WordPress Flaws and Vulnerabilities

All In One WP Security & Firewall 4.0.9 Security Patch

May 12, 2016 0 comments

On May 10th 2016, All In One WP Security & Firewall patched some SQL injection detected by our team. Those flaws allow any visitor to alter DB queries. This represent a high security risk.

Read more
WordPress Flaws and Vulnerabilities

iThemes Security 5.3.6 Security Fix

April 25, 2016 0 comments

Recently around april, 19th 2016, iThemes Security got patched against a vulnerability discovered by our team, a lack of capability check, allowing any member with any role to perform an Administrator action.

Read more
WordPress Flaws and Vulnerabilities

BJ Lazy Load and TimThumb

September 2, 2015 0 comments

BJ Lazy Load is a plugin to differ the image loads, available for free on the official WordPress repository and he’s using TimThumb. On 1st september 2015, we did some research about Laly loading plugins and we finally discovered that this plugin, BJ Lazy Load v 0.7.5, was using an outdated version of TimThumb, this famous script which is still responsible of […]

Read more
Web Flaws and Vulnerabilities

Redux Framework and Privilege Escalation

September 2, 2015 0 comments

Redux Framework is a code structure script that allows you to easily create good looking option pages and adding its own features. Versions before 3.5.6.8 are victims of a privilege escalation flaw, the scénario for the exploit is not mainstream, here comes the requirement: Using a theme with Redux Framework, Using a plugin with Redux Framework, Having a user with a role […]

Read more