Advertisement · 728 × 90

Posts by Plugin Vulnerabilities

Preview
Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of June 6

Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of June 6

10 months ago 0 0 0 0
Preview
WordPress Firewall Plugin Claimed to Protect Against “Any Threat” Doesn’t Stop Even One Simulated Attack From Firewall Testing Tool

WordPress Firewall Plugin Claimed to Protect Against "Any Threat" Doesn't Stop Even One Simulated Attack From Firewall Testing Tool

10 months ago 0 0 0 0
Preview
Patchstack Now Withholding Misappropriated Information Needed to Secure Plugins in WordPress Plugin Directory From WordPress

Patchstack Now Withholding Misappropriated Information Needed to Secure Plugins in WordPress Plugin Directory From WordPress

10 months ago 0 0 0 0
Preview
Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 30

Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 30

10 months ago 0 0 0 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 4 days, 9 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can reac…

Perhaps you could explain to your members that they shouldn't lie about the CRA as an excuse to withhold security vulnerability information from the open source WordPress project. Which is putting millions of websites at unnecessary risk of security issues.

10 months ago 0 0 0 0

The WordPress Meta team holding up the community once again.

10 months ago 0 0 0 0
Preview
A Month On, a Glaring Problem With Five for the Future Pledges Hasn’t Been Addressed

Also worth re-upping is that Five for the Future pledges are in general highly suspect.

It is one of the many things that are need of reform with WordPress.

10 months ago 0 0 0 0
Preview
Aligning Automattic’s Sponsored Contributions to WordPress Automattic has always been deeply committed to the success of WordPress, dedicating significant resources and talent to its development for almost two decades. However, we’ve observed an imbalance …

With Automattic announcing a return to contributing to WordPress, it's worth noting that there hasn't been a change with the cited reasons they gave for reducing their contributions in January.

WP Engine's lawsuit is still on and they haven't boosted their contributions.

10 months ago 0 0 1 0
Preview
WP Engine Study Finds That Security Is Somehow Considered One of WordPress’ Benefits and Also Disadvantages

WP Engine Study Finds That Security Is Somehow Considered One of WordPress' Benefits and Also Disadvantages

10 months ago 0 0 0 0
Advertisement
Preview
WordPress Hasn’t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed “Critical” Vulnerability

The unfixed vulnerability that support forum discussion is about is something we posted was likely being targeted by a hacker last week.

10 months ago 0 0 0 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 1 day, 10 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can reac…

Are you going to cover how Patchstack is refusing to provide WordPress with information needed to properly handle vulnerable plugins? This is leading to websites remaining vulnerable to easily fixed vulnerabilities.

10 months ago 0 0 1 0
Preview
Patchstacks’s Vulnerability Disclosure Program (VDP) Goes Against Important Requirements of EU’s Cyber Resilience Act

Patchstack are claiming the EU Cyber Resilience Act (CRA) requires this.

It isn't the first time they have lied about that act.

10 months ago 0 0 0 0

The US Government through their funding of CVE is also supporting this.

10 months ago 0 0 1 0
Preview
Patchstack Secures $5M in Series A Funding Patchstack, a leading WordPress security company, recently raised $5 million in its Series A funding round. The funding round was led by Karma Ventures, G+D Ventures, and Emilia Capital, an investm…

Joost de Valk (@joost.blog) is funding what is basically a man-in-the-middle (MiTM) attack against WordPress.

10 months ago 0 0 1 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 1 day, 9 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can react…

Patchstack tries to get people to report plugin vulnerabilities to them instead of developers or WordPress. Now they are refusing to provide the information to WordPress.

10 months ago 0 0 1 0
Preview
Wordfence Missed That Authenticated Persistent XSS Vulnerability in 2+ Million Install MC4WP: Mailchimp for WordPress Wasn’t Fixed

We provided our customers with the details of the vulnerability last week.

10 months ago 0 0 0 0
Advertisement

Would anyone guess that this changelog entry for a WordPress plugin with 2+ million installs was referring to fixing a vulnerability?:

"Improved context-dependent escaping in dynamic content tags."

10 months ago 0 0 1 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 1 day, 7 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can react…

"we always take security seriously" - WordPress plugin developer who still hasn't fixed an exploitable vulnerability two months after apparently being notified of it

10 months ago 0 0 0 0

Is anyone keeping track of incident reports that haven't even received a response?

We still haven't received a response for one we filed in January of last year. It involved, among other things, returning a known vulnerable plugin to the plugin directory.

10 months ago 1 0 2 0
Preview
WordPress Hasn’t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed “Critical” Vulnerability

Patchstack claimed today that over 100,000 websites are affected, but as we noted last week, it is significantly less than that.

10 months ago 0 0 0 0
Preview
Unpatched Critical Vulnerability in TI WooCommerce Wishlist Plugin - Patchstack 🚨 A critical unpatched vulnerability in the TI WooCommerce Wishlist plugin allows unauthenticated file uploads and potential RCE. Over 100K sites affected. As usual, Patchstack users are protected. 🛡️

A WordPress plugin with 100,000 installs has an unfixed vulnerability being targeted by a hacker and Patchstack's response is to suggest you pay them $5 a month for a firewall rule they call a "patch".

WordPress could release a real patch for free. We would provide them with the patch for free.

10 months ago 0 0 1 0
Preview
WordPress Hasn’t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed “Critical” Vulnerability

In other areas the team are still failing pretty badly. A situation like this one this shouldn't happen. We have offered for years to provide fixes to stop this sort of thing from happening, and yet it keeps happening. 2/2

10 months ago 0 0 0 0
Preview
WordPress Plugin Submission Review Seems to Have Failed Badly With ConvertPro

As we said in a comment we just left on the post, it is great that automated testing finally got implemented, as it has addressed a lot of issues that should have been caught for a long time.

But there still look to significant problems with the review process, like this. 1/2

10 months ago 0 0 1 0
Preview
WordPress Plugin Submission Review Seems to Have Failed Badly With ConvertPro

WordPress Plugin Submission Review Seems to Have Failed Badly With ConvertPro

10 months ago 0 0 0 0
Preview
Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 23

Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 23

10 months ago 0 0 0 0
Preview
Long Overdue Security Review of WordPress Would Cost Only 0.25% of WP Engine’s Estimate of Cost of One WordPress Website

Long Overdue Security Review of WordPress Would Cost Only 0.25% of WP Engine's Estimate of Cost of One WordPress Website

10 months ago 0 0 0 0
Advertisement

Mary Hubbard goes on to say "If we continue to center empathy, transparency, and the shared goal of making WordPress better for everyone, we won’t just be stronger. We’ll be ready for whatever comes next."

When has WordPress centered transparency?

10 months ago 0 0 0 0

Mary Hubbard:

"Rotating roles can help us avoid centralizing too much authority in any one place, and it guards against the single points of failure that open source and communities should always aim to minimize."

Is rotating roles going to apply to her boss Matt Mullenweg?

10 months ago 0 0 1 0
Preview
WordPress Hasn’t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed “Critical” Vulnerability

WordPress Hasn't Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed "Critical" Vulnerability

10 months ago 0 0 0 0

8 months after a vulnerability was reported to someone, it still hasn't been fixed.

It's unclear what happened here, but the developer claims that the vulnerability was reported to @patchstack.com instead of to them. They say Patchstack made a public claim after 6 months, but didn't notify them.

11 months ago 0 0 0 0