3 Mar 2020

Bad Practices by Fortinet and the WPScan Vulnerability Database Lead to False Claim of Vulnerability Being Fixed in WordPress Plugin

Years ago we recommended data from the WPScan Vulnerability Database as good alternative to our service, since while their data was of lower quality, it was available for free. Now more and more access is being charged for, while the quality of the data has gotten worse since we used to recommend it. Here is a recent example of that, which also shows bad practices from Fortinet made it hard to figure when they screwed up in disclosing a vulnerability.

Here is the current version of the entry from WPScan of a vulnerability in Testimonials: [Read more]