21 Jun 2023

Patchstack’s “Early Warning” About Vulnerability Isn’t Early and Fails to Warn It Isn’t Fixed

As we have noted in the past, the WordPress security provider Patchstack is falsely claiming to know about hundreds of zero-day vulnerabilities and claiming to be providing “early warnings” to their customers on vulnerabilities that were already public before they had warned about them. If they are willing to mislead on such things, it shouldn’t be a surprise that there are other problems with these “early warnings” that are more significant. That is exactly what happened with an “early warning” this week.

On Monday, June 19, Patchstack claimed to be providing an early warning about a vulnerability in the plugin Super Socializer that was fixed in the latest version of the plugin: [Read more]

12 Jan 2017

Vulnerability Details: Reflected Cross-Site Scripting (XSS) Vulnerability in Super Socializer

From time to time vulnerabilities are fixed in plugin without someone putting out a report on the vulnerability and we will put out a post detailing the vulnerability. While putting out the details of the vulnerability increases the chances of it being exploited, it also can help to identify vulnerabilities that haven’t been fully fixed (in some cases not fixed at all) and help to identify additional vulnerabilities in the plugin.


[Read more]