Recently the web scanner service Detectify has been vaguely disclosing minor vulnerabilities in a number of WordPress plugins. It seems like they are aware that they could notify the developer of these, but usually haven’t been doing it. One of the more recent batch was a cross-site request forgery (CSRF) vulnerability in the plugin Use Any Font.
When we went to look into this ...
To read the rest of this post you need to have an active account with our service.
For existing customers, please log in to your account to view the rest of the post.
If you are not currently a customer, when you sign up now you can try the service for half off (there are a lot of other reason that you will want to sign up beyond access to posts like this one).
If you are a security researcher please contact us to get free access to all of our Vulnerability Details posts.