WPIntell

Source evidence

Vulnerability

Backup Migration · support · 2026-04-18T20:29:00+00:00

mixedsentiment
highseverity
0.9relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 25 rows with source links

20.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

20 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
goidige resolved
What can you say to the following recent problem; I did install and reinstall the most recent version of both BackUpBliss (pro) and Really Simple Security Pro; the same problem exist on the several sites. Updated: 2026-04-08 Published: 2023-07-28 Updated: 2026-04-08 Title: Inisev Plugins (Various Versions) – Cross-Site Request Forgery on handle_installation functionDescription Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.CWE 1 Total Learn more CWE-352: CWE-352 Cross-Site Request Forgery (CSRF) The page I need help with: [ log in to see the link] Hello @goidige , Whenever you see “news” like these, it is good to verify them on the trustworthy WP security sites, that are frequently updated , such as Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/detail/inisev-plugins-various-versions-cross-site-request-forgery-on-handle-installation-function Many other security websites and pages out there keep the date and status of security issues non-transparent to attract more traffic. But WP users should always look for these very important details: – When was the issue detected? – Is it already patched? In this specific example, you will notice that the issue was detected years ago and immediately patched. We keep our plugins patched and secure at all times. Kind regards

Comments

1 shown
MixHa 2026-04-20T11:54:00+00:00

Hello @goidige , Whenever you see “news” like these, it is good to verify them on the trustworthy WP security sites, that are frequently updated , such as Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/detail/inisev-plugins-various-versions-cross-site-request-forgery-on-handle-installation-function Many other security websites and pages out there keep the date and status of security issues non-transparent to attract more traffic. But WP users should always look for these very important details: – When was the issue detected? – Is it already patched? In this specific example, you will notice that the issue was detected years ago and immediately patched. We keep our plugins patched and secure at all times. Kind regards