10 Dec 2021

WordPress Forum Moderators Again Stop WP Community From Helping Each Other Deal With Hacked Sites

On Monday, a serious vulnerability was fixed in the WordPress plugin PublishPress Capabilities, which we detailed for customers on Tuesday (we also warned about less serious vulnerability the same day). On Wednesday, the vulnerability was widely exploited.

That is a situation that could have largely avoided by the WordPress plugin team, if they had automatically updated the plugin before the exploitation happened, instead of after (or by websites enabling WordPress to automatically update plugins). Instead, what WordPress did through the team running their support forum (which is led by one of two people that also control the plugin team), is shutdown and largely deleted the discussion where users were helping other to deal with the hacked websites. [Read more]

7 Dec 2021

Cross-Site Request Forgery (CRSF)/Settings Change Vulnerability in PublishPress Capabilities

Based on the level of insecurity we found while looking in to the details of a serious vulnerability being fixed in version 2.3.1 of the WordPress plugin PublishPress Capabilities, we started checking for other security issues and we quickly found another vulnerability. The plugin doesn’t check for a valid nonce when making changes on the plugin’s Admin Features page.

What makes that vulnerability more concerning is the vulnerable feature was only introduced inversion 2.3 of the plugin: [Read more]