Privilege Escalation Vulnerability in Super Socializer
One of the changelog entries for the second latest version of the WordPress plugin Super Socializer suggested a privilege escalation vulnerability had been fixed:
…
One of the changelog entries for the second latest version of the WordPress plugin Super Socializer suggested a privilege escalation vulnerability had been fixed:
…
As we have noted in the past, the WordPress security provider Patchstack is falsely claiming to know about hundreds of zero-day vulnerabilities and claiming to be providing “early warnings” to their customers on vulnerabilities that were already public before they had warned about them. If they are willing to mislead on such things, it shouldn’t be a surprise that there are other problems with these “early warnings” that are more significant. That is exactly what happened with an “early warning” this week.
On Monday, June 19, Patchstack claimed to be providing an early warning about a vulnerability in the plugin Super Socializer that was fixed in the latest version of the plugin: [Read more]
One of the changelog entries for the latest version of the WordPress plugin Super Socializer is:
…
One of the changelog entries for the latest version of the WordPress plugin Super Socializer is:
…
If you want the best information and therefore best protection against vulnerabilities in WordPress plugins we provide you that through our service.
Here is what we did to keep those are already using our service secure from WordPress plugin vulnerabilities during March (and what you have been missing out on if you haven’t signed up yet): [Read more]
From time to time vulnerabilities are fixed in plugin without someone putting out a report on the vulnerability and we will put out a post detailing the vulnerability. While putting out the details of the vulnerability increases the chances of it being exploited, it also can help to identify vulnerabilities that haven’t been fully fixed (in some cases not fixed at all) and help to identify additional vulnerabilities in the plugin.
…