[uwebd] Are Wordpress plugins susceptible to attacks?

39 views
Skip to first unread message

Gerlando Termini

unread,
Jun 19, 2013, 2:59:21 PM6/19/13
to University and College Webmasters

In fairness, the research also mentions that all of them released updated in the following 18 months to fix those vulnerabilities.

 

http://www.checkmarx.com/wp-content/uploads/2013/06/The-Security-State-of-WordPress-Top-50-Plugins.pdf

 

Gerlando.

 

From: Greg Gamble [mailto:gga...@sbctc.edu]
Sent: Wednesday, June 19, 2013 2:29 PM
To: University and College Webmasters
Subject: [uwebd] RE: Listserv back from the dead!

 

For all the WordPress users … just an FYI:

 

Research from security vendor Checkmarx revealed that 12 of the top 50 plug-ins for the WordPress platform are susceptible to attacks such as SQL injection and cross-site scripting.”

 

http://www.eweek.com/security/popular-wordpress-plugins-vulnerable-to-attack-checkmarx-research/

 

Greg

 

 

From: Gerlando Termini [mailto:Gerlando...@cuny.edu]
Sent: Wednesday, June 19, 2013 11:24 AM
To: University and College Webmasters
Subject: [uwebd] RE: Listserv back from the dead!

 

So glad to see this ‘reloaded’ version of the list still alive and well. Thank you to all those who made it happen.

 

Gerlando Termini

Web Developer

The City University of New York

www.cuny.edu

 

From: Smith, Brian J [mailto:bsm...@albany.edu]
Sent: Wednesday, June 19, 2013 2:15 PM
To: University and College Webmasters
Subject: [uwebd] Listserv back from the dead!

 

Many thanks to all those who are keeping it alive! Best group evr.

 

My main criticism of Ning is that it’s a mile wide (tons of participants), but not too deep. So many of the groups seem deserted.

 

Cheers!

 

Brian Smith

Web Developer

UAlbany

 

 

---
You are currently subscribed to uw...@umich.edu as: gerlando...@cuny.edu.
To unsubscribe send an email to uwebd-...@umich.edu
with the word UNSUBSCRIBE as the SUBJECT of the message.

Make Web-based changes or subscribe/unsubscribe at:
http://listserver.itd.umich.edu/cgi-bin/lyris.pl?enter=uwebd&text_mode=0. If you experience problems, contact list owner Terry Calhoun at sple...@umich.edu.

Visit this list's sister community at http://cuwebd.ning.com/.

---
You are currently subscribed to uw...@umich.edu as: gga...@sbctc.edu.
To unsubscribe send an email to uwebd-...@umich.edu
with the word UNSUBSCRIBE as the SUBJECT of the message.

Make Web-based changes or subscribe/unsubscribe at:
http://listserver.itd.umich.edu/cgi-bin/lyris.pl?enter=uwebd&text_mode=0. If you experience problems, contact list owner Terry Calhoun at sple...@umich.edu.

Visit this list's sister community at http://cuwebd.ning.com/.

---
You are currently subscribed to uw...@umich.edu as: gerlando...@cuny.edu.
To unsubscribe send an email to uwebd-...@umich.edu
with the word UNSUBSCRIBE as the SUBJECT of the message.

Make Web-based changes or subscribe/unsubscribe at:
http://listserver.itd.umich.edu/cgi-bin/lyris.pl?enter=uwebd&text_mode=0. If you experience problems, contact list owner Terry Calhoun at sple...@umich.edu.

Visit this list's sister community at http://cuwebd.ning.com/.

---
You are currently subscribed to uw...@umich.edu as: uwebd-garc...@googlegroups.com.
To unsubscribe send an email to uwebd-...@umich.edu
with the word UNSUBSCRIBE as the SUBJECT of the message.

Make Web-based changes or subscribe/unsubscribe at:
http://listserver.itd.umich.edu/cgi-bin/lyris.pl?enter=uwebd&text_mode=0. If you experience problems, contact list owner Terry Calhoun at sple...@umich.edu.

Visit this list's sister community at http://cuwebd.ning.com/.

Pat Ramsey

unread,
Jun 19, 2013, 3:07:23 PM6/19/13
to University and College Webmasters
This report reads more as link-bait & attention-getting than it does anything else. If you're writing about 12 plugins being vulnerable, say that; don't say "More than 20% of the top 50 plugins are bad".

The shorter version would read "If you run a WordPress website, pay attention to updates, install updates, be smart about things."


Cheers!

Pat


June 19, 2013 1:59 PM

In fairness, the research also mentions that all of them released updated in the following 18 months to fix those vulnerabilities.

 

http://www.checkmarx.com/wp-content/uploads/2013/06/The-Security-State-of-WordPress-Top-50-Plugins.pdf

 

Gerlando.

 

From: Greg Gamble [mailto:gga...@sbctc.edu]
Sent: Wednesday, June 19, 2013 2:29 PM
To: University and College Webmasters
Subject: [uwebd] RE: Listserv back from the dead!

 

For all the WordPress users … just an FYI:

 

Research from security vendor Checkmarx revealed that 12 of the top 50 plug-ins for the WordPress platform are susceptible to attacks such as SQL injection and cross-site scripting.”

 

http://www.eweek.com/security/popular-wordpress-plugins-vulnerable-to-attack-checkmarx-research/

 

Greg


--
Pat Ramsey
@pat_ramsey

Code that works,… beautifully
Reply all
Reply to author
Forward
0 new messages