21 Nov 2022

Privilege Escalation Vulnerability in WordPress Popular Posts

The JVN released an advisory for the WordPress plugin WordPress Popular Posts stating that versions of the plugin prior to version 6.1.0 accepted “untrusted external inputs to update certain internal variables”, which they credited to Tsubasa Iinuma of Origami Systems. One of the changelog entries for that version is:


[Read more]

31 May 2017

Vulnerability Details: Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS) Vulnerability in WordPress Popular Posts

From time to time vulnerabilities are fixed in plugin without someone putting out a report on the vulnerability and we will put out a post detailing the vulnerability. While putting out the details of the vulnerability increases the chances of it being exploited, it also can help to identify vulnerabilities that haven’t been fully fixed (in some cases not fixed at all) and help to identify additional vulnerabilities in the plugin.


[Read more]