Skip to content

Davey Winder

delivering award-winning technology journalism since 1991

  • home
  • about me
  • follow me on mastodon
  • privacy policy
  • Toggle search form
photo of swiss cheese

WordPress Summer of Pwnage: 64 holes in 21 days

Posted on July 22, 2016 By Davey Winder

Summer of Pwnage hacking event has uncovered 64 vulnerabilities. Does this make WordPress the Adobe Flash of the CMS world?

Summer of Pwnage (#sumofpwn) describes itself as being a “community program for everyone with interest in software security” and that means everyone from “enthusiastic beginners to the 1337est hackers out there” apparently. When you strip back the leet speak marketing, it’s actually an open source security bug hunting event. The brainchild of Dutch application security outfit Security, #sumofpwn states that everyone is the owner of their bugs and exploits and can “use them as you like.” It does, however, encourage participants to be part of the solution and disclose them responsibly to the original code authors.

As SC publishes this story today, #sumofpwn has reached day 21 of 29 and uncovered 64 vulnerabilities. We cannot confirm how many of these have been responsibly disclosed and patched as a result. However, one of the most serious of newly disclosed bugs we are aware of included a reflected XSS problem in the very popular Ninja Forms plugin which has some 600,000 users. This has, thankfully, already been patched in a plugin update.

All of this does sound like evidence that WordPress is very insecure and sites built using it should be treated with suspicion. But hold on a moment, how true is that?

Click here to read complete article

Vulnerabilities Tags:CMS, pwn, Research, vulnerabilities, WordPress

Post navigation

Previous Post: Pokemon GO security scares: gotta catch ’em all
Next Post: AI could rescue failing cyber security sector

Related Articles

New Google Report Warns Of ‘Real And Significant Threat’ To User Privacy Google
Google Security Warning: First Hack Attack Of 2024—Update Chrome Now Google
Hackers Prompt Emergency Google 0-Day Attack Patch For Chrome Users Google
Photo of front end collision, crash test of cars This Surprisingly Simple Hack Can Crash iPhones—Update To iOS 17.2 Now Hacking
Google Chrome 120—Update Now As New Security Risks Revealed Google
New Critical Google Chrome Security Warning As 0-Day Exploit Confirmed Announcements

Categories

Post Archive

Tags

0day Analysis Android Apple Apps breach bug bounty Business Chrome crime Cybercrime Data Protection Encryption Enterprise Google Government Hackers Hacking Health healthcare industry iOS IoT iPhone Malware Microsoft News NHS Opinion passwords Phishing Privacy ransomware Research Russia Samsung threat intelligence Twitter Update Vulnerabilites vulnerabilities Vulnerability Windows Windows 10 zero-day

Copyright © 2025 Davey Winder .

×
Cookies
We serve cookies. If you think that's ok, just click "Accept all". You can also choose what kind of cookies you want by clicking "Settings". Read our cookie policy
Settings Refuse all Accept all
Cookies
Choose what kind of cookies to accept. Your choice will be saved for one year. Read our cookie policy
  • Necessary
    These cookies are not optional. They are needed for the website to function.
  • Statistics
    In order for us to improve the website's functionality and structure, based on how the website is used.
  • Experience
    In order for our website to perform as well as possible during your visit. If you refuse these cookies, some functionality will disappear from the website.
  • Marketing
    By sharing your interests and behavior as you visit our site, you increase the chance of seeing personalized content and offers.
Save Refuse all Accept all
GDPR Cookie Policy