Plugin Vulnerabilities's Avatar

Plugin Vulnerabilities

@pluginvulns.bsky.social

Provider of service to protect websites from being exploited due to vulnerable WordPress plugins. https://www.pluginvulnerabilities.com/

64 Followers  |  26 Following  |  1,119 Posts  |  Joined: 02.01.2024  |  2.2638

Latest posts by pluginvulns.bsky.social on Bluesky

Preview
Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of June 6

Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of June 6

06.06.2025 22:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
WordPress Firewall Plugin Claimed to Protect Against โ€œAny Threatโ€ Doesnโ€™t Stop Even One Simulated Attack From Firewall Testing Tool

WordPress Firewall Plugin Claimed to Protect Against "Any Threat" Doesn't Stop Even One Simulated Attack From Firewall Testing Tool

03.06.2025 22:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Patchstack Now Withholding Misappropriated Information Needed to Secure Plugins in WordPress Plugin Directory From WordPress

Patchstack Now Withholding Misappropriated Information Needed to Secure Plugins in WordPress Plugin Directory From WordPress

30.05.2025 22:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 30

Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 30

30.05.2025 22:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 4 days, 9 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can reacโ€ฆ

Perhaps you could explain to your members that they shouldn't lie about the CRA as an excuse to withhold security vulnerability information from the open source WordPress project. Which is putting millions of websites at unnecessary risk of security issues.

30.05.2025 20:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The WordPress Meta team holding up the community once again.

30.05.2025 20:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
A Month On, a Glaring Problem With Five for the Future Pledges Hasnโ€™t Been Addressed

Also worth re-upping is that Five for the Future pledges are in general highly suspect.

It is one of the many things that are need of reform with WordPress.

30.05.2025 20:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Aligning Automatticโ€™s Sponsored Contributions to WordPress Automattic has always been deeply committed to the success of WordPress, dedicating significant resources and talent to its development for almost two decades. However, weโ€™ve observed an imbalance โ€ฆ

With Automattic announcing a return to contributing to WordPress, it's worth noting that there hasn't been a change with the cited reasons they gave for reducing their contributions in January.

WP Engine's lawsuit is still on and they haven't boosted their contributions.

30.05.2025 20:25 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
WP Engine Study Finds That Security Is Somehow Considered One of WordPressโ€™ Benefits and Also Disadvantages

WP Engine Study Finds That Security Is Somehow Considered One of WordPress' Benefits and Also Disadvantages

28.05.2025 22:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
WordPress Hasnโ€™t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed โ€œCriticalโ€ Vulnerability

The unfixed vulnerability that support forum discussion is about is something we posted was likely being targeted by a hacker last week.

27.05.2025 22:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 1 day, 10 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can reacโ€ฆ

Are you going to cover how Patchstack is refusing to provide WordPress with information needed to properly handle vulnerable plugins? This is leading to websites remaining vulnerable to easily fixed vulnerabilities.

27.05.2025 22:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Patchstacksโ€™s Vulnerability Disclosure Program (VDP) Goes Against Important Requirements of EUโ€™s Cyber Resilience Act

Patchstack are claiming the EU Cyber Resilience Act (CRA) requires this.

It isn't the first time they have lied about that act.

27.05.2025 21:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

The US Government through their funding of CVE is also supporting this.

27.05.2025 21:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Patchstack Secures $5M in Series A Funding Patchstack, a leading WordPress security company, recently raised $5 million in its Series A funding round. The funding round was led by Karma Ventures, G+D Ventures, and Emilia Capital, an investmโ€ฆ

Joost de Valk (@joost.blog) is funding what is basically a man-in-the-middle (MiTM) attack against WordPress.

27.05.2025 21:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 1 day, 9 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can reactโ€ฆ

Patchstack tries to get people to report plugin vulnerabilities to them instead of developers or WordPress. Now they are refusing to provide the information to WordPress.

27.05.2025 21:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Wordfence Missed That Authenticated Persistent XSS Vulnerability in 2+ Million Install MC4WP: Mailchimp for WordPress Wasnโ€™t Fixed

We provided our customers with the details of the vulnerability last week.

