4 Apr 2023

Awesome Motive Isn’t Disclosing They Are Trying (and Sometimes Failing) to Fix Vulnerabilities in Their Plugins

Yesterday, Automattic’s WPScan claimed that the latest version of the 1+ million install WordPress plugin WPCode had fixed a vulnerability:

The plugin has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders [Read more]