Membership is FREE, giving all registered users unlimited access to every Acorn Domains feature, resource, and tool! Optional membership upgrades unlock exclusive benefits like profile signatures with links, banner placements, appearances in the weekly newsletter, and much more - customized to your membership level!

Wordpress Plugin Vulnerabilities

Status
Not open for further replies.
Joined
Feb 23, 2011
Posts
730
Reaction score
15
I have long been an advocate of using Wordpress for content based sites & blogs whilst using more professional systems or bespoke coding for ecommerce sites, sensitive database sites, or any site dealing with real client transactions etc.

For anyone that is interested I have posted a link below to a recently published report on the top 50 plugins for wordpress and their (if any) security vulnerabilities.

20% were vulnerable to attacks such as SQL injections and so far over 8 million vulnerable plugins or plugins containing concealed instructions have been downloaded.

http://www.checkmarx.com/wp-content...curity-State-of-WordPress-Top-50-Plugins3.pdf
 
It doesn't actually name the 11 top 50 plugins that still have vulns, although you could guess them from the descriptions and download counts.

I suspect that some of the vulnerabilities can only be exploited if you have access to the admin side. Looking at the list, a few only work on the admin side and others only have inputs on the admin side. Source Code Analysis tends to ignore the context of "only trusted people can actually use this screen".

The general advice it gives is broadly sound but naturally enough for a report from a source code analysis provider it recommends automated source code analysis...
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members online

Premium Members

Latest Comments

New Threads

Domain Forum Friends

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators
General chit-chat
Help Users
  • No one is chatting at the moment.
      There are no messages in the current room.
      Top Bottom