Conversation
supportWhat can you say to the following recent problem; I did install and reinstall the most recent version of both BackUpBliss (pro) and Really Simple Security Pro; the same problem exist on the several sites. Updated: 2026-04-08 Published: 2023-07-28 Updated: 2026-04-08 Title: Inisev Plugins (Various Versions) – Cross-Site Request Forgery on handle_installation functionDescription Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers to install plugins from the limited list via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.CWE 1 Total Learn more CWE-352: CWE-352 Cross-Site Request Forgery (CSRF) The page I need help with: [ log in to see the link]
Hello @goidige , Whenever you see “news” like these, it is good to verify them on the trustworthy WP security sites, that are frequently updated , such as Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/detail/inisev-plugins-various-versions-cross-site-request-forgery-on-handle-installation-function Many other security websites and pages out there keep the date and status of security issues non-transparent to attract more traffic. But WP users should always look for these very important details: – When was the issue detected? – Is it already patched? In this specific example, you will notice that the issue was detected years ago and immediately patched. We keep our plugins patched and secure at all times. Kind regards
Hello @goidige , Whenever you see “news” like these, it is good to verify them on the trustworthy WP security sites, that are frequently updated , such as Wordfence: https://www.wordfence.com/threat-intel/vulnerabilities/detail/inisev-plugins-various-versions-cross-site-request-forgery-on-handle-installation-function Many other security websites and pages out there keep the date and status of security issues non-transparent to attract more traffic. But WP users should always look for these very important details: – When was the issue detected? – Is it already patched? In this specific example, you will notice that the issue was detected years ago and immediately patched. We keep our plugins patched and secure at all times. Kind regards