What Happened With WordPress Plugin Vulnerabilities in March 2018
If you want the best information and therefore best protection against vulnerabilities in WordPress plugins we provide you that through our service.
Here is what we did to keep those are already using our service secure from WordPress plugin vulnerabilities during March (and what you have been missing out on if you haven’t signed up yet):
Plugin Vulnerabilities We Discovered and Publicly Disclosed This Month
We don’t just collect data on vulnerabilities in plugins that others have discovered, we also discover vulnerabilities through proactive monitoring of changes made to plugins, monitoring hackers’ activity, reviewing other vulnerabilities, and by doing additional checking on the security of plugins.
The most concerning vulnerabilities this month were several PHP object injection vulnerabilities. That is a type of vulnerability likely to be exploited. One of them were in plugins with 9,000+ active installs according to wordpress.org. Our Plugin Security Checker (which is now accessible through a WordPress plugin of its own) can detect the possibility of those variants of PHP object injection, so anyone can check if plugins they use may be impacted by a similar vulnerability.
- PHP object injection vulnerability in WL Katalogsøk
- PHP object injection vulnerability in WooCommerce Save For Later Cart Enhancement
- Persistent cross-site scripting (XSS) vulnerability in Limit Login Attempts
- Persistent cross-site scripting (XSS) vulnerability in Limit Login Attempts Reloaded
- Authenticated PHP object injection vulnerability in bbPress Move Topics
- Cross-site request forgery (CSRF)/PHP object injection vulnerability in bbPress Move Topics
- PHP object injection vulnerability in HappyForms
- PHP object injection vulnerability in DukaPress
- PHP object injection vulnerability in Newsletters
Plugin Vulnerabilities We Helped Get Fixed This Month
Letting you know that you are using a vulnerable version of a plugin is useful, but it is much more useful if you can fully protect yourself by simple updating to a new version. So we work with plugin developers to make sure that vulnerabilities get fixed.
- Authenticated PHP object injection vulnerability in bbPress Move Topics, discovered by us
- Cross-site request forgery (CSRF)/PHP object injection vulnerability in bbPress Move Topics, discovered by us
- PHP object injection vulnerability in HappyForms, discovered by us
- PHP object injection vulnerability in DukaPress, discovered by us
- PHP object injection vulnerability in Newsletters, discovered by us
Plugin Vulnerabilities Added This Month That Are In The Current Version of the Plugins
Keeping your plugins up to date isn’t enough to keep you secure as these vulnerabilities in the current versions of plugins show:
- Arbitrary file upload vulnerability in IP-Logger, discovered by ?
- Local file inclusion (LFI) vulnerability in Site Editor, discovered by Nicolas Buzy-Debat
Additional Vulnerabilities Added This Month
As usual, there were plenty of other vulnerabilities that we added to our data during the month. The most serious vulnerabilities were the PHP object vulnerabilities that we had discovered.
- PHP object injection vulnerability in WL Katalogsøk, discovered by us
- Arbitrary file upload vulnerability in Open Flash Chart Core, discovered by ?
- PHP object injection vulnerability in WooCommerce Save For Later Cart Enhancement, discovered by us
- Persistent cross-site scripting (XSS) vulnerability in Limit Login Attempts, discovered by us
- Persistent cross-site scripting (XSS) vulnerability in Limit Login Attempts Reloaded, discovered by us
- Authenticated PHP object injection vulnerability in bbPress Move Topics, discovered by us
- Cross-site request forgery (CSRF)/PHP object injection vulnerability in bbPress Move Topics, discovered by us
- PHP object injection vulnerability in HappyForms, discovered by us
- PHP object injection vulnerability in DukaPress, discovered by us
- PHP object injection vulnerability in Newsletters, discovered by us
- Authentication bypass vulnerability in Super Socializer, discovered by ?
- Reflected cross-site scripting (XSS) vulnerability in Duplicator, discovered Stefan Broeder
- Authenticated cross-site scripting (XSS) vulnerability in Events Manager, discovered by Luigi Gubello
Plugin Security Scorecard Grade for Limit Login Attempts
Checked on August 2, 2024See issues causing the plugin to get less than A+ grade