WPScan

WPScan publishes reporting and resources in the Security section of WPURLs.

Type
Company publication
Section
Security
How often they publish
0 items in 30 days
Last checked
9m ago
Website
Visit publisher

Topics covered

WPScan

WPScan 4.0.0: We’re Back

WPScan 4.0.0 is here. We read through years of community issues. We addressed every major complaint. 75+ open issues → 0. Explicit scan control. Authentication‑based enumeration. Real‑time streaming. Consolidated codebase. This is WPScan shaped by what you asked for. You Control…

By Automattic Special Projects

WPScan

Unauthorized Plugin Installation/Activation in Hunk Companion

This report highlights a vulnerability in the Hunk Companion plugin < 1.9.0 that allows unauthenticated POST requests to install and activate plugins directly from the WordPress.org repository. This flaw poses a significant security risk, as it enables attackers to install…

By Daniel Rodriguez

WPScan

Identifying Traffic from Shell Finder Bots

A shell finder is a type of reconnaissance tool that is used by threat actors to identify websites that have already been compromised and contain backdoor shells. A backdoor shell is a form of malware that is added by a threat actor after gaining unauthorized access to a…

By Luke

WPScan

Unpatched Vulnerability in TI WooCommerce Wishlist Plugin

A few weeks ago a SQL Injection was discovered in the TI WooCommerce Wishlist plugin. After checking closer we found another entry point, affecting over 100,000 active installs. Despite the severity of this issue, the vendor has not yet provided a patch, leading to public…

By John Castro

WPScan

Unauthenticated Privilege Escalation in Profile-Builder plugin

During a routine audit of various WordPress plugins, we identified some issues in Profile Builder and Profile Builder Pro (50k+ active installs). We discovered an Unauthenticated Privilege Escalation Vulnerability which could allow attackers to gain administrative access without…

By John Castro

WPScan

Object Injection vulnerability fixed in SEOPress 7.9

During a routine audit of various WordPress plugins, we identified a few issues in SEOPress (300k+ active installs). More specifically, we discovered an authentication bug which could allow attackers to access certain protected REST API routes without having any kind of account…

By Marc Montpas

WPScan

A persistent twist in the current Malware Campaign

Recently while covering malware campaigns exploiting the LiteCache and WP‑Automatic WordPress plugins, we found that attackers were installing php‑everywhere, a plugin that allows users to run arbitrary PHP code in their site’s posts. This plugin was closed on April 25th per its…

By Fioravante Souza