29 Sep 2021

Our Proactive Monitoring Caught a Shortcode Execution Vulnerability in Two WordPress Plugins

One way we help to improve the security of WordPress plugins, not just for our customers of our service, but for everyone using them, isĀ our proactive monitoring of changes made to plugins in the Plugin Directory to try to catch serious vulnerabilities. Through that, we caught a type of vulnerability that has in the past been combined with a more serious vulnerability and then exploited. That being a shortcode execution vulnerability, which we found in two plugins, Active Products Tables for WooCommerce and TableOn, that look like they might be have been closed on the Plugin Directory for a different security issue. The vulnerability also permits reflected cross-site scripting (XSS) to occur.

The possibility of this vulnerability is also flagged by our Plugin Security Checker, so you can check plugins you use to see if they might have similar issues with that tool. [Read more]