WebsiteBaker Community Forum

WebsiteBaker => General Announcements => Topic started by: dbs on August 01, 2026, 09:41:58 AM

Title: WebsiteBaker 2.13.10 Security Update
Post by: dbs on August 01, 2026, 09:41:58 AM
WebsiteBaker 2.13.10 Security Update

DOWNLOAD:
- WebsiteBaker 2.13.10 Full Package: https://addon.WebsiteBaker.org/en/browse-add-ons/?id=0CD2C876 (https://addon.WebsiteBaker.org/en/browse-add-ons/?id=0CD2C876)
  New install / für Neuinstallationen und reguläre Updates

- WebsiteBaker 2.13.10 Security Update for WB 2.13.9: https://addon.WebsiteBaker.org/en/browse-add-ons/?id=022BA186 (https://addon.WebsiteBaker.org/en/browse-add-ons/?id=022BA186)
  Upgrade 2.13.9 / für bestehende WebsiteBaker-2.13.9-Installationen
----------------------------------------------------------------------------------------------------------------------------

Hello WebsiteBaker community,  (Deutsch weiter unten)
we have released WebsiteBaker 2.13.10 as an important security update for WebsiteBaker 2.13.x.
Two security vulnerabilities were responsibly reported to us by an independent security researcher. We would like to thank the researcher for the responsible disclosure and the cooperation.
The reported issues could allow remote code execution after successful exploitation. However, exploitation requires a valid WebsiteBaker administrator login. This means that the vulnerabilities cannot be used by an anonymous visitor without backend access. Nevertheless, websites with compromised, shared, weak, or reused administrator credentials could be at risk.
WebsiteBaker 2.13.10 includes security hardening and CodeGuard (new) protection improvements for areas such as:

- Droplets
- add-on/module installation
- template installation
- language file installation
- media uploads
- media ZIP extraction
- backend security checks

We strongly recommend that all WebsiteBaker 2.13.x users update to WebsiteBaker 2.13.10.

As always, please make a full backup of your files and database before updating.
For additional safety, we also recommend checking administrator accounts, using strong unique passwords, and removing unused administrator accounts.

-------------
Compatibility note for custom Droplets, add-ons, and templates
-------------

The WebsiteBaker Team


### DEUTSCH ########################################################

Hallo WebsiteBaker-Community,

wir haben WebsiteBaker 2.13.10 als wichtiges Security Update für die WebsiteBaker-2.13.x-Serie veröffentlicht.

Uns wurden von einem unabhängigen Security Researcher zwei Sicherheitslücken verantwortungsvoll gemeldet. Wir bedanken uns ausdrücklich für die verantwortungsvolle Meldung und die Zusammenarbeit.

Die gemeldeten Schwachstellen konnten nach erfolgreicher Ausnutzung eine Ausführung von Code auf dem Server ermöglichen. Für die Ausnutzung ist jedoch ein gültiger WebsiteBaker-Administratorzugang erforderlich. Die Schwachstellen können also nicht direkt von anonymen Besuchern ohne Backend-Zugang ausgenutzt werden. Trotzdem können Installationen gefährdet sein, wenn Administratorzugäng e kompromittiert wurden oder schwache, gemeinsam genutzte oder wiederverwendete Passwörter verwendet werden.

WebsiteBaker 2.13.10 enthält Sicherheitsverbesse rungen und CodeGuard-Schutzmaßnahmen unter anderem für:

- Droplets
- Add-on-/Modulinstallation
- Template-Installation
- Sprachdatei-Installation
- Media-Uploads
- Entpacken von Media-ZIP-Dateien
- Backend-Sicherheitsprüfungen

Wir empfehlen allen Nutzern der WebsiteBaker-2.13.x-Serie dringend, auf WebsiteBaker 2.13.10 zu aktualisieren.

Bitte erstellt vor dem Update wie immer ein vollständiges Backup der Dateien und der Datenbank.
Zusätzlich empfehlen wir, Administratorzugäng e zu prüfen, starke individuelle Passwörter zu verwenden und nicht mehr benötigte Administratorzugäng e zu entfernen.
-------------------
Hinweis zu eigenen Droplets, Add-ons und Templates
-------------------

Das WebsiteBaker-Team