30 May 2019

Did Wordfence Know They Were Keeping The Public in the Dark About Unfixed Vulnerability in WordPress Plugin Already Being Exploited?

We often find that the information provided about vulnerabilities in WordPress plugins presented by security companies and developers of the plugins is not telling the full story. Take a vulnerability that Wordfence disclosed yesterday. They don’t provide any explanation of how they came across it:

On Friday May 24th, our Threat Intelligence team identified a vulnerability present in Convert Plus, a commercial WordPress plugin with an estimated 100,000 active installs. [Read more]