WordPress Flaws and Vulnerabilities
WordPress has made some great strides in terms of security with the latest version releases. Despite all these efforts, flaws and vulnerabilities are always being discovered. It's important to keep an eye on them and make sure to install the proper security patches. Check out our articles regarding some flaws found on WordPress.
On May 10th 2016, All In One WP Security & Firewall patched some SQL injection detected by our team. Those flaws allow any visitor to alter DB queries. This represent a high security risk.
Recently around april, 19th 2016, iThemes Security got patched against a vulnerability discovered by our team, a lack of capability check, allowing any member with any role to perform an Administrator action.
BJ Lazy Load is a plugin to differ the image loads, available for free on the official WordPress repository and he’s using TimThumb. On 1st september 2015, we did some research about Laly loading plugins and we finally discovered that this plugin, BJ Lazy Load v 0.7.5, was using an outdated version of TimThumb, this famous script which is still responsible of […]
WPML contains a XSS flaw since v2.9.3