9 Oct 2017

Vulnerability Details: Authenticated Local File Inclusion (LFI) Vulnerability in Insert Pages

From time to time a vulnerability is fixed in a plugin without the discoverer putting out a report on the vulnerability and we will put out a post detailing the vulnerability so that we can provide our customers with more complete information on the vulnerability.

Recently in our monitoring of the WordPress Support Forum for indications of vulnerabilities in plugins, we came across the author of the plugin Insert Pages explaining why the plugin had been removed from the Plugin Directory. They described that a vulnerability had been reported in the plugin: [Read more]