Tag: wordpress plugin security

  • WordPress.org Plugin Authors Receive Suspicious Requests For Repository Access

    WordPress.org Plugin Authors Receive Suspicious Requests For Repository Access

    A suspicious request has been circulating via email, soliciting WordPress.org plugin authors to give a third party write access to their repositories. The originator of these requests goes by the username bestweblayout on WordPress.org and operates the bestweblayout.com domain. The issue was first reported by WordPress user FractalizeR, who posted the contents of the email:…

  • WordPress Plugin Challenge: Fix the Intentionally Vulnerable Plugin

    WordPress Plugin Challenge: Fix the Intentionally Vulnerable Plugin

    Attention WordPress plugin developers! Here’s an opportunity to sharpen your skills. Back in April, Jon Cave created a learning exercise, asking developers to review an intentionally vulnerable plugin that he created. Cave loaded this plugin up with a range of common security vulnerabilities that you might find out in the wild. The plugin is located…