EU Regulating InfoSec: How Detectify helps achieving NIS 2 and DORA compliance
**Disclaimer: The content of this blog post is for general information purposes only and is not legal advice. We are very passionate about cybersecurity rules and …
Detectify
We have recently added a bunch of new security tests to Detectify, so you can now check your WordPress site for XSS vulnerabilities in popular plugins like Ninja Forms and Loco Translate.
If you’re using one (or more) of the plugins listed below, make sure to run a new Detectify scan to see if your site is vulnerable.
XSS can be used to steal cookies, perform phishing attacks and tabnabbing, all of which can lead to stolen information and hijacked accounts.
WooCommerce PDF Invoices & Packing Slips Authenticated XSS (v. 2.0.9)
The plugin is vulnerable to authenticated reflected XSS via the ‘tab’ parameter.
Ninja Forms Authenticated XSS (prior to v. 3.1.9)
Ninja Forms is a popular web form plugin that has over 900.000 installs on WordPress. Versions prior to v. 3.1.9 are vulnerable to authenticated reflected XSS. The vulnerability was submitted to Detectify Crowdsource as a 0-day, but is now patched.
Pretty Links Authenticated XSS (v. 2.1.2)
The plugin is vulnerable to authenticated reflected XSS via the ‘message’ parameter.
Loco Translate Authenticated XSS (v. 2.0.15)
This version of the Loco Translate plugin is vulnerable to authenticated reflected XSS via the translation filter bypass.
Google Pagespeed Insights Authenticated XSS (v. 3.0.0)
Performance plugin Google Pagespeed Insights is vulnerable to authenticated reflected XSS via the ‘filter’ parameter.
Booking Calendar Authenticated XSS (v. 2.0.9)
The plugin is vulnerable to authenticated reflected XSS via the tab_cvm parameter.
Crelly Slider Authenticated XSS (prior to v. 1.2.2)
The Crelly Slider plugin is vulnerable to authenticated reflected XSS via the id parameter.
Pinfinity XSS (prior to v. 1.9.2)
The popular WordPress theme Pinfinity is vulnerable to reflected XSS via the ‘s’ (search) parameter.
If you think your site might be affected, simply log in to your Detectify account, click on your Scan profile and start a new scan. All security issues the scanner discovers will be listed in your scan report.
Stay safe!
The Detectify team
**Disclaimer: The content of this blog post is for general information purposes only and is not legal advice. We are very passionate about cybersecurity rules and …
TLDR: This article details methods and tools (from DNS records and IP addresses to HTTP analysis and HTML content) that practitioners can use to classify …