Web Flaws and Vulnerabilities

Handle the ReDoS (Regular Expression Denial of Service), or Evil Regex

November 4, 2025 0 comments

You know I spend my time dissecting vulnerabilities, whether they’re simple or require a twisted mind to cause harm. Today, we’re talking about a sneaky attack—a simple coding mistake. Buckle up, because we’re diving into ReDoS, the nightmare of regular expressions (Regex) for developers.

Read more
SecuPress

SecuPress v2.4 aka Midas

October 8, 2025 0 comments

A major update, version 2.4, just two months after 2.3—that’s not bad. It’s less intimidating than the previous one. The changelog is short, and the risk of seeing a 2.4.20 version is very low. Let’s see what this new feature is and why it was added precisely.

Read more
Web Flaws and Vulnerabilities

Widget Logic and the undesired JavaScript injection

October 12, 2024 0 comments

Timothée Allemmoz reported on the WordPress France Community Slack  that the Widget Logic plugin seemed to be hijacked. Let see this together. (TL;DR It’s infected but I’ll give you a solution to keep it!)

Read more
Web Flaws and Vulnerabilities

Anatomy of a Shortcode with its Flaws

February 13, 2024 0 comments

During my research in free extensions, or during code audits ordered by customers, I find from time to time things so simple to correct and yet so devastating that I wanted to show you one, a beautiful one.

Read more