Our Proactive Monitoring Caught a CSRF/Arbitrary File Upload Vulnerability in One of 10Web’s Plugins
One way we help to improve the security of WordPress plugins, not just for our customers of our service, but for everyone using them, is our proactive monitoring of changes made to plugins in the Plugin Directory to try to catch serious vulnerabilities. Through that we caught a cross-site request forgery (CSRF)/arbitrary file upload vulnerability in the plugin 10WebEcommerce. The developer of that plugin, 10Web, also offers what they claim is the “Most Trustable WordPress Security Service”, despite this not being the first time we have run in to a vulenrability in one of their plugins recently.
The possibility of this vulnerability is also flagged by our Plugin Security Checker, so you can check plugins you use to see if they might have similar issues with that tool. [Read more]