4 ms·
That’s awesome, now can you find one that points to all the plugins that cause these security exploits? Because none of those are from the default WordPress ins
by bdlowery 5y ago
That’s awesome, now can you find one that points to all the plugins that cause these security exploits? Because none of those are from the default WordPress install with the Standard plugins (ACF Pro, CPT UI, etc).
- camillomiller 5y agoTHIS. Impressive how experienced developers and professionals fall for this fallacy all the time because, wait, they don't actually KNOW A THING about wordpress.
- ironmagma 5y agoIt’s an interesting semantic game, but ultimately not very revealing. The platform is what gave you the vulnerability; whether it was core, a theme, or a plug-in is a matter of trivia. Especially considering the plug-in “store” is curated. Contrary to your assessment I’ve deployed quite a few things with Wordpress before.
- danuker 5y agoHere's one from this year: https://www.cvedetails.com/cve/CVE-2022-21664/ https://www.cvedetails.com/cve/CVE-2022-21664/ "SQL injection due to improper sanitization in WP_Meta_Query", fixed in WordPress itself: https://bugzilla.redhat.com/show_bug.cgi?id=2039317 https://bugzilla.redhat.com/show_bug.cgi?id=2039317 https://github.com/WordPress/wordpress-develop/commit/c09ccfbc547d75b392dbccc1ef0b4442ccd3c957 https://github.com/WordPress/wordpress-develop/commit/c09ccf...
- difu_disciple 5y agoThose are all related to Wordpress core. Plugins are categorized separately from WordPress on the CVE website.