Sucuri Doesn’t Care That WordPress Plugin with Unfixed Vulnerability They Believe Is Being Exploited Is Still in the Plugin Directory
When it comes to our full disclosures of vulnerabilities as a protest of the continued inappropriate behavior of the WordPress Support Forum moderators, we are certainly not above criticism, but it is incredible to us that other security companies escape any criticism despite repeatedly doing things that seems out of line with them actually caring about keeping websites secure. In a post earlier today we noted how a security journalist didn’t link to our post about a vulnerability we full disclosed, apparently due to including a proof of concept for confirming that vulnerability exists, while linking to a post from the web security company Sucuri providing payloads for how hackers were trying to exploit vulnerabilities. That seems hypocritical, but looking at Sucuri’s post we noticed something else, they seemed to be unconcerned that a plugin with an unfixed vulnerability that they believed was being exploited was still in the Plugin Directory.
In their post they provide this information: [Read more]