12 Aug 2019

Exploitation of Simple 301 Redirects Connected Plugin is Another Reminder of How Our Service Keeps You Ahead of WordPress Plugin Vulnerabilities

When we say that our service provides the best data on vulnerabilities in WordPress plugins you are using that isn’t just a marketing slogan. That is something that is based on us continually comparing what we are doing to others and also continually looking at how we can improve. An improvement that is just over a week old already has paid off in terms of our customers being warned well ahead of others about a vulnerability now being exploited in the plugin Simple 301 Redirects – Addon – Bulk CSV Uploader.

Yesterday we had a lot of traffic coming to our website for content we have on a plugin related to that Simple 301 Redirects, which would usually indicates something security related is occurring with it. Yet early last year we did a security review of the plugin and only found one minor issue among the things we checked for, so at least at that time it was rather secure. Monitoring we do and other information pointed to what was going on, as we had what looked to be a hacker probing for usage of the plugin Simple 301 Redirects – Addon – Bulk CSV Uploader on our website by requesting this file: [Read more]

5 Aug 2019

Vulnerability Details: Multiple in Simple 301 Redirects – Addon – Bulk CSV Uploader

With our full disclosures of vulnerabilities in protest of the continued inappropriate behavior of the WordPress Support Forum Moderators, one of the criticisms we have gotten is that we are notify our customers before disclosing the vulnerabilities, despite that not being the case. We have always publicly disclosed vulnerabilities at the same time we start warning our customers of them, doing otherwise would raise some serious ethical issues. Other security providers don’t follow that type of practice, one of them being the makers of the NinjaFirewall plugin. Two of the vulnerabilities they are attempting to protect their customers from (though probably only doing so partially) that they haven’t publicly disclosed are a persistent cross-site scripting (XSS) vulnerability and a privilege escalation vulnerabilities in the plugin Simple 301 Redirects – Addon – Bulk CSV Uploader. That plugin was closed on the Plugin Directory on July 28.


[Read more]