https://www.pluginvulnerabilities.com/2017/10/20/cross-site-request-forgery-csrf-vulnerability-in-duplicate-page/While looking into the details of a reflected cross-site scripting (XSS) vulnerability in the plugin Duplicate Page we noticed that there was no...
https://www.pluginvulnerabilities.com/2017/10/20/vulnerability-details-reflected-cross-site-scripting-xss-vulnerability-in-duplicate-page/Recently the security scanner service Detectify seems to have disclosed a number of unfixed reflected cross-site scripting...
https://www.pluginvulnerabilities.com/2017/10/20/vulnerability-details-cross-site-request-forgery-csrfcross-site-scripting-xss-vulnerability-in-use-any-font/Recently the web scanner service Detectify has been vaguely disclosing minor vulnerabilities in a number of...
https://www.pluginvulnerabilities.com/2017/10/19/arbitrary-file-viewing-vulnerability-in-candidate-application-form/Recently in our monitoring of the WordPress Support Forum we ran across a thread about claiming a vulnerability being exploited in a plugin Candidate...
https://www.pluginvulnerabilities.com/2017/10/19/this-might-be-why-note-press-was-removed-from-the-wordpress-plugin-directory/When it comes to improving the security of WordPress one the easiest things to do would be to start alerting when websites are using plugins...