Status notice</a>.</p>]]></description>
</item>

<item>
    <title><![CDATA[WordPress 6.5 "Regina" has been released!]]></title>
    <link>https://my.wpnet.nz/announcements/720</link>
    <guid>https://my.wpnet.nz/announcements/720</guid>
    <pubDate>Thu, 04 Apr 2024 12:34:00 +1300</pubDate>
    <description><![CDATA[<p>The latest version of WordPress, version 6.5 is now available.</p>
<p>You can read about this release on the <a href="https://wordpress.org/news/2024/04/regina/">WordPress.org blog post</a>.</p>
<p>Detailed <a href="https://wordpress.org/documentation/wordpress-version/version-6-5/">release notes</a> are also available on the WordPress.org Docs page.</p>]]></description>
</item>

<item>
    <title><![CDATA[WooCommerce &lt;= 8.1.1 - Cross Site Scripting (XSS)]]></title>
    <link>https://my.wpnet.nz/announcements/719</link>
    <guid>https://my.wpnet.nz/announcements/719</guid>
    <pubDate>Mon, 27 Nov 2023 12:55:00 +1300</pubDate>
    <description><![CDATA[<p>A new, medium severity vulnerability has been disclosed in the WooCommerce plugin.</p>
<p>Where possible, WP NET will deploy this update on behalf of our customers, but in some cases incompatibility with themes and / or other plugins may prevent us from doing so.</p>
<p>We recommend that all WooCommerce users update to 8.2 at your earliest convenience.</p>
<p>If you need assistance, please <a href="https://wpnet.nz/ticket">open a support ticket</a>.</p>
<p><a href="https://patchstack.com/database/vulnerability/woocommerce/wordpress-woocommerce-plugin-8-1-1-contributor-cross-site-scripting-xss-vulnerability">Details on the PatchStack website</a>.</p>]]></description>
</item>

<item>
    <title><![CDATA[Slider Revolution - Vulnerabilities Disclosed]]></title>
    <link>https://my.wpnet.nz/announcements/718</link>
    <guid>https://my.wpnet.nz/announcements/718</guid>
    <pubDate>Fri, 17 Nov 2023 13:14:00 +1300</pubDate>
    <description><![CDATA[<p>Two vulnerabilities have recently been disclosed in the widely used Slider Revolution (revslider) plugin.</p>
<ul>
<li>Author+ Arbitrary File Upload vulnerability &lt;= 6.6.15 (CVSS score: 8.4)</li>
<li>Cross Site Scripting (XSS) vulnerability &lt;= 6.6.14 (CVSS score: 6.5)</li>
</ul>
<p>For more details, please see this <a href="https://patchstack.com/database/vulnerability/revslider">PatchStack page</a>.</p>
<p>Due to the fact that Revolution Slider is a premium / paid plugin and is often bundled with a WordPress theme, this does pose a challenge for WP NET to rollout updates, as automatic update of the plugin is rarely possible.</p>
<p>However, due to the relatively serious nature of one of these vulnerabilities (Author+ Arbitrary File Upload vulnerability), we think it's important that we take what steps we can to ensure that our customer's websites are safe and secure. Whereever possible, we will manually deploy the patched version of Slider Revolution (v6.6.18) over the next few days.</p>
<p>If you use Slider Revolution on your website, and you have an active license, we strongly urge you to ensure that you are using at least version 6.6.16.</p>
<p>If Slider Revolution was bundled with your theme, we suggest you contact your theme author and request an updated version.</p>
<p>If you have any questions or concerns, or just need some help, please <a href="https://wpnet.nz/ticket">open a support ticket</a>.</p>
<p> </p>
<p> </p>]]></description>
</item>

<item>
    <title><![CDATA[WordPress 6.4 Fieldguide]]></title>
    <link>https://my.wpnet.nz/announcements/717</link>
    <guid>https://my.wpnet.nz/announcements/717</guid>
    <pubDate>Thu, 26 Oct 2023 13:00:00 +1300</pubDate>
    <description><![CDATA[<p>WordPress 6.4 is releasing soon, in the meantime, here's the <a href="https://make.wordpress.org/core/2023/10/23/wordpress-6-4-field-guide/">WordPress 6.4 fieldguide</a>.</p>]]></description>
</item>

<item>
    <title><![CDATA[WordPress 6.3.2 maintenance &amp; security release ]]></title>
    <link>https://my.wpnet.nz/announcements/715</link>
    <guid>https://my.wpnet.nz/announcements/715</guid>
    <pubDate>Fri, 13 Oct 2023 10:52:00 +1300</pubDate>
    <description><![CDATA[<p><a href="https://wordpress.org/documentation/wordpress-version/version-6-3-2/">WordPress 6.3.2</a> has been released and includes important security fixes.</p>
<p>WordPress core automatically installs security updates, however at time of writing many sites have not yet updated. Therefore, we are now pre-emptively pushing out 6.3.2 to all WP NET customers.</p>
<p>Also note that this update is back-ported to <a href="https://wordpress.org/download/releases/">previous WordPress versions</a>, from 4.1 to 6.2.</p>]]></description>
</item>

<item>
    <title><![CDATA[Security Alert: Optimize Database After Deleting Revisions plugin]]></title>
    <link>https://my.wpnet.nz/announcements/716</link>
    <guid>https://my.wpnet.nz/announcements/716</guid>
    <pubDate>Fri, 13 Oct 2023 10:05:00 +1300</pubDate>
    <description><![CDATA[<p>The <a href="https://en-gb.wordpress.org/plugins/rvg-optimize-database/">Optimize Database After Deleting Revisions</a> plugin has a reported <a href="https://patchstack.com/database/vulnerability/rvg-optimize-database/wordpress-optimize-database-after-deleting-revisions-plugin-5-0-110-cross-site-request-forgery-csrf-vulnerability">CSRF vulnerability</a>. Affected verison is 5.1 and below.</p>
<p>At time of writing, no patch has yet been made available.</p>
<p>The plugin has been temporarily removed from the WordPress plugin repository.</p>
<p><em>This plugin has been closed as of 29 September 2023 and is not available for download. This closure is temporary, pending a full review.</em></p>
<p>As a precaution, to protect our customers we have now deactivated and removed the plugin from WP NET customers sites.</p>
<hr />
<p>If you have any questions or concerns, please <a href="https://wpnet.nz/ticket/">open a support ticket</a>.</p>]]></description>
</item>
                </channel>
            </rss>