13 Jul 2016

Protecting You Against Wordfence’s Bad Practices: XSS Vulnerability in All in One SEO Pack

Wordfence is putting WordPress website at risk by disclosing vulnerabilities in plugins with critical details needed to double check their work missing, in what appears to be an attempt to profit off of these vulnerabilities. We are releasing those details so that others can review the vulnerabilities to try to limit the damage Wordfence’s practice could cause.

The latest in our ongoing series of putting out the details of details of vulnerabilities discovered by Wordfence is good example of why what Wordfence is doing is hurting the security of WordPress plugins. In this case they saw a report of  a persistent cross-site scripting (XSS) vulnerability in the plugin All in One SEO Pack and discovered a similar vulnerability, which is something that often happens we security researchers see reports of vulnerabilities in plugins. The difference is that with that report, like other reports by responsible parties, it included the details of the vulnerabilities, so it was easy for Wordfence to see what the issue was in that case. By Wordfence excluding those details it makes it harder to do the same with vulnerabilities that they have discovered, but through our work on this we have already found two additional security vulnerabilities in the Yoast SEO plugin and one in the WP Fastest Cache plugin. [Read more]

12 Jul 2016

Wordfence Spreading False Information on All in One SEO Pack Vulnerability

When it comes to improving WordPress security one of the things that we think is needed is better information, unfortunately we often see security companies being the ones pushing false information out there. We just ran across yet another example of this coming from the folks at Wordfence, which we though is important to point out, since they are trying to get people to share their “post with the larger WordPress community to create awareness of this security issue”, which we hope people don’t do since they are pushing out false information.

On Sunday a persistent cross-site scripting (XSS) vulnerability that existed in some versions of the All in One SEO Pack plugin was disclosed. The vulnerability was fixed in version 2.3.7, which was released on Friday. The same day we added it to our data set, so if you use our service and hadn’t already updated the plugin (you can use our Automatic Plugin Updates plugin to have plugin updates applied automatically), you would have been notified then. [Read more]