8 Nov 2022

New WordPress Plugin Vulnerability Data Sources Are Just Copies of Existing Inaccurate Sources

Last week, we wrote about confusion over whether a claimed vulnerability in a WordPress plugin exists if it hasn’t been mentioned by a particular data source. That was in the context of a developer claiming there wasn’t a vulnerability in the plugin because it wasn’t mentioned by one of those, WPScan, despite being included in another, Patchstack. We also noted that Patchstack had not provided the information needed for anyone else to confirm their claim of a vulnerability.

Someone involved in yet another data source submitted a comment on that post, though it appears they didn’t pay attention to what the post said, to the detriment of those relying on it. Part of what they said in promoting their data source is they had this vulnerability in its data set. That isn’t surprising since on their website they admit to copying information from Patchstack. They didn’t address the inability to confirm the claimed vulnerability, which someone would want to before adding it to their data set. [Read more]