27.05.2025 20:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Would anyone guess that this changelog entry for a WordPress plugin with 2+ million installs was referring to fixing a vulnerability?:

"Improved context-dependent escaping in dynamic content tags."

27.05.2025 20:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Security vulnerability Security vulnerability Resolved Artan (@artankrasniqi1988) 1 day, 7 hours ago Hi, wordfence reported a high level vulnerability: Had to uninstall the plugin for now. Hope a fix comes so I can reactโ€ฆ

"we always take security seriously" - WordPress plugin developer who still hasn't fixed an exploitable vulnerability two months after apparently being notified of it

27.05.2025 19:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Is anyone keeping track of incident reports that haven't even received a response?

We still haven't received a response for one we filed in January of last year. It involved, among other things, returning a known vulnerable plugin to the plugin directory.

27.05.2025 17:39 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
WordPress Hasnโ€™t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed โ€œCriticalโ€ Vulnerability

Patchstack claimed today that over 100,000 websites are affected, but as we noted last week, it is significantly less than that.

27.05.2025 17:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Unpatched Critical Vulnerability in TI WooCommerce Wishlist Plugin - Patchstack ๐Ÿšจ A critical unpatched vulnerability in the TI WooCommerce Wishlist plugin allows unauthenticated file uploads and potential RCE. Over 100K sites affected. As usual, Patchstack users are protected. ๐Ÿ›ก๏ธ

A WordPress plugin with 100,000 installs has an unfixed vulnerability being targeted by a hacker and Patchstack's response is to suggest you pay them $5 a month for a firewall rule they call a "patch".

WordPress could release a real patch for free. We would provide them with the patch for free.

27.05.2025 17:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
WordPress Hasnโ€™t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed โ€œCriticalโ€ Vulnerability

In other areas the team are still failing pretty badly. A situation like this one this shouldn't happen. We have offered for years to provide fixes to stop this sort of thing from happening, and yet it keeps happening. 2/2

27.05.2025 17:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
WordPress Plugin Submission Review Seems to Have Failed Badly With ConvertPro

As we said in a comment we just left on the post, it is great that automated testing finally got implemented, as it has addressed a lot of issues that should have been caught for a long time.

But there still look to significant problems with the review process, like this. 1/2

27.05.2025 17:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
WordPress Plugin Submission Review Seems to Have Failed Badly With ConvertPro

WordPress Plugin Submission Review Seems to Have Failed Badly With ConvertPro

23.05.2025 22:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 23

Plugin Vulnerabilities Customers Helped Make WordPress Plugins More Secure, Week of May 23

23.05.2025 22:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Long Overdue Security Review of WordPress Would Cost Only 0.25% of WP Engineโ€™s Estimate of Cost of One WordPress Website

Long Overdue Security Review of WordPress Would Cost Only 0.25% of WP Engine's Estimate of Cost of One WordPress Website

23.05.2025 18:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Mary Hubbard goes on to say "If we continue to center empathy, transparency, and the shared goal of making WordPress better for everyone, we wonโ€™t just be stronger. Weโ€™ll be ready for whatever comes next."

When has WordPress centered transparency?

22.05.2025 22:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Mary Hubbard:

"Rotating roles can help us avoid centralizing too much authority in any one place, and it guards against the single points of failure that open source and communities should always aim to minimize."

Is rotating roles going to apply to her boss Matt Mullenweg?

22.05.2025 22:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
WordPress Hasnโ€™t Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed โ€œCriticalโ€ Vulnerability

WordPress Hasn't Addressed Hacker Targeted Plugin With 100,000+ Installs That Has Unfixed "Critical" Vulnerability

22.05.2025 20:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

8 months after a vulnerability was reported to someone, it still hasn't been fixed.

It's unclear what happened here, but the developer claims that the vulnerability was reported to @patchstack.com instead of to them. They say Patchstack made a public claim after 6 months, but didn't notify them.

21.05.2025 22:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@pluginvulns is following 20 prominent accounts