1 Feb 2018

What Happened With WordPress Plugin Vulnerabilities in January 2018

If you want the best information and therefore best protection against vulnerabilities in WordPress plugins we provide you that through our service.

Here is what we did to keep those are already using our service secure from WordPress plugin vulnerabilities during January (and what you have been missing out on if you haven’t signed up yet): [Read more]

16 Jan 2018

Making Sure That Valid Values Are Provided For Shortcode Attributes Can Prevent Security Issues As Well Providing a Better Experience

One of the areas of WordPress plugins that has received additional attention when it comes to security recently has been shortcodes, as WordPress now allows anyone that is logged in to WordPress to access those. While that change has expanded the pool of people that might exploit an issue related to those, it was already the case that lower level users could access those and proper security should have been place, which hasn’t always been the case. Making sure things are done securely doesn’t just protect against vulnerabilities, but can provide a better experience for users, as can be seen with the plugin Power Charts.

Recently we were contacted by one of the users of our service, J.D. Grimes, who had found some possible vulnerabilities that involved shortcodes and another issue that we will get to in a moment. He was too busy to go further with them at the time and was wondering if we could take it from there in confirming them and getting in touch with the developers. One of the impacted plugins was Power Charts. [Read more]