Self-Proclaimed “WordPress Core Security Team Lead” John Blackbourn Is Telling People to Not Report Security Bugs in His Plugins to Him
A week ago we posted on our finding fairly stunning examples of poor security in WordPress. Those examples suggest that WordPress hasn’t had a comprehensive security review since at least 2009. The security page for WordPress would seem to say that is something that the “WordPress Security Team” should be addressing:
The WordPress Security Team works to identify and resolve security issues across the WordPress core software, harden the software against threats such as the OWASP Top Ten, and provide guidance across the ecosystem. [Read more]