Plugin Vulnerabilities

6.4K posts

Plugin Vulnerabilities banner
Plugin Vulnerabilities

Plugin Vulnerabilities

@pluginvulns

Provider of service to protect websites from being exploited due to vulnerable WordPress plugins.

Beigetreten Ocak 2016
19 Folgt301 Follower
Angehefteter Tweet
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
Our weekly update post on what on how our customers are helping to make WordPress plugins more secure is mostly about vulnerabilities that haven't been fixed. A vulnerability in the 300,000+ install Formidable Forms did get fixed this week, though. pluginvulnerabilities.com/2024/02/16/how…
English
0
0
0
260
Brian Gardner
Brian Gardner@bgardner·
Happy to announce we just published ACF 6.3.9 Security Release (@wp_acf), which will be automatically available to users who are @wpengine customers. (Link w/ info in reply.) ⚡️
Brian Gardner tweet media
English
4
22
106
5.3K
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
@getnitropack We reached out to you on Friday morning through your security email address about a vulnerability in the WordPress plugin. We still haven't heard back from you.
English
1
0
0
375
NitroPack
NitroPack@getnitropack·
The NitroPack team has a new solution to ensure NitroPack users receive updates to the WordPress plugin. Please update to the latest version of NitroPack using the steps outlined in our post: support.nitropack.io/en/articles/99… The NitroPack team has been blocked from accessing WordPress.org, which prevents us from releasing updates through WordPress.org. To continue receiving updates, please upgrade to the latest NitroPack version, following the steps outlined in our article linked above. Note: WP Engine and Flywheel hosting customers are unaffected and do not need to manually install this update to continue to receive automatic updates.
English
6
33
112
57.4K
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
@jacklynbiggin @WooCommerce @brentmackinnon This is also happened with a security improvement made in version 8.4.0, which included in the changelog for 8.5.0. The entry was: Fix – Remove the potential for a Reflected XSS attack in relation to a dismissable notice in the edit comments screen. #42728
English
1
0
0
35
Aditya R Sharma
Aditya R Sharma@adityaarsharma·
WordPress has added a limit of 1500 words for README, for most plugins this is okay, but for Elementor Addons with long list of feature this seems highly limiting. #WordPress
Aditya R Sharma tweet media
English
5
4
18
1.6K
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
@hackinglife7 Maybe you can spend some money making sure your plugins are properly secured before you acquire a plugin. Based on the recently fixed vulnerability in the ThemeIsle SDK caused by basic security failures, it doesn't look like that has already happened.
English
0
0
1
125
Ionut
Ionut@hackinglife7·
We're looking again to acquire one WordPress plugin generating between $60k - 150k per year in revenue. Read below on how we're different:
English
8
17
46
8K
Maciek Palmowski
Maciek Palmowski@palmiak_fp·
Working at @patchstackapp made my approach toward security even more strict. - I would convert whatever website possible to static - I would pay for @patchstackapp - it's almost impossible to keep up with vulnerabilities That said - I'm not saying #WordPress isn't secure. It's a huge market, with a lot of plugins and a lot of researchers. Core is secure and many plugins are very serious about #security (some less).
English
1
0
5
535
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
We found incomplete fixes with three plugins being used by our customers in the last week. One developer got an additional fix out very quickly, so quickly they didn't fully address the insecurity. The other two haven't released additional fixes. pluginvulnerabilities.com/2024/02/23/how…
English
1
0
0
38
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
One of the reasons there are too many updates for WordPress plugins is that developers are not being proactive about security. Not only are they not getting security reviews to catch issues, but when they are reported to them by others, the fixes are frequently incomplete.
Katie Keith@KatieKeithBarn2

We send an email requesting feedback after a cancelled subscription. Today I received this sensible but depressing response from someone who moved to Shopify due to the maintenance overhead of using WooCommerce with multiple plugins. We do need to consider this as a community and try to make things easier for site owners.

English
1
0
0
100
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
You can sign up for a free trial of our service to see if you are using plugins known to be vulnerable. We currently have data on plugins with at least 8.2 million installs that are known to be vulnerable and still in the WordPress Plugin Directory! pluginvulnerabilities.com/product/subscr…
English
0
0
0
32
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
The developer of Brave Conversion Engine still hasn't fully fixed a previous incomplete fix from November! They fixed the one example we provided of the remaining issue, but didn't resolve any of the others.
English
1
0
0
26
Plugin Vulnerabilities
Plugin Vulnerabilities@pluginvulns·
Another week, another post about how we are helping make WordPress plugins more secure. This week we caught incomplete vulnerability fixes in Download Manager and Brave Conversion Engine. Unfortunately, they still haven't been fixed. pluginvulnerabilities.com/2024/02/23/how…
English
1
0
0
60