Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How we closed almost 1000 plugins in a month - a story of the biggest WordPress bug bounty hunt #577

Closed
sh-aps opened this issue Jan 19, 2025 · 8 comments

Comments

@sh-aps
Copy link
Collaborator

sh-aps commented Jan 19, 2025

In October 2024, our usual bug bounty hunt resulted in receiving 1570 valid reports and closing almost 1000 plugins from the official WordPress repository. This huge number looks scary and seems once again to prove the fact that WordPress ecosystem security is poor.But is it? Let's dive deeper into how it all happened, what were the consequences, and what we can learn from this.

@Stdubic
Copy link

Stdubic commented Jan 20, 2025

Crazy numbers.

@darius-fx
Copy link

That moment when you realize that this is ~1.67% of all the plugins on wp.org repository 😱

@muslimfrompk
Copy link

Sounds Insane!

@joaopedrosalcantara
Copy link

October was an amazing month!

@AurelioNinja
Copy link

Congrats folks!

@0vulns
Copy link

0vulns commented Jan 20, 2025

Crazy October!

@planningwrite
Copy link

Love it!

@TheJoin95
Copy link
Member

Accepted as OSDay25 talk!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

9 participants