17 Oct 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) Vulnerability in Max Mega Menu

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

13 Oct 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) Vulnerability in My Tickets

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

13 Oct 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) Vulnerability in Simple Membership

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

12 Oct 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) Vulnerability in Booking Calendar

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

11 Oct 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) Vulnerability in My WP Translate

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

7 Oct 2017

Vulnerability Details: Flash Cross-Site Scripting (XSS) Vulnerability in Caldera Forms

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

6 Oct 2017

Vulnerability Details: Reflected Cross-Site Scriting (XSS) Vulnerability in Crelly Slider

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

4 Oct 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) in WooCommerce PDF Invoices & Packing Slips

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

2 Oct 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) Vulnerability in Google Pagespeed Insights

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.


[Read more]

29 Sep 2017

Detectify Doesn’t Do A Good Job of Protecting WordPress Websites

When it comes to security these days you have situation that should be a crisis for the industry, 10s of billions on their products and services and yet a quick perusal of the news would show that the results for all the money spent are not good. Instead, as far as we have seen the security industry has no problem with the current situation and if you point out some of the problems leading to that you are likely to be criticized.

As an example of how the money is being spent on solutions that are not doing job, let’s take a look at company that we ran across recently, Detectify. That is marketed as the “Leading Web Security Scanner for Continuous Security”, though looking at what it provides for WordPress websites indicates that if it’s the leading scanner, then the lead isn’t very impressive. [Read more]