WPIntell

Source evidence

Security issue?

Testimonial Slider · support · 2018-10-08T16:27:00+00:00

mixedsentiment
highseverity
0.88relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 31 rows with source links

19.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

25 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
David Anderson / Team Updraft resolved
@tejaswini @slidervilla Hi, Does anybody know what the security issue in this plugin that has led to it being closed is? In the absence of any information, it’s hard to know what to do. (Full site compromise possible by anyone? Or, minor self-XSS possible if you stand on your left leg on the Statue of Liberty during a blue moon?) David Does it matter? It is insecure, and not being updated any longer. Don’t use it. Remove it and find a new plugin. Hi Otto, “Insecure” covers a multitude of possibilities, ranging from the very hard to trigger and very limited in impact when triggered, up to the easy to trigger and disastrous in impact. Time is a limited resource, and people like to prioritise their time based on the most pressing problems. Having no information upon whether a problem is pressing or not is very unhelpful to the operators of the 10,000+ active sites that this is on, who, in the absence of any information, are forced to assume the worst. I’m also a plugin developer, not a simple end-user. If a problem is an easy one-line fix, then it’s easier for me to make the fix than to research migration paths and move to a different plugin. Again, not having that information is frustrating and leads to unnecessary duplication of work. In the case of this particular plugin, I’ve audited the code. Users are susceptible to targeted persistent XSS attacks. Googling shows that others have also done so and come to the same conclusion. David I’m marking my own thread as closed now, since I took over maintainership of the plugin and cleaned it up so that it now has no known vulnerabilities. (Users were exposed to various things of this sort: http://vinnievanhoecke.be/blog/1530144000 ). David

Comments

3 shown
Samuel Wood (Otto) 2018-10-14T21:50:00+00:00

Does it matter? It is insecure, and not being updated any longer. Don’t use it. Remove it and find a new plugin.

David Anderson / Team Updraft 2018-10-15T08:01:00+00:00

Hi Otto, “Insecure” covers a multitude of possibilities, ranging from the very hard to trigger and very limited in impact when triggered, up to the easy to trigger and disastrous in impact. Time is a limited resource, and people like to prioritise their time based on the most pressing problems. Having no information upon whether a problem is pressing or not is very unhelpful to the operators of the 10,000+ active sites that this is on, who, in the absence of any information, are forced to assume the worst. I’m also a plugin developer, not a simple end-user. If a problem is an easy one-line fix, then it’s easier for me to make the fix than to research migration paths and move to a different plugin. Again, not having that information is frustrating and leads to unnecessary duplication of work. In the case of this particular plugin, I’ve audited the code. Users are susceptible to targeted persistent XSS attacks. Googling shows that others have also done so and come to the same conclusion. David

David Anderson / Team Updraft 2018-10-16T15:45:00+00:00

I’m marking my own thread as closed now, since I took over maintainership of the plugin and cleaned it up so that it now has no known vulnerabilities. (Users were exposed to various things of this sort: http://vinnievanhoecke.be/blog/1530144000 ). David