Security Issue Remains in 200,000+ Install WordPress Plugin Over Two Years After Vulnerabilities Were “Fixed”
In August 2020, NinTechNet, the developers of the WordPress plugin NinjaFirewall, disclosed vulnerabilities that had been in the plugin CMP – Coming Soon & Maintenance Plugin. That plugin had 100,000+ installs at the time and is now up to 200,000+ installs. While NinTechNet stated the vulnerabilities were fixed at the time, while reviewing code in the plugin related to that recently, as at least one of our customers now uses the plugin, we found that there still is a security issue that hasn’t been resolved.
NinTechNet’s post described part of the problem with the plugin this way: [Read more]