Homepage
Homepage
Sign inGet started

websec

Go to the profile of slavco
slavco
Feb 15

WordPress ACF 5.7.10 unserialize of user input

In this writing there will be only technical description of the vulnerability…

Read more…
Go to the profile of slavco
slavco
Feb 8

WordPress tighten up

Right on time and it was a time. We all know about many of the issues WP faces today because its sins from the past and…

Read more…
Go to the profile of slavco
slavco
Feb 4

WordPress NextGen Gallery <= 3.1.5 RCE via low priviledged users

Read more…
2 responses
Go to the profile of slavco
slavco
Jan 22

WordPress, serve happy!

WordPress project continue its path towards, somewhere… Maybe people there know what are they doing, but for the rest…

Read more…
Go to the profile of slavco
slavco
Jan 21

Don’t worry, WP elite is safe

WP elite is safe, but are you? Are you WP service (of any kind) provider like hosting company, small/big…

Read more…
Go to the profile of slavco
slavco
Jan 11

Security means a lot for WP users

Lucky for me I had an opportunity to see how average WordPress users care about their installations…

Read more…
Go to the profile of slavco
slavco
Dec 27, 2018

Information technology vs believes

It happened. My research with results on live target which is hosting sensitive data, finally is…

Read more…
Go to the profile of slavco
slavco
Dec 23, 2018

History of not fixed WP bug

In the latest “security” release of WordPress for the forth time the same bug was reported / fixed e.g. Lack…

Read more…
Go to the profile of slavco
slavco
Dec 21, 2018

CTF — Woo HerringPress

Today I was ready to share something more interesting about my lovely punch bag, but let us put a break and go step by…

Read more…
Go to the profile of slavco
slavco
Nov 1, 2018

Crocodile tears for accessibility

WordPress world is facing interesting point in its existence — release of gutenber. Everyone…

Read more…
Go to the profile of slavco
slavco
Oct 10, 2018

ImagePress NOT

We all know that WordPress powers more than 30% of the web and web is let say colorful, full of images. Many web sites grab images…

Read more…
Go to the profile of slavco
slavco
Oct 9, 2018

WooCommerce and Azis with scotch

Most of the topics here are WordPress related, written with heavy sarcasm, as only way to reach the…

Read more…
Go to the profile of slavco
slavco
Sep 8, 2018

When punters fail they hide in the ghetto

Punter is interesting word. Have two meanings:

Read more…
Go to the profile of slavco
slavco
Aug 1, 2018

Wordpress 4.9.7 — RCE via Author

EDIT: Wordpress 4.9.8 is vulnerable too e.g. wasn’t security release.

Wordpress have suffered from Arbitrary file deletion that leads towards RCE. In our lovely relationship with WP PR person I have stated quite clearly that offered solution…

Read more…
Go to the profile of slavco
slavco
Jul 9, 2018

Wordpress ≥ 4.9.7 and evil author with scotch

Recently Wordpress suffered from authenticated arbitrary file deletion vulnerability. The vulnerability (probably calculated as low severity) was hanging 7 months and after the disclosure they rushed to fix it with their PR agent guiding the process…

Read more…
Go to the profile of slavco
slavco
Jun 11, 2018

Fixed lvl GoatPress

Wordpress have fixed flash upload vulnerability, but do they?

I won’t write too much regarding wp druids (security team), but I’ll make clear that after 11 months the issue remains not patched, while the fix is obviously trivial. So, this disclosure is more than…

Read more…
Go to the profile of slavco
slavco
May 22, 2018

JSON endpoints without tokens doesn’t leak they whisper

Read more…
Go to the profile of slavco
slavco
Mar 2, 2018

wp-job-manager ≤ 1.29.2 preauth POI / unserialize of user supplied data

Wordpress has gone trough interesting period of time. They have tried to fix critical vulnerabilities:

  • https://hackerone.com/reports/179920
Read more…
1 response
Go to the profile of slavco
slavco
Feb 28, 2018

Authentication bypass / RCE on 300k live websites using mainwp-child < 3.4.5

Month ago I was performing a security audit on one web setup for a client and I have meet the mainwp-child plugin there. Looking at the code I have noticed a quite “interesting” issue there e.g. I…

Read more…
Go to the profile of slavco
slavco
Jan 26, 2018

Unserialize attack don’t work in cmd

Few months ago I wrote regarding notorious unserialize and wordpress e.g. how implemented “security” serialization functions work in the core. The conclusion is that valid serialized strings, those with :+ as second and third character in the payload will be…

Read more…
Go to the profile of slavco
slavco
Nov 13, 2017

Wordpress 4.8.3 - wrecking ball

Wordpress 4.8.3 security “fix”, solved something already reported 10+ months ago and have introduced 3 new features:

  • PHP object injection
  • SQLi
  • DoS
Read more…
Go to the profile of slavco
slavco
Sep 21, 2017

Easy Digital Downloads and wp api

In past few weeks I’ve been talking regarding concerns in the wp core functionalities. I have gone trough DB and its SQLi vulnerable prepare method, but also some toughs regarding @unserialize in the wp-core were shared too.

Encounter the EDD…

Read more…
Go to the profile of slavco
slavco
Sep 20, 2017

Wordpress is prepare -d

This morning I was delighted to see that center of my wp-centric universe is prepared! I have pushed my coffee on the side, throw the cigarette and continued with my book: Learn Wordpress in 21 days. I have my reasons to learn, maybe I’ll write regarding it in future, but let me show…

Read more…
2 responses
Go to the profile of slavco
slavco
Sep 15, 2017

unauthenticated RCE in vaultpress-the most powerful backups and security for your Wordpress site

This summer I decided to start a security project, endpoint security implementing new strategy in order to protect online services. Also decided to create the PoC…

Read more…
1 response
Go to the profile of slavco
slavco
Sep 1, 2017

Wordpress and recursive unserialize

I have already wrote regarding wordpress and the notorious unserialize and everything from serialized bypass values is mentioned there. At the wp community there are dozen of popular plugins that implement the following functionality…

Read more…
About websecLatest StoriesArchiveAbout MediumTermsPrivacy