9 Jun 2023

Our Proactive Monitoring Caught a Shortcode Execution Vulnerability in a Brand New WordPress ChatGPT Plugin

One way we help to improve the security of WordPress plugins, not just for our customers of our service, but for everyone using them, is our proactive monitoring of changes made to plugins in the Plugin Directory to try to catch serious vulnerabilities. Through that, we caught a type of vulnerability that has in the past been combined with a more serious vulnerability and then exploited. That being a shortcode execution vulnerability, which we found in a brand new WordPress plugin. That plugin, ShortcodeGPT, being yet another ChatGPT related plugin that hasn’t been properly secured.

We now are also running all the code in the plugins used by our customers through that monitoring system on a weekly basis to provide additional protection for them. [Read more]