Membership is FREE – with unlimited access to all features, tools, and discussions. Premium accounts get benefits like banner ads and newsletter exposure. ✅ Signature links are now free for all. Share your own thoughts and experience, accounts may be terminated for violations.
  • Welcome to AcornDomains.co.uk, a friendly community for UK domain investors, developers and anyone interested in domain names.

    Whether you're looking to buy or sell domains, learn more about the UK domain market, get feedback on your names, or simply chat with other domainers, you're in the right place. AcornDomains has been bringing together people from across the UK domain industry for many years, from complete beginners to experienced investors.

    Have a look around, join the discussions and, if you haven't already, create a free account and introduce yourself.

Wordpress Plugin Vulnerabilities

Status
Not open for further replies.
Joined
Feb 23, 2011
Posts
730
Reaction score
15
I have long been an advocate of using Wordpress for content based sites & blogs whilst using more professional systems or bespoke coding for ecommerce sites, sensitive database sites, or any site dealing with real client transactions etc.

For anyone that is interested I have posted a link below to a recently published report on the top 50 plugins for wordpress and their (if any) security vulnerabilities.

20% were vulnerable to attacks such as SQL injections and so far over 8 million vulnerable plugins or plugins containing concealed instructions have been downloaded.

http://www.checkmarx.com/wp-content...curity-State-of-WordPress-Top-50-Plugins3.pdf
 
It doesn't actually name the 11 top 50 plugins that still have vulns, although you could guess them from the descriptions and download counts.

I suspect that some of the vulnerabilities can only be exploited if you have access to the admin side. Looking at the list, a few only work on the admin side and others only have inputs on the admin side. Source Code Analysis tends to ignore the context of "only trusted people can actually use this screen".

The general advice it gives is broadly sound but naturally enough for a report from a source code analysis provider it recommends automated source code analysis...
 
Status
Not open for further replies.
Top Bottom