25 Jul 2017

Vulnerability Details: PHP Object Injection Vulnerability in Referrer Detector

A month ago we discussed the web hosting company Pagely’s discovery of a number of PHP objection injection vulnerabilities in WordPress plugins. For some reason the unfixed ones have remained in the WordPress Plugin Directory despite being reported to the people running it. We recently took a closer look at those vulnerabilities while improving our detection of this kind of vulnerability for our new proactive monitoring of changes to WordPress plugins to look for vulnerabilities and that seemed like a good time to document them.


[Read more]