WordPress.org

Ready to get started?Download WordPress

Forums

SecurePress Website Security System
JavaScript Exploit (3 posts)

  1. markizano
    Member
    Posted 1 year ago #

    http://blog.markizano.net/2012/07/wordpress-securepress-plugin.html

    There's an exploit available in this plugin.
    I've detailed the recommended function to properly escape the data.

    Tested and verified on SecurePress Plugin version 8.4.0.1.

    http://wordpress.org/extend/plugins/securepress-plugin/

  2. lakersalex
    Member
    Posted 1 year ago #

    a site i manage got hacked and the security service i use advised me that it looks like the plugin or portions of it were installed on my site.

    The names of the directory and filename are similar to Securelive software http://www.securelive.net . The particular directory and filename is included in this plugin http://plugins.svn.wordpress.org/securepress-plugin/tags/5.3.02/sl_admin.php which belongs to securelive.net (securepress) which is a web application security software. This seems legitimate plugin of this software.

    The problem is I never installed that plugin!

    What's going on here!?

  3. lakersalex
    Member
    Posted 1 year ago #

    Funny you posted this right as I was discovering this connection!

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic