26 Jun 2019

Cross-Site Request Forgery (CSRF)/Settings Change Vulnerability in ACF: Better Search

One of the ways we make sure customers of our service have the best data on vulnerabilities in WordPress plugins they use is that we monitor changes being made to plugins for indications that vulnerabilities have been fixed. We often find that issues haven’t been fully resolved or that there are other related issues still in the plugin. That was the case when we looked into the details of a vulnerability in the plugin WebP Converter for Media, which in part involved a lack of protection against cross-site request forgery (CSRF). What we also noted was another instance of that, which also impacted another more popular plugin by the same developer, ACF: Better Search.

That plugin makes its settings page available to those with the “manage_options” capability, so normally only Administrators: [Read more]

1 Aug 2017

What Happened With WordPress Plugin Vulnerabilities in July 2017

If you want the best information and therefore best protection against vulnerabilities in WordPress plugins we provide you that through our service.

Here is what we did to keep those are already using our service secure from WordPress plugin vulnerabilities during July (and what you have been missing out on if you haven’t signed up yet): [Read more]