Addressing Security Concerns Related to WPCode Usage
-
Hi @gripgrip,
I’m Parog, and I’m both a WordPress plugin developer and a security enthusiast. I recently encountered an issue on a client’s website that was redirecting traffic to malicious sites. During my investigation, I noticed that WPCode was being used as part of the exploit strategy, which led me to reach out.While I understand that a compromised access point, likely through another plugin or credentials, was necessary to leverage WPCode in this attack, I’m concerned about the potential security risks associated with your plugin. Specifically, WPCode’s functionality can be appealing to those with malicious intent, particularly because it can be easily hidden to run server-side scripts.
I recognize that there are limits to what you can do as a developer, and I appreciate the value your plugin brings to many users. However, I believe there might be room for improvement in addressing the risks posed by those who seek to misuse WPCode. For instance, implementing safeguards that prevent the execution of user-input code if the plugin is hidden from the plugin list could be a meaningful step towards mitigating these risks.
My intent in reaching out is not to criticize, but rather to share my observations and hope that they might contribute to further strengthening the security of your plugin. By proactively addressing these concerns, I believe WPCode can avoid negative feedback and continue to be a trusted tool within the WordPress community.
For context, here’s how the attack is being used: the infected site in question did not have WPCode installed prior to the breach, and the method of infection remains unclear. I found this article that might be relevant: Link to Article.
Thank you for your time and consideration. I’m happy to discuss this further if you have any questions or need additional insights.
PS: Version 2.1.12 seems to be the version being installed by script kiddies at the moment, if it can be any help.
- You must be logged in to reply to this topic.