[wp-forums] FYI plugins being closed

Mika A Epstein ipstenu at ipstenu.org
Mon Jun 11 18:01:05 UTC 2012


Oh the tl;dr is they have uploadify in their plugin without any safeguards, so if you know where the file is, you can go and upload any file, php included, to the server. So they're being closed and told to use protection.

Now to figure out how to copy that email to my iPad... Forwarding chain commencing.

On Jun 11, 2012, at 12:36 PM, Kathryn Presner <zoonini at gmail.com> wrote:

> Thanks for the heads-up.
> 
>> there's a nice explanation as to what's wrong with them.
> 
> Curious - could we see a copy?
> 
> kp
> 
> On Mon, Jun 11, 2012 at 1:23 PM, Mika A Epstein <ipstenu at ipstenu.org> wrote:
>> A lot of plugins are being closed right now for a security issue. Every last one of them is being emailed, so if someone asks "Where is my plugin?" tell them to check their email first.
>> 
>> The emails are long, because there's a nice explanation as to what's wrong with them.
> ]
> _______________________________________________
> wp-forums mailing list
> wp-forums at lists.automattic.com
> http://lists.automattic.com/mailman/listinfo/wp-forums


More information about the wp-forums mailing list