Login Register






Thread Rating:
  • 0 Vote(s) - 0 Average


WordPress's WooCommerce Fixes SQL Injection filter_list
Author
Message
WordPress's WooCommerce Fixes SQL Injection #1
Looks like input sanitization practices are still bad, even though it's 2021. Many websites run this plugin and it's likely that a good portion still need to be updated.

Quote:WooCommerce, the popular e-commerce plugin for the WordPress content management system has been updated to patch a serious vulnerability that could be exploited without authentication.

Administrators are urged to install the latest release of the platform as the flaw affects more than 90 versions starting with 5.5.0.

Owned by Automattic, the company behind the WordPress.com blogging service, the WooCommerce plugin has more than five million installations.

Read More: https://www.bleepingcomputer.com/news/se...ata-theft/
[Image: fSEZXPs.png]

Reply

RE: WordPress's WooCommerce Fixes SQL Injection #2
Quote:Looks like input sanitization practices are still bad, even though it's 2021
It's the very first thing that should be Implemented to help protect against SQLi.

You'd think In this day and age, It'd be standard practice with entities who operate on a medium to large scale.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: WordPress's WooCommerce Fixes SQL Injection #3
That will stop the majority of automated hacks but the cleverer targeted hacks are a little harder to stop.

Reply

RE: WordPress's WooCommerce Fixes SQL Injection #4
After all it is a free service, you get what you pay for. You would think that software/plugin secuirty would be a top priority considering its an e-commerce platform. SMH
Telegram: pjspooky
Discord: 99xyz
Kik: tweaker

Reply

RE: WordPress's WooCommerce Fixes SQL Injection #5
I'm not really surprised after seeing Developers who still save passwords without hashing in database.
Die  But Don't Lie
“Oh Abu Dharr! Don’t look at the smallness of the sin but look at the one you disobeyed.” Prophet Muhammad (pbuh)
[Image: p_237m2jx1.png]
Click for Free VPN

Reply

RE: WordPress's WooCommerce Fixes SQL Injection #6
(07-25-2021, 06:54 PM)Alex1759 Wrote: That will stop the majority of automated hacks but the cleverer targeted hacks are a little harder to stop.
Yes, It certainly will not prevent exploitation In Its entirety, but any form of protection Is better than nothing at all.
[Image: AD83g1A.png]

Reply







Users browsing this thread: 1 Guest(s)