• ResolvedPlugin Author David Anderson / Team Updraft

    (@davidanderson)


    @tejaswini @slidervilla

    Hi,

    Does anybody know what the security issue in this plugin that has led to it being closed is?

    In the absence of any information, it’s hard to know what to do. (Full site compromise possible by anyone? Or, minor self-XSS possible if you stand on your left leg on the Statue of Liberty during a blue moon?)

    David

Viewing 3 replies - 1 through 3 (of 3 total)
  • Moderator Samuel Wood (Otto)

    (@otto42)

    www.remarpro.com Admin

    Does it matter? It is insecure, and not being updated any longer.

    Don’t use it. Remove it and find a new plugin.

    Plugin Author David Anderson / Team Updraft

    (@davidanderson)

    Hi Otto,

    “Insecure” covers a multitude of possibilities, ranging from the very hard to trigger and very limited in impact when triggered, up to the easy to trigger and disastrous in impact. Time is a limited resource, and people like to prioritise their time based on the most pressing problems. Having no information upon whether a problem is pressing or not is very unhelpful to the operators of the 10,000+ active sites that this is on, who, in the absence of any information, are forced to assume the worst.

    I’m also a plugin developer, not a simple end-user. If a problem is an easy one-line fix, then it’s easier for me to make the fix than to research migration paths and move to a different plugin. Again, not having that information is frustrating and leads to unnecessary duplication of work.

    In the case of this particular plugin, I’ve audited the code. Users are susceptible to targeted persistent XSS attacks. Googling shows that others have also done so and come to the same conclusion.

    David

    Plugin Author David Anderson / Team Updraft

    (@davidanderson)

    I’m marking my own thread as closed now, since I took over maintainership of the plugin and cleaned it up so that it now has no known vulnerabilities. (Users were exposed to various things of this sort: https://vinnievanhoecke.be/blog/1530144000 ).

    David

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Security issue?’ is closed to new replies.