Login

Plugin Vulnerabilities

A service to protect your site against vulnerabilities in WordPress plugins.

  • Why Plugin Vulnerabilities?
    • We Provide Fixes for Vulnerabilities
    • We Provide Accurate Vulnerability Information
    • Insightful Blocked Exploit Attempt Reporting
    • How We Are Improving the Security of WordPress Plugins
    • Proactive Monitoring for Vulnerabilities in New Versions of WordPress Plugins
    • Select Plugins to Receive Security Reviews
  • Sign Up
    • Set Up
  • PV Firewall
    • Set Up
    • Block Insights
    • WordPress Firewall Comparison
  • Other Services
    • WordPress Security Checkup
    • Plugin Security Review
    • Continuous Plugin Security Review Service
    • Theme Security Review
    • Hacked WordPress Website Cleanup
    • Abandoned WordPress Plugin Maintenance Service
    • Blue Hat Hacking Service for WordPress Plugins/Websites
    • Plugin Vulnerabilities Subscription for ClassicPress
    • Solutions for Web Hosts
    • Solutions for Security Providers
  • Plugin Search
    • WordPress Firewall Tester
    • WordPress Plugins Checker
    • Plugin Security Scorecard
    • Security Scorecard WordPress Plugin
    • WordPress REST API Route Checker
  • Research
    • Plugin Vulnerabilities Survey
    • Report Hacking of WordPress Website
    • Unfixed Security Issues in WordPress
    • Security Advisories on WordPress Plugin Developers
    • WP Security Researcher Database
    • Send us a Tip
  • About
    • WordPress Plugin Zero-Day Vulnerability Exploitation Info Sharing Partnership
    • Get Free Help Fixing A Security Vulnerability In Your WordPress Plugin
    • Contact Us
    • Feedback
    • Report a WordPress Plugin Vulnerability We Are Missing

Tag Archives: Custom Admin Page by BestWebSoft

13 Apr 2017

Reflected Cross-Site Scripting (XSS) Vulnerability in Numerous Plugins by BestWebSoft

Last Thursday we notified the developer of the plugin Contact Form by BestWebSoft of the results of our security review of their plugin (the plugin was chosen by our customer to receive a review from us). One of the issues we noticed was reflected cross-site scripting (XSS) vulnerability, which we also found existed in 40 other of their plugins due to the code that caused the vulnerability being shared among the plugins.

While preparing the data on the vulnerability in those plugins to add to our data set once we disclosed the vulnerability we noticed that the same issue had been fixed in 12 other plugins by the developer as of the day we notified them, so we figured that we were not the only ones that had noticed this vulnerability. Today a company named DefenseCode put out a report on the vulnerabilities (PDF), in which they state they notified the developer of the vulnerability on March 24. In their report the response from the developer states they were already aware of the issue before even then: [Read more]

Plugin Vulnerabilities Posted in Vulnerability Report Captcha by BestWebSoft, Car Rental by BestWebSoft, Contact Form by BestWebSoft, Contact Form Multi by BestWebSoft, Contact Form to DB by BestWebSoft, Custom Admin Page by BestWebSoft, Custom Fields Search by BestWebSoft, Custom Search by BestWebSoft, Donate by BestWebSoft, Email Queue by BestWebSoft, Error Log Viewer by BestWebSoft, Facebook Button by BestWebSoft, Featured Posts by BestWebSoft, Gallery by BestWebSoft, Gallery Categories by BestWebSoft, Google +1 by BestWebSoft, Google AdSense by BestWebSoft, Google Analytics by BestWebSoft, Google Captcha (reCAPTCHA) by BestWebSoft, Google Maps by BestWebSoft, Google Shortlink by BestWebSoft, Google Sitemap by BestWebSoft, Htaccess by BestWebSoft, Job Board by BestWebSoft, Latest Posts by BestWebSoft, Limit Attempts by BestWebSoft, LinkedIn by BestWebSoft, Multilanguage by BestWebSoft, Pagination by BestWebSoft, PDF & Print by BestWebSoft, Pinterest by BestWebSoft, Popular Posts by BestWebSoft, Portfolio by BestWebSoft, Post to CSV by BestWebSoft, Profile Extra Fields by BestWebSoft, PromoBar by BestWebSoft, Quotes and Tips by BestWebSoft, Rating by BestWebSoft, Re-attacher by BestWebSoft, Realty by BestWebSoft, Reflected Cross-Site Scripting (XSS), Relevant – Related Posts by BestWebSoft, Sender by BestWebSoft, SMTP by BestWebSoft, Social Buttons Pack by BestWebSoft, Social Login by BestWebSoft, Subscriber by BestWebSoft, Testimonials by BestWebSoft, Timesheet by BestWebSoft, Twitter Button by BestWebSoft, Updater by BestWebSoft, User Role by BestWebSoft, Visitors Online by BestWebSoft, Vulnerability Report, Zendesk Help Center by BestWebSoft Leave a comment

Post navigation

Follow Us

  • Google News
  • Bluesky
  • RSS

Latest Plugin Security Reviews

  • WordPress Plugin Security Review: FV Gravatar Cache
  • WordPress Plugin Security Review: Popup Builder
  • WordPress Plugin Security Review: WP Time Capsule
Powered by WordPress and WooCommerce
© 2016-2025 White Fir Design LLC | Privacy Policy
Fruitful theme by fruitfulcode
↑