23 Aug

Closures of Very Popular WordPress Plugins, Week of August 23

While we already are far ahead of other companies in keeping up with vulnerabilities in WordPress plugins (amazingly that isn’t an exaggeration), in looking in to how we could get even better we noticed that in a recent instance were a vulnerability was exploited in a plugin, we probably could have warned our customers about the vulnerability even sooner if we had looked at the plugin when it was first closed on the Plugin Directory instead of when the vulnerability was fixed (though as far as we are aware the exploitation started after we had warned our customers of the fix). So we are now monitoring to see if any of the 1,000 most popular plugins are closed on the Plugin Directory and then seeing if it looks like that was due to a vulnerability.

This week two of those plugins were closed and both of them have been reopened. [Read more]

16 Aug

Cross-Site Request Forgery (CSRF) Vulnerability in Post SMTP

As part of the security review of the plugin Post SMTP that we did after it was selected for a review by our customers we found the plugin contains a cross-site request forgery (CSRF) vulnerability that would cause all of the plugin’s email logging to be deleted.

The plugin’s Email Log admin page is accessible to those with the plugin’s MANAGE_POSTMAN_CAPABILITY_LOGS: [Read more]

16 Aug

WordPress Plugin Security Review: Post SMTP

For our 31st security review of a WordPress plugin based on the voting of our customers, we reviewed the plugin Post SMTP.

If you are not yet a customer of the service, once you sign up for the service as a paying customer you can start suggesting and voting on plugins to get security reviews. For those already using the service that haven’t already suggested and voted for plugins to receive a review, you can start doing that here. You can use our tool for doing limited automated security checks of plugins to see if plugins you are using have possible issues that would make them good candidates to get a review. You can also order a review of a plugin separately from our service. [Read more]