Home / Companies / Detectify / Blog / Post Details
Content Deep Dive

Newly Added Security Tests, February 3, 2017: WordPress plugins and Elastic search

Blog post from Detectify

Post Details
Company
Date Published
Author
Detectify
Word Count
90
Company Posts That Month
9
Language
-
Hacker News Points
-
Post removed?
No
Summary

Security is a dynamic field that requires continuous updates to address new vulnerabilities, which is why regular updates are crucial. Recent updates have highlighted several issues including SQL injection vulnerabilities in WMPL, cross-site scripting (XSS) in the Jetpack WordPress plugin, user enumeration via the WordPress REST API, and publicly exposed Predis example files. Other noted vulnerabilities include exposure of the Webalizer interface, remote code execution in Elasticsearch, discovering /.bash_history files, open memcache ports, and XSS issues with WordPress plupload.swf and wpml-plugin, along with an information disclosure module for /unzip.php. These updates aim to enhance security by addressing these vulnerabilities promptly.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.