Discussion
Loading...

Discussion

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Ben Ramsey
Ben Ramsey
@ramsey@phpc.social  ·  activity timestamp last week

Is there an official or “blessed” vulnerability database for #WordPress plugins? I’m looking for what the community uses as the definitive resource.

  • Copy link
  • Flag this post
  • Block
threadi
threadi
@threadi@mastodon.social replied  ·  activity timestamp last week

@ramsey Unfortunately, I often ask myself the same question. Officially, there is nothing from WordPress itself, but https://www.cve.org/CVERecord/SearchResults?query=wordpress%20plugin should theoretically have some information. I follow #wordpress here in the Fediverse, where a few messages are posted from time to time. You can also use a security plugin that informs you about possible problems on your site. Or https://wordpress.org/plugins/patchstack/ #patchstack

WordPress.org

Patchstack – WordPress & Plugins Security

Patchstack automatically identifies and mitigates security vulnerabilities in WordPress plugins, themes, and core.
https://www.cve.org/CVERecord/SearchResults?query=wordpress%20plugin
  • Copy link
  • Flag this comment
  • Block
Ian
Ian
@soviut@hachyderm.io replied  ·  activity timestamp last week

@ramsey WordPress _IS_ the vulnerability.

I'm being facetious, but WP seems like an odd choice these days, given how many better options for building static sites and blogs exist now (eg: Astro).

It could be argued that WordPress has a rich ecosystem, but you're literally asking for ways to ensure said ecosystem doesn't bite you.

  • Copy link
  • Flag this comment
  • Block
Alerta! Alerta!
Alerta! Alerta!
@heiglandreas@phpc.social replied  ·  activity timestamp last week

@ramsey According to https://www.cve.org/PartnerInformation/ListofPartners the "official CNAs for WordPress are Wordfence and WPScan

https://www.cve.org/PartnerInformation/ListofPartners/partner/Wordfence

https://www.cve.org/PartnerInformation/ListofPartners/partner/WPScan

Not sure that helps though...

https://www.cve.org/PartnerInformation/ListofPartners/partner/WPScan
https://www.cve.org/PartnerInformation/ListofPartners/partner/Wordfence
https://www.cve.org/PartnerInformation/ListofPartners
  • Copy link
  • Flag this comment
  • Block
Arnan
Arnan
@arnan@mas.to replied  ·  activity timestamp last week

@ramsey whoever shouts the loudest the current week as far as I know…

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.44 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